Hacker News new | ask | show | jobs
by josephcsible 1416 days ago
> a bad actor build script could technically mount the root directory `/` underneath the sandbox area in /<sandbox>/rootdir/` using Linux's bind mounts feature

How could you do this without already being outside of the sandbox?