4 ms·
Shouldn't the OS already do containering with its processes (based on user)? That's kind of the [functional context] approach I take with: https://github.com/m
by onesphere 3y ago
Shouldn't the OS already do containering with its processes (based on user)?
That's kind of the [functional context] approach I take with:
https://github.com/matrixApi/encapsule https://github.com/matrixApi/encapsule
- miohtama 3y agoDesktop and server operating system do not prevent any process to access file system. Any process can effectively steal any work you have on your file system, and also perform malware attacks by encrypting your files. This is not true for mobile operating systems like Android and iOS where processes cannot know about other processes or access file system.
- insanitybit 3y agoThe typical User in linux is pretty unconstrained. They can view a lot of global resources, perform arbitrary system calls, view other processes, other users, etc. It's not really a tight sandbox. That's why Linux offers other, more powerful mechanisms for sandboxing such as namespaces, which are the backbone of containers.