4 ms·
Meh I don’t consider it bad. It’s in FreeBSD. You want it? Run FreeBSD. Waiting for Linux to implement their “version” of capsicum, poorly, Might be a while. Pl
by X86BSD 9y ago
Meh I don’t consider it bad. It’s in FreeBSD. You want it? Run FreeBSD. Waiting for Linux to implement their “version” of capsicum, poorly, Might be a while. Plus you have other great tech like CloudABI in FreeBSD as well which makes it even more compelling.
- 2trill2spill 9y agoIt would be wonderful for FreeBSD as well as Linux if both operating systems supported capsicum. It would mean that both would have the same sandboxing API. Which would make it more likely for application authors to use capsicum, which in turn increases the amount of applications using it. Also why do you assume Linux's implementation would be poor? there's nothing to indicate that it is. Also capsicum is already implemented for Linux and has been for a couple years, it's just not in Linus's tree[1]. [1]: https://github.com/google/capsicum-linux https://github.com/google/capsicum-linux
- X86BSD 9y agoBecause almost every thing that Linux implements is poorly done. Let’s take the subject at hand. Containers. They never created containers. Instead they came up with docker. And never designed it to be secure. Hence all these efforts to figure out how to secure docker. They keep trying to retroactively bolt security on. Which is never going to secure it. Eventually someone’s going to have to throw it out and redo it with the initial goal of making it secure. When it should have been designed secure as the main feature. Like Zones or Jails were. Also for sand boxing apps you really should look at CloudABI. Ed has put a ton of work into it. The last time I looked at capsicum for Linux it wasn’t complete. That’s changed?