Skip to content

Latest commit

 

History

History
47 lines (35 loc) · 2.7 KB

06-sandboxing.md

File metadata and controls

47 lines (35 loc) · 2.7 KB

Sandboxing

The original intent was to have bramble be rootless. I think this is still an admirable goal, but in the immediate term it conflicts with some security issues.

The module import and command running syntax will allow this:

bramble run github.com/maxmcd/unsafe/virus:inject

If bramble is going to have this level of flexibility it should be sandboxed by default.

Links and ideas

Linux

Runc