Skip to content

Topic archive

Cybersecurity

Cybersecurity articles focus on practical application and infrastructure security, access controls, TLS, hardening, attack prevention, and secure operational practices.

540 articles
Cybersecurity 19 Sep 2026 7 min read

CSP Nonces and strict-dynamic Shift Script Trust to the Bootstrap Boundary

A Content Security Policy can contain a long list of approved script hosts and still expose more execution authority than its author intended. A host source such as https://cdn.example.net authorizes matching script resources from that origin; it does not express which individual response or which application decision is trusted. When a permitted host serves user-controlled files, legacy JSONP endpoints, or another executable resource outside the application’s intended set, the host boundary can become too broad.

Cybersecurity 19 Sep 2026 6 min read

COOP and COEP Turn Cross-Origin Isolation into a Document-Group Boundary

COOP and COEP Turn Cross-Origin Isolation into a Document-Group Boundary A web page can be same-origin with its own application code while still maintaining relationships with cross-origin popups, frames, workers, and resources. Those relationships matter when a browser decides which documents can occupy the same browsing context group and which capabilities can be exposed safely. Cross-origin isolation changes that arrangement through two response policies with different jobs. Cross-Origin-Opener-Policy (COOP) controls top-level opener relationships and browsing context group switches. Cross-Origin-Embedder-Policy (COEP) constrains the cross-origin resources a document and its descendants may load. Used together in the configuration required for isolation, they establish a browser-enforced boundary that is broader than the same-origin policy alone.

Cybersecurity 19 Sep 2026 7 min read

Certificate Transparency Makes Certificate Issuance Auditable, Not Automatically Safe

Certificate Transparency Makes Certificate Issuance Auditable, Not Automatically Safe A publicly trusted certificate can be syntactically valid, chain to a trusted root, and still represent issuance that a domain operator did not expect. Certificate Transparency (CT) addresses that visibility gap by placing certificate issuance into publicly auditable append-only logs. The mechanism changes the observability of the Web PKI; it does not turn a logged certificate into proof that every issuance decision was correct.

Cybersecurity 18 Sep 2026 6 min read

UNIX Socket Peer Credentials Bind Local IPC to Kernel-Observed Identity

A privileged local daemon accepts a request over an AF_UNIX socket and needs to decide whether the sender may perform an operation. Trusting a UID, PID, or account name encoded inside the request merely trusts data supplied by the client. Linux provides a different identity channel: the kernel can expose credentials associated with the peer or with an individual message. SO_PEERCRED and SCM_CREDENTIALS both carry a struct ucred, but they describe different moments in an IPC relationship. Treating them as interchangeable can turn a sound local authorization boundary into a stale-identity assumption.

Cybersecurity 18 Sep 2026 7 min read

Seccomp User Notification Moves Selected System Calls Behind a Supervisor Decision

A sandboxed process may need an operation that cannot be represented safely as a permanent seccomp allow rule. The operation can depend on runtime policy, external state, or a resource that only a more privileged component should inspect. Allowing the system call unconditionally widens the sandbox, while rejecting it removes required functionality. Linux seccomp user notification provides a mediation point for this case. A seccomp filter can return SECCOMP_RET_USER_NOTIF for selected calls. The kernel then blocks the triggering task and emits a notification through a listener file descriptor. A supervisor reads that notification and sends a response that determines the immediate disposition of the intercepted call.

Cybersecurity 18 Sep 2026 5 min read

Seccomp User Notification Delegates Syscall Execution Across a Privilege Boundary

A confined process can reach a syscall that the kernel would reject under its current credentials, while a separate supervisor has enough privilege to perform an equivalent operation safely on its behalf. Linux seccomp user notification creates a mediation channel for that arrangement: a filter can stop the calling thread, emit a notification to a listener, and wait for a userspace response. That mechanism is more precise than treating the supervisor as a general syscall proxy. The notification carries register-level syscall data and an identifier tied to the pending request. The supervisor can synthesize a return value, inject a file descriptor, or in selected cases tell the kernel to continue the original syscall. Each option places the trust boundary in a different location.

Cybersecurity 18 Sep 2026 6 min read

process_vm_readv Crosses Process Memory Behind ptrace Access Checks

A diagnostic agent may need bytes from another process without stopping that process or attaching a traditional debugger. Linux process_vm_readv() provides that data path: the caller supplies local buffers and address ranges in a target process, and the kernel transfers bytes between the two address spaces. The interface is powerful because the target does not explicitly send the data. Its security boundary therefore sits outside the target’s application protocol. Linux gates the operation with a ptrace access-mode check, while the memory transfer itself remains subject to the target’s changing virtual-memory layout.

Cybersecurity 18 Sep 2026 5 min read

PR_SET_DUMPABLE Changes Linux Process Inspection Boundaries

A service receives credentials into process memory, drops privileges, and continues running under an ordinary account. Another same-account process may still be able to inspect it through interfaces intended for debugging. Linux places an additional process attribute, commonly called dumpable, into several of these access decisions. prctl(PR_SET_DUMPABLE, 0) marks the calling process non-dumpable. The effect is broader than suppressing a core file: Linux also incorporates dumpable state into ptrace access checks and changes ownership behavior for files under /proc/<pid>. These effects form related boundaries, but they are not a single universal ban on process observation.

