Capability-based sandboxing library using Landlock (Linux) and Seatbelt (macOS).
copied from cf-post-staging / nononono provides OS-enforced sandboxing where unauthorized operations are structurally impossible. Once a sandbox is applied, there is no API to expand permissions - the kernel enforces all restrictions.