Comment by saagarjha

2 hours ago

Sandboxing something like that is challenging, yes. But probably not for this reason you can always disclaim responsibility for your process.

It really isn't; the program just needs to be able to declare what it expects it should be able to do, and what it expects its children should be able to do. The latter doesn't need to be a subset of the former.

  • That “just” is doing a LOT of work.

    • It's already done on OpenBSD, and linux has the pieces to do it, though it's far more fragile and complicated. I'm not speaking hypothetically here, I've implemented code that works this way.

      1 reply →

  • This is really hard to do in general

    • It's done on the majority of the OpenBSD base system, as well as important ports like Chrome and Firefox. Linux also has the parts to do this, though it's more fragile and complicated.