rimerosolutions / entrusted

Sanitize documents to safe PDFs, for active content removal
GNU General Public License v3.0
26 stars 0 forks source link

Live CD: Implement gVisor support #36

Closed yveszoundi closed 1 year ago

yveszoundi commented 1 year ago

Background

gVisor is a container sandbox developed by Google that focuses on security, efficiency and ease of use.

gVisor has been preferred to a combination of seccomp (existing) and apparmor profiles:

Request

Enable gVisor on the Live CD as it provides a rather complete out of the box container security solution.

Overall changes

yveszoundi commented 1 year ago

This is working just fine on amd64 and aarch64.