Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: tmp Clear Filter

A quick look at unprivileged sandboxing

blog - git - desktop - images - contact A quick look at unprivileged sandboxing Disclaimer: This is to the best of my knowledge. It's a complicated topic, there are tons of options, and this only covers a tiny fraction of this topic anyway. If you spot mistakes, please tell me. Suppose you have a server daemon that you want to confine to a single directory. During the startup phase of the program, it also needs to read some files outside of that directory -- you can apply the confinement only

Save your disk, write files directly into RAM with /dev/shm

There are garbage dumps everywhere for those with eyes to see Given my interest in extending the life of my SD cards and hard drives as much as possible, I’m surprised I haven’t come across /dev/shm before. In a word it’s a world-accessible RAM scratchpad, which seems baked right into POSIX, so that virtually every Unix system already has it mounted as a tmpfs by default: 1 2 ❯ mount | grep '/dev/shm' tmpfs on /dev/shm type tmpfs ( rw,nosuid,nodev,inode64 ) Today’s lucky 10,000, indeed. It ge

Topics: dev ram shm tmpfs word