> the ability to start a program with restricted access to files, network or OS calls (on Windows and on Linux)
Bubblewrap allows you to do that on Linux.