Sunday, January 11, 2009

Application isolation by packages

Applications only see a virtual filesystem consisting only of themselves and the packages they depend on, as if the user had decided to install a system that had only the minimal functionality to get that application working.

And a nearly empty home directory populated with only the files the user chose to make readable to the application.

No comments :