Posted by Solar Designer on Apr 20

Thank you. So with my idea/proposal, someone using these tools on a
desktop system would need to set the max depth to 1. That would leave
the kernel’s full attack surface exposed on the host system, but not to
sandboxed programs because those would run with capabilities already
relinquished (per what you write above) and would not be able to regain
them by creating a nested namespace. Sounds like a worthwhile feature?

Does bubblewrap
