3 ms·
I don't think you need a full object-capability security implementation to get the specific file dialog/powerbox pattern you outlined. Windows (in UWP), MacOS a
by contextfree 5y ago
I don't think you need a full object-capability security implementation to get the specific file dialog/powerbox pattern you outlined. Windows (in UWP), MacOS and I think Linux all support it, albeit with a more ad hoc implementation.
- johnnyapol 5y agoFlatpak achieved this on Linux. There are "portals" which are dispatched and will mount virtual filesystems to permit access to specific files selected by the user. These portals typically are provided by the desktop environment as to resemble to look and feel of the user's choice. There's no kernel-level interface as the OP was alluding to but by combining several other kernel interfaces we can get this kind of sandboxing.