16 ms·
From what I can see a process running in that "sandbox" would happily write to a file descriptor passed into it... Like other posters in that thread I am very
by Rondom 10y ago
From what I can see a process running in that "sandbox" would happily write to a file descriptor passed into it...
Like other posters in that thread I am very skeptical that this approach can be made secure and running with acceptable performance (given there are other more practical approaches to restrict processes available (namespaces, seccomp, SELinux...).