linneman
labs
building
breaking
observing
content
···
verified
home
/ systemd
Systemd
2026.08.12
Confined Root Is Still Root
A compromised root daemon can’t change its own SELinux domain. It doesn’t need to - it recruits something already unconfined.
2026.07.20
Measuring the Blast Radius of a Root Daemon
The real confinement of a root daemon is the intersection of SELinux policy, systemd sandboxing, Linux capabilities, and DAC.