-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Please update the Landlock library #15
Comments
ngergs
added a commit
that referenced
this issue
Oct 14, 2024
landlock update fixes GHSA-vv6c-69r6-chg9, see issue #15 thanks to @gnoack for pointing this out
Hi Günther, thanks a lot for pointing this out as well as suggested changes 👍 Cheers, |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Please update the Landlock library use in this project - the version you are using has a known bug
GHSA-vv6c-69r6-chg9
P.S. Without understanding all details of how you do the networking in your webserver, consider that you do not need to configure the "TCP bind" access right in your policy, if you are doing the
net.Listen()
before you enable the Landlock policy. That way, you can have a stronger and less complicated policy.Here is an example where this is done: https://github.com/gnoack/ukuleleweb/blob/main/cmd/ukuleleweb/main.go#L55
Thanks,
—Günther
The text was updated successfully, but these errors were encountered: