Re: [PATCH v1 0/8] x86_64 SandBox Mode arch hooks

From: H. Peter Anvin
Date: Wed Feb 14 2024 - 10:32:28 EST


On February 14, 2024 6:52:53 AM PST, Dave Hansen <dave.hansen@xxxxxxxxx> wrote:
>On 2/14/24 03:35, Petr Tesarik wrote:
>> This patch series implements x86_64 arch hooks for the generic SandBox
>> Mode infrastructure.
>
>I think I'm missing a bit of context here. What does one _do_ with
>