[](https://gitlab.exherbo.org/sydbox/sydbox/-/blob/main/data/sydbox-logo.svg)
[](https://en.wikipedia.org/wiki/Syd_Barrett)
[](https://en.wikipedia.org/wiki/Tigran_Petrosian)
[](https://blog.rust-lang.org/2023/07/13/Rust-1.71.0.html)
[](https://repology.org/project/sydbox/versions)
[](https://builds.sr.ht/~alip/syd?)
[](https://gitlab.exherbo.org/sydbox/sydbox/-/pipelines)
[](https://gitlab.exherbo.org/sydbox/sydbox/-/blob/main/COPYING)
[](https://git.sr.ht/~alip/syd)
[](https://deps.rs/repo/sourcehut/~alip/syd)
[](https://www.bestpractices.dev/projects/8040)
[Syd](https://en.wikipedia.org/wiki/Syd_Barrett) is a
[rock-solid](https://en.wikipedia.org/wiki/Tigran_Petrosian)
[unikernel](https://en.wikipedia.org/wiki/Unikernel)
to [sandbox](https://en.wikipedia.org/wiki/Sandbox_(computer_security))
[applications](https://en.wikipedia.org/wiki/Application_software)
on [Linux>=5.19](https://en.wikipedia.org/wiki/Linux).
[Syd](https://en.wikipedia.org/wiki/Syd_Barrett) is similar to
[Bubblewrap](https://github.com/containers/bubblewrap),
[Firejail](https://firejail.wordpress.com/),
[GVisor](https://en.wikipedia.org/wiki/GVisor), and
[minijail](https://google.github.io/minijail/).
[Syd](https://en.wikipedia.org/wiki/Syd_Barrett) is
[secure by default](https://en.wikipedia.org/wiki/Secure_by_default), and
intends to provide a
[simple](https://en.wikipedia.org/wiki/KISS_principle)
[interface](https://en.wikipedia.org/wiki/API)
over various intricate
[Linux](https://en.wikipedia.org/wiki/Linux)
[sandboxing](https://en.wikipedia.org/wiki/Sandbox_(computer_security))
mechanisms such as
[LandLock](https://landlock.io/),
[Namespaces](https://en.wikipedia.org/wiki/Linux_namespaces),
[ptrace](https://en.wikipedia.org/wiki/Ptrace), and
[seccomp](https://en.wikipedia.org/wiki/Seccomp)-{[bpf](https://en.wikipedia.org/wiki/Berkeley_Packet_Filter),[notify](https://www.man7.org/linux/man-pages/man3/seccomp_notify_receive.3.html)}.
You may run [Syd](https://en.wikipedia.org/wiki/Syd_Barrett) [_as a regular user,
with no extra privileges_](https://en.wikipedia.org/wiki/Privilege_separation),
and you can even set [Syd](https://en.wikipedia.org/wiki/Syd_Barrett) as your
[_login shell_](https://linuxhandbook.com/login-shell/).
A brief overview of
[Syd](https://en.wikipedia.org/wiki/Syd_Barrett)'s
capabilities are as follows:
- [Read sandboxing](http://man.exherbolinux.org/syd.7.html#Read_Sandboxing)
- [Write sandboxing](http://man.exherbolinux.org/syd.7.html#Write_Sandboxing)
(and [Path Masking](http://man.exherbolinux.org/syd.7.html#Path_Masking))
- [Stat sandboxing](http://man.exherbolinux.org/syd.7.html#Stat_Sandboxing)
(aka **Path Hiding**)
- [Exec sandboxing](http://man.exherbolinux.org/syd.7.html#Exec_Sandboxing)
(and [SegvGuard](http://man.exherbolinux.org/syd.7.html#SegvGuard))
- [Ioctl sandboxing](http://man.exherbolinux.org/syd.7.html#Ioctl_Sandboxing)
(contain [AI/ML](https://en.wikipedia.org/wiki/Artificial_intelligence)
workloads, access
[PTY](https://en.wikipedia.org/wiki/Pseudo_terminal),
[DRM](https://en.wikipedia.org/wiki/Direct_Rendering_Manager),
[KVM](https://en.wikipedia.org/wiki/Kernel-based_Virtual_Machine)
safely)
- [Force sandboxing](http://man.exherbolinux.org/syd.7.html#Force_Sandboxing)
(aka **Verified execution**, like
[Veriexec](https://netbsd.org/docs/guide/en/chap-veriexec.html) and
[Integriforce](https://github.com/HardenedBSD/gitlab-wiki/blob/master/Home.md#security-administration-secadm)
)
- [TPE sandboxing](http://man.exherbolinux.org/syd.7.html#TPE_sandboxing)
(aka [Trusted Path Execution](https://wiki.gentoo.org/wiki/Hardened/Grsecurity_Trusted_Path_Execution))
- [Network sandboxing](http://man.exherbolinux.org/syd.7.html#Network_Sandboxing)
(feat.
