#freebsd #sandbox #capsicum

sys casper-sys

FFI bindings for FreeBSD's libcasper

2 releases

0.1.1 Aug 7, 2023
0.1.0 Feb 16, 2023

#4 in #free-bsd

Download history 26/week @ 2024-03-11 16/week @ 2024-03-18 27/week @ 2024-03-25 58/week @ 2024-04-01 22/week @ 2024-04-08 13/week @ 2024-04-15 23/week @ 2024-04-22 9/week @ 2024-04-29 8/week @ 2024-05-06 12/week @ 2024-05-13 40/week @ 2024-05-20 8/week @ 2024-05-27 48/week @ 2024-06-03 7/week @ 2024-06-10 21/week @ 2024-06-17 15/week @ 2024-06-24

91 downloads per month
Used in 4 crates (2 directly)

MPL-2.0 license

110 lines


Current Version

Contain the awesome!

Rust bindings for the FreeBSD capsicum framework for OS capability and sandboxing


Rust, Cargo, and FreeBSD.

Note: This currently only compiles on FreeBSD

Getting Started

Get the code

git clone https://github.com/danlrobertson/capsicum-rs
cd capsicum-rs
cargo build

Writing code using capsicum-rs

Entering capability mode

    use capsicum::{enter, sandboxed};
    use std::fs::File;
    use std::io::Read;

    let mut ok_file = File::open("/tmp/foo").unwrap();
    let mut s = String::new();

    enter().expect("enter failed!");
    assert!(sandboxed(), "application is not sandboxed!");

    match File::create("/tmp/cant_touch_this") {
        Ok(_) => panic!("application is not properly sandboxed!"),
        Err(e) => println!("properly sandboxed: {:?}", e)

    match ok_file.read_to_string(&mut s) {
        Ok(_) => println!("This is okay since we opened the descriptor before sandboxing"),
        Err(_) => panic!("application is not properly sandboxed!")

Limit capability rights to files

    use capsicum::{CapRights, Right, RightsBuilder};
    use std::fs::File;
    use std::io::Read;

    let x = rand::random::<bool>();
    let mut ok_file = File::open("/tmp/foo").unwrap();
    let mut s = String::new();
    let mut builder = RightsBuilder::new(Right::Seek);
    if x {

    let rights = builder.finalize().unwrap();

    match ok_file.read_to_string(&mut s) {
        Ok(_) if x => println!("Allowed reading: x = {} ", x),
        Err(_) if !x => println!("Did not allow reading: x = {}", x),
        _ => panic!("Not properly sandboxed"),


~37K SLoC