Hacker News new | ask | show | jobs
by westurner 121 days ago
> on the Component Model side when we get there. Your syscall isolation work + our semantic policy layer seem pretty complementary.

I've hardly done any syscall isolation work. Though I have long wondered whether a userspace runtime/VM can ever be an effective sandbox.

Sure. What about the Component Model?