It's described in detail here:
* https://wiki.mozilla.org/Security/Sandbox
* http://www.morbo.org/2017/11/linux-sandboxing-improvements-i...