3 ms·
Because the goal was to make an API that works the same both inside the sandbox and outside the sandbox. Edit: It wouldn't work with just processes and namespac
by BrightGlow 5y ago
Because the goal was to make an API that works the same both inside the sandbox and outside the sandbox. Edit: It wouldn't work with just processes and namespaces because you need a way to talk to a resource with a privilege level above the current mount namespace.
- Cloudef 5y agoRight, the child process can't escape the sandbox. I guess IPC here is the only sane choice.