Cybersecurity 18 Sep 2026 6 min read

pidfds Bind Process Operations to Stable Kernel References

A supervisor records PID 4127, performs unrelated work, then sends a signal to 4127. Between those steps, the original process can exit and the kernel can eventually assign the same numeric PID to another process. The integer still names a process, but not necessarily the process that the supervisor intended to affect. Linux PID file descriptors, commonly called pidfds, move that boundary from repeated numeric lookup to a file descriptor that refers to a particular task. That change is narrow but security-relevant: operations that accept a pidfd can stay bound to the task selected when the reference was acquired rather than resolving a reusable number again.

Cybersecurity 18 Sep 2026 6 min read

Pidfd Process References Separate Identity from Numeric PIDs

A supervisor records a worker PID, performs unrelated work, then sends a signal to that number. If the original worker exited and the kernel reused its numeric PID, a later operation can address a different process. The number identifies an entry in a PID namespace at a moment in time; it is not, by itself, a durable process handle. Linux pidfds add a file-descriptor representation of process identity. A pidfd obtained for a process continues to refer to that process rather than being retargeted when its numeric PID is recycled. This changes the identity boundary for supervision, but it does not grant broad authority over the referenced process.

Cybersecurity 18 Sep 2026 7 min read

OverlayFS Stashed Credentials Separate Overlay Access from Backing Filesystem Access

OverlayFS Stashed Credentials Separate Overlay Access from Backing Filesystem Access A process opens a path through an OverlayFS mount and appears to access one ordinary filesystem object. The kernel may actually consult an upper layer, a lower layer, or both, and a write can trigger copy-up before the requested operation proceeds. That indirection creates an authorization problem: the caller must be permitted to use the object as exposed by the overlay, while the internal access to the backing filesystems must also run under a defined security identity.

Cybersecurity 18 Sep 2026 5 min read

openat2 Resolution Flags Constrain Path Traversal at the Kernel Boundary

A service can validate a pathname and still open a different object if the namespace changes between validation and use. Symbolic links, mount topology, rename operations, and special procfs links make pathname resolution a kernel operation with state that can change concurrently. Linux openat2() addresses part of this boundary by attaching resolution constraints to the lookup that produces the file descriptor. The security property is narrower than generic path sanitization. openat2() does not declare a pathname safe. It lets a caller ask the kernel to reject specific resolution behavior while the kernel performs the walk.

Cybersecurity 18 Sep 2026 6 min read

openat2 Makes Path Resolution an Explicit Security Boundary

A privileged service may accept a relative pathname from a less trusted component while intending to access only files below a designated directory. Checking the string for .., rejecting an initial slash, or inspecting symbolic links before a later open() does not bind the check to the kernel lookup that acquires the file. Directory entries can change between operations, symbolic links can redirect traversal, and mount topology can alter the namespace reached by a path.

Cybersecurity 18 Sep 2026 6 min read

Mount Propagation Defines the Filesystem Boundary Between Linux Mount Namespaces

A process can enter a new Linux mount namespace and still observe a later mount created elsewhere. The namespace boundary is intact: the process has its own mount table. The new mount appears because some mounts in the two namespaces remain connected by propagation relationships. This distinction matters in container runtimes, service sandboxes, build systems, and privileged helpers. Creating a mount namespace separates the namespace’s view of the mount table, but it does not by itself make every future mount event local. Shared-subtree state determines whether mount and unmount events cross that boundary.

Cybersecurity 18 Sep 2026 4 min read

Memfd Seals Turn Mutable Anonymous Files into Explicit Handoff Objects

A process prepares a binary payload in memory, passes a file descriptor to another process, and expects the bytes to remain stable after validation. A plain descriptor does not create that guarantee. If some holder still has write authority, the object can change after a consumer has inspected it, and pathname permissions offer no useful boundary when the object has no ordinary filesystem name. Linux memfd_create() provides an anonymous file backed by memory-like filesystem storage, and file seals can constrain later changes to that file. The useful security property is not anonymity by itself. It is the ability to construct a mutable object, apply irreversible restrictions to that object, then hand out descriptors whose backing file can no longer be changed in the prohibited ways.

Cybersecurity 18 Sep 2026 6 min read

memfd File Seals Turn Shared Memory into a Kernel-Enforced Mutation Boundary

A broker can allocate a memory-backed object, populate it, and pass its file descriptor to another process over a UNIX domain socket. The receiver may treat the bytes as immutable configuration, compiled code, or a serialized artifact. That assumption is unsafe if the sender or another holder can still alter the same inode after validation. Linux memfd_create() and file seals provide a kernel-enforced way to narrow that mutation surface without assigning the object a persistent filesystem pathname.

Cybersecurity 18 Sep 2026 5 min read

MADV_DONTDUMP Excludes Selected Memory Mappings from Linux Core Images

A long-running service may keep credentials, session material, or decrypted state in memory while still relying on core images for crash diagnosis. Disabling core generation for the entire process removes diagnostic state along with sensitive state. Linux provides a narrower control: madvise() with MADV_DONTDUMP marks selected mappings so the kernel omits them from a core image. This mechanism changes core-dump inclusion policy for an address range. It does not make the bytes inaccessible to the process, encrypt them, erase them, or create a general barrier against process inspection. Its security value is specific to one data-exposure path: memory captured through the kernel core-dump mechanism.

Cybersecurity 18 Sep 2026 6 min read

Landlock Rulesets Add a Process-Scoped Filesystem Access Boundary

A service can begin with ordinary filesystem permissions that are broader than the files it needs during steady-state operation. Changing ownership or mount topology may be impractical because the same host resources are shared with other processes. Linux Landlock addresses this gap by letting a process add a kernel-enforced access restriction to itself and, through inheritance, to descendants. Landlock is a Linux Security Module designed for sandboxing. Its rules do not grant filesystem access that DAC, ACLs, capabilities, or another security mechanism would otherwise deny. They add another authorization layer. An operation succeeds only when the other applicable controls and the Landlock policy permit it.

Cybersecurity 18 Sep 2026 7 min read

Landlock Adds a Process-Local Restriction Layer to Linux Access Control

A service may start with every filesystem permission granted to its Unix identity, yet only need a small subset after initialization. Changing the service account or mount topology can reduce that authority, but both are deployment-wide decisions. Linux Landlock provides a different boundary: a process can add restrictions to itself and its descendants without receiving privilege to grant new access. Landlock is a stackable Linux Security Module. Its rules are additional constraints, not replacements for discretionary access control, capabilities, or other active LSM policy. A Landlock rule cannot turn a denied operation into an allowed one. It can only remove authority that the process would otherwise possess.

Cybersecurity 18 Sep 2026 6 min read

io_uring Restrictions Freeze an Allowed Operation Surface Before Ring Activation

A service can expose an io_uring instance to code that should perform only a narrow class of asynchronous operations. The ring itself, however, supports many submission opcodes and registration commands. Relying only on application code to avoid unwanted operations leaves the allowed surface as a convention rather than a kernel-enforced property. Linux provides a tighter mechanism through IORING_REGISTER_RESTRICTIONS. A ring created with IORING_SETUP_R_DISABLED can receive a restriction set before it becomes usable for submissions. The process then enables the ring with IORING_REGISTER_ENABLE_RINGS. From that point, the kernel evaluates operations against the registered restrictions.

Cybersecurity 18 Sep 2026 4 min read

Idmapped Mounts Remap File Ownership Without Rewriting Inodes

Idmapped Mounts Remap File Ownership Without Rewriting Inodes A container needs read-write access to a directory whose files carry host ownership values that do not line up with the container’s user namespace. Recursively changing ownership can make the directory usable, but it also mutates persistent inode metadata and can disrupt every other view of the same filesystem. Linux idmapped mounts provide a narrower mechanism: one mount can apply a different identity mapping while the stored ownership remains intact.

Cybersecurity 18 Sep 2026 7 min read

fs-verity Binds File Reads to a Merkle Tree Digest

A package manager can place an executable on a writable filesystem, close it, and later expect every byte returned from that file to match a previously approved object. Ordinary permissions can stop cooperative writers, but they do not turn file contents into a cryptographically identified object. Linux fs-verity supplies that narrower property for individual files: after verity is enabled, file data becomes read-only and reads are checked against a Merkle tree rooted in a stable file digest.

Cybersecurity 18 Sep 2026 6 min read

Fanotify Permission Events Put File Access Behind a Userspace Decision

A process calls execve() for a binary on a monitored filesystem, but the kernel does not immediately complete the execution open. A fanotify group has requested FAN_OPEN_EXEC_PERM, so the access waits while a userspace listener receives an event and returns FAN_ALLOW or FAN_DENY. The mechanism inserts a synchronous userspace decision into a filesystem operation that would otherwise proceed after ordinary kernel permission checks. That interception point is useful for policy engines that need information outside normal inode permissions, but it creates a distinct enforcement boundary. Availability now depends on a userspace responder, event coverage depends on the selected fanotify marks and event classes, and the mechanism does not convert every form of file use into a mediated operation.

Cybersecurity 18 Sep 2026 6 min read

close_range Narrows File Descriptor Inheritance Before exec

A service process can accumulate sockets, pipes, directory handles, log files, and control descriptors long before it launches a helper. If those descriptors survive into the new program, the helper receives capabilities that its command-line arguments and environment do not reveal. A connected socket can carry authenticated access; an open directory can preserve reachability to a filesystem location; a pipe can expose another component’s data path. Linux close_range() gives pre-exec code a range operation over file descriptors. Its security value is not that descriptors become harmless. It is that a process can narrow the descriptor set that crosses an execve() boundary without enumerating /proc/self/fd or issuing one close() call per candidate descriptor.