Walsh: Cool things with SELinux... Introducing sandbox -X
Walsh: Cool things with SELinux... Introducing sandbox -X
Posted Sep 17, 2009 21:05 UTC (Thu) by martinfick (subscriber, #4455)Parent article: Walsh: Cool things with SELinux... Introducing sandbox -X
After all, why not have each real user confined to their own linux container where they have root privileges? Constraint the container appropriately so that a real user has no more power on the host system with this root ability than a real user would today. Within each container, a user would run apps (or categories of apps) as different users with different abilities and additional sandboxing mechanisms. This would give real users access to all the root level sysadmin tools to create sandboxes with standard linux tools instead of creating new ones for regular (non sysadmin) users.