[UNIX](https://en.wikipedia.org/wiki/Unix_domain_socket),
[IPv4](https://en.wikipedia.org/wiki/Internet_Protocol_version_4),
[IPv6](https://en.wikipedia.org/wiki/IPv6),
[Netlink](https://en.wikipedia.org/wiki/Netlink), and
[KCAPI](https://en.wikipedia.org/wiki/Crypto_API_(Linux))
sockets)
- [Lock sandboxing](http://man.exherbolinux.org/syd.7.html#Lock_Sandboxing)
(uses [Landlock LSM](https://landlock.io/))
- [Crypt sandboxing](http://man.exherbolinux.org/syd.7.html#Crypt_Sandboxing)
(**Transparent File Encryption** with
[AES](https://en.wikipedia.org/wiki/Advanced_Encryption_Standard)-[CTR](https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#CTR))
- [Proxy sandboxing](http://man.exherbolinux.org/syd.7.html#Proxy_Sandboxing)
([SOCKS](https://en.wikipedia.org/wiki/SOCKS)
[proxy](https://en.wikipedia.org/wiki/Proxy_server)
forwarding with
[network namespace](https://en.wikipedia.org/wiki/Linux_namespaces#Network_(net))
isolation, defaults to
[TOR](https://www.torproject.org/))
- [Memory sandboxing](http://man.exherbolinux.org/syd.7.html#Memory_Sandboxing)
- [PID sandboxing](http://man.exherbolinux.org/syd.7.html#PID_sandboxing)
(simpler alternatives to [Control Groups](https://en.wikipedia.org/wiki/Cgroups))
- [SafeSetID](https://man.exherbolinux.org/syd.7.html#SafeSetID)
(Safe [user/group switching](https://en.wikipedia.org/wiki/Privilege_separation)
with predefined
[UID/GID](https://en.wikipedia.org/wiki/User_identifier_(Unix))
[transitions](https://en.wikipedia.org/wiki/Transition_system))
- [Ghost mode](http://man.exherbolinux.org/syd.7.html#Ghost_mode)
(similar to [Seccomp](https://en.wikipedia.org/wiki/Seccomp) Level 1 aka **Strict Mode**)
- [Namespaces and Containerization](https://en.wikipedia.org/wiki/Containerization_(computing))
- **Learning mode** with [Pandora](https://crates.io/crates/pandora_box)
Read the fine manuals of [syd](https://man.exherbolinux.org/),
[libsyd](https://libsyd.exherbolinux.org/),
[gosyd](https://gosyd.exherbolinux.org/),
[plsyd](https://plsyd.exherbolinux.org/),
[pysyd](https://pysyd.exherbolinux.org/),
[rbsyd](https://rbsyd.exherbolinux.org/),
[syd.el](https://sydel.exherbolinux.org/) and watch the asciicasts [Memory
Sandboxing](https://asciinema.org/a/625243), [PID
Sandboxing](https://asciinema.org/a/625170), [Network
Sandboxing](https://asciinema.org/a/623664), and [Sandboxing Emacs with
syd](https://asciinema.org/a/627055). Join the CTF event at
https://ctftime.org/event/2178 and try to read the file `/etc/CTF`¹ on
syd.chesswob.org with ssh user/pass: syd.²
- Use cargo to install from source, requires [libseccomp](https://github.com/seccomp/libseccomp).
- To use with
[Docker](https://www.docker.com/),
[Podman](https://podman.io/), or
[CRI-O](https://cri-o.io/)
build with the "oci" feature,
see: https://man.exherbolinux.org/syd-oci.1.html
- Packaged for
[Alpine](https://pkgs.alpinelinux.org/packages?name=sydbox),
[Exherbo](https://summer.exherbolinux.org/packages/sys-apps/sydbox/index.html),
and
[Gentoo](https://packages.gentoo.org/packages/sys-apps/syd).
- Binary releases are located at https://distfiles.exherbolinux.org/#sydbox/
- Releases are signed with this key: https://keybase.io/alip/pgp_keys.asc
- Change Log is here: https://gitlab.exherbo.org/sydbox/sydbox/-/blob/main/ChangeLog.md
- [VIM](https://www.vim.org/)
[syntax highlighting](https://en.wikipedia.org/wiki/Syntax_highlighting)
file for
[Syd](https://en.wikipedia.org/wiki/Syd_Barrett)
profiles is here: https://gitlab.exherbo.org/sydbox/sydbox/-/tree/main/vim
- Tested on [arm64](https://en.wikipedia.org/wiki/Arm64),
[armv7](https://en.wikipedia.org/wiki/Armv7),
[x86](https://en.wikipedia.org/wiki/X86), and
[x86-64](https://en.wikipedia.org/wiki/X86-64) with
[GitLab Pipelines](https://gitlab.exherbo.org/sydbox/sydbox/-/pipelines), and
[SourceHut Builds](https://builds.sr.ht/~alip/syd?).
Maintained by Ali Polatel. Up-to-date sources can be found at
https://gitlab.exherbo.org/sydbox/sydbox.git and bugs/patches can be submitted to
<https://gitlab.exherbo.org/groups/sydbox/-/issues>. Follow toots with the [#sydbox
hashtag](https://mastodon.online/tags/sydbox) and discuss in [#sydbox on Libera
Chat](ircs://irc.libera.chat/#sydbox).
¹: [SHA256](https://en.wikipedia.org/wiki/SHA-2)(`/etc/CTF`)=`f1af8d3946546f9d3b1af4fe15f0209b2298166208d51a481cf51ac8c5f4b294`
²: Start by reading [the CTF sandbox profile](https://gitlab.exherbo.org/sydbox/sydbox/-/raw/main/data/ctf.syd-3).
³: [That cat's something I can't explain!](https://gitlab.exherbo.org/paludis/paludis/-/commit/dd0566f16e27f2110581234fe1c48a11d18a7d64)