Landlock sandbox: kernel file limits for agents

A Landlock sandbox uses the Linux kernel's Landlock module to limit which files a process can reach; DevFlow applies one to agent CLI runs, with write access in only 5 places.

What Landlock is

Landlock is a Linux security module that lets an unprivileged process restrict its own access to the file system. The process builds a ruleset of paths it may read or write and applies it to itself. From then on the kernel refuses everything outside that set, for the process and for every child it starts.

How DevFlow applies it

DevFlow does not modify the coding CLI. Before each run it re-executes its own binary with a hidden subcommand that receives the allowed paths, applies the ruleset and then replaces itself with the CLI.

The process keeps the same PID and pipes, so output streaming, timeouts and cancellation behave exactly as they would without a sandbox.

The policy

Each run gets a fresh policy built from its worktree path:

  • writable: the task worktree, the main repository's .git (a linked worktree writes its commits there), $HOME, /tmp and /dev;
  • read-only: toolchains such as /usr, /go and /etc;
  • invisible: everything else, including the worktrees of other tasks, the application folder and the main repository's working tree.

A multi-repository task that uses symlinked folders has those links resolved to real paths before the rules are built. Writable folders also allow renames across directories, which git needs for its temporary object and ref files, and terminal control calls on /dev.

Which runs it covers

The Claude Code backend runs under this sandbox. OpenCode runs under it too, unless the operator turns on agent containers, which replace the re-exec step for OpenCode with a per-run Docker container.

How it fits with the other layers

The sandbox limits files only. Agent containers add dropped Linux capabilities, resource caps and an internal network whose only way out is the egress proxy, which decides which hosts a run may reach.

The environment of every coding run is built from an allowlist as well, so server secrets never reach the sandboxed process, whatever paths it can read.

FAQ

Which paths are read-only under DevFlow's Landlock sandbox?

DevFlow's Landlock sandbox gives agent CLI runs read and execute access, without write access, to toolchain and system folders such as /usr, /bin, /lib, /etc, /opt and /go, and to the folder holding a task's planning attachments.

Does the DevFlow task chat run under the Landlock sandbox?

Yes, except for OpenCode runs when agent containers are on. Under Landlock, the DevFlow task chat gets a stricter policy: DevFlow makes the worktree and its git data read-only, except the worktree's .opencode folder, which OpenCode writes at startup; /tmp, /dev and, unless it contains the worktree, $HOME stay writable.