Comment by jitl

6 days ago

stuff that talks to "the internet" and runs as "root" seems like a good thing to build with filc.

It probably uses OS sandboxing primitives already.

  • In normal operation, apt has to be able to upgrade the kernel, the bootloader, and libc, so it can't usefully be sandboxed except for testing or chroots.