Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

or like bsds pledge


This is on a different level than pledge. pledge applies to the whole process. This sandboxing, as far as I understand, would restrict syscall access to individual functions and modules inside a process.


Can pledge apply to child/sub-processes only?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: