_confine
_confine
¶
Self-confinement floor for shield's long-lived state reader.
shield watch reads only its per-container state_dir — dnsmasq and
audit logs, the domain cache, the DNS-tier marker — plus the shared runtime
it imports from. It writes nothing outside state_dir. Before the loop
starts, the reader pins itself to that lane: terok-util's process-hardening
floor plus Landlock filesystem confinement. A bug in the reader then cannot
read another container's state and cannot write outside its own lane. NFLOG
is a netlink socket, not a filesystem access, so confinement leaves it
untouched.
shield simple-clearance is deliberately outside this policy: it is a
controller that invokes Podman and verdict subprocesses, not a state-only reader.
confine_to_state(state_dir)
¶
Harden this process and pin its filesystem to state_dir plus system reads.
Applies terok-util's hardening floor, then Landlock-confines the process: read and execute the system roots, read and write only state_dir. Both steps are best-effort and never raise. An old kernel may apply only its supported subset, or may leave the daemon unconfined. The reader logs either outcome at debug level and starts anyway.