might be interesting: a new process isolation method was just merged into the #linux kernel, landlock, that does not itself need special permissions to use, and has object instead of syscall granularity
@vertigo @cjd @orionwl <snark>I see Linux is finally catching up to where FreeBSD was nearly a decade ago w.r.t. OCAP. And as usual the Linux version is far more complicated and will probably be riddled with security holes due to the much larger attack surface.</snark>
(The snark tags mean you can't argue with me.)
The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!