| ▲ | corv 12 hours ago | |||||||
I happen to use a Mac, even when targeting Linux so I'd have to use a container or VM anyways. It's nice how lightweight bubblewrap would be however. Consider one wanted to replicate the human-approval workflow that most agent harnesses offer. It's not obvious to me how that could be accomplished by dropping privileges without an escape hatch. | ||||||||
| ▲ | kernc 12 hours ago | parent [-] | |||||||
It being deprecated and all, didn't feel like wrapping it, but macOS supposedly has a similar `sandbox-exec` command ... | ||||||||
| ||||||||