Hacker News new | ask | show | jobs
by zokier 502 days ago
systemd-run inherits afaik all the extensive sandboxing features from systemd

https://www.freedesktop.org/software/systemd/man/latest/syst...

https://www.freedesktop.org/software/systemd/man/latest/syst...

sure, the command line get bit verbose but nothing that an alias or small wrapper couldn't solve

the big problem is that modern operating systems have huge surface area and applications tend to expect all sorts of things, so figuring out what you need to allow is often non-trivial