| ▲ | like_any_other 3 hours ago | |
It's getting so very old - all I want out of a process is code autocomplete, but I have to grant it read & write permission to my entire disk and network. When do we get good permissions and sandboxing and isolation? This can't go on. | ||
| ▲ | nextos 2 hours ago | parent | next [-] | |
I agree granting processes permission to read any file is unsustainable. In Linux, sandboxing with Firejail or bwrap is quite easy to configure and allows fine-grained permissions. Also, the new Landlock LSM and LSM-eBPF are quite promising. | ||
| ▲ | boxedemp 3 hours ago | parent | prev [-] | |
I build my own. Maybe I nee to externalize it... | ||