Dan Walsh recently
introduced SELinux sandbox. This is a mechanism for launching untrusted applications from the command line, which uses a strict MAC policy to isolate the executed application from the rest of the system. There's been a good discussion of the topic
LWN, and I thought it might be worth highlighting a few points
(
Read more... )