|
|
|
|
|
by kjok
72 days ago
|
|
> There are dozens of projects like this emerging right now. They all share the same challenge: establishing credibility. Care to elaborate on the kind of "credibility" to be established here? All these bazillion sandboxing tools use the same underlying frameworks for isolation (e.g., ebpf, landlock, VMs, cgroups, namespaces) that are already credible. |
|
Most people are building on top of Apple's sandbox-exec which is itself almost entirely undocumented!