5 ms·
> but for some reason it doesn't seem like the right approach. The approach being used in containerization is namespaces. You can put new processes into a new
by CyberShadow 5y ago
> but for some reason it doesn't seem like the right approach.
The approach being used in containerization is namespaces. You can put new processes into a new IPC / user / PID / network / time / etc. namespace, which isolates them from the parent namespace. Once that's done and you can't mess with other processes via the filesystem / kernel, the remaining hole is servers with inadequate security models, such as X11.
- AshamedCaptain 5y agoWhat I mean is that if you are going to put your processes as a different user anyway (or a different user namespace), trying to break all the features that allow a user to manage same UID processes is unnecessary.