Troubleshooting
Almost every problem is the same problem: the policy is missing something. These are the shapes it takes.
The program does not start at all
bailey: io error: Permission denied (os error 13)Bailey could not exec the target. The target is granted implicitly, so this means a config layer retracted that grant. bailey show <target> prints the denials; bailey also warns up front when the policy denies the target itself.
The program starts and immediately fails
Usually a missing library, config file, or device. Confirm what the policy actually is:
bailey show ./programCheck that the layer you expected is listed. Each is labelled with the walk that found it, target or working dir, which is usually enough to explain a config that did not apply.
Then find out what it wanted:
bailey audit --save-trace trace.json ./programWithout the audit helper installed, strace -f -e trace=file ./program outside the sandbox gives you a rougher version of the same answer.
Landlock is not enforcing
bailey: warning: Landlock is not enforced by this kernelThe kernel has no Landlock support, or it is not enabled. Check:
grep landlock /sys/kernel/security/lsmIf it is absent, Landlock needs to be in the kernel's lsm= list. Bailey still applies seccomp and cgroups, but the filesystem and network policy is not being enforced.
Isolation is skipped
bailey: warning: unprivileged user namespaces unavailable; running without namespace isolationUnprivileged user namespaces are disabled or blocked by a security policy such as AppArmor. The run continues with Landlock and seccomp. To check:
cat /proc/sys/user/max_user_namespaces
sysctl kernel.unprivileged_userns_clone 2>/dev/nullResource limits are skipped
bailey: warning: resource limits not applied: ...There is no writable delegated cgroup v2 for your session. On a systemd system, running inside a user session usually provides one; running from a bare TTY or an unusual init may not.
Relative paths fail under --isolate
cat: ./file.txt: No such file or directoryThe target keeps the directory you invoked it from, but under --isolate that directory only exists inside the sandbox if the policy grants it. Where it does not, the run says so and starts in the private home instead:
bailey: warning: the working directory is not granted, so it is absent under
isolation; starting in /home/you insteadGrant the directory, and the relative path resolves.
The audit helper will not start
bailey: audit helper did not start; it needs CAP_BPF and CAP_PERFMONEither the helper was not built, it is not where bailey looks for it, or it does not have its capabilities. Check each:
ls -l target/release/bailey-bpf-helper
getcap target/release/bailey-bpf-helper
BAILEY_BPF_HELPER=$PWD/target/release/bailey-bpf-helper bailey audit ./programA network rule seems to do nothing
The traffic is probably not TCP. Only TCP connect and bind are restricted; UDP, QUIC, and DNS are not. See known limitations.
A rule with no port no longer fails quietly: it is a resolution error naming the layer.
A deny seems to do nothing
A denial nested inside a granted directory is not enforced. Bailey warns when this applies and marks it NOT ENFORCED in bailey show. Instead of granting a parent and denying a child, grant the specific children you want:
[filesystem]
# Does not protect ~/.ssh:
# read = ["~"]
# deny = ["~/.ssh"]
# Does:
read = ["~/Documents", "~/Downloads"]