|
|
|
|
|
by ori_b
3488 days ago
|
|
Even better, in my opinion, is that many of the caps that you would use to sandbox an app (like PID and FS namespaces) require you to have the sysadmin capability set on the process. Great. You need to give a process more or less root so that it can deny itself privileges. |
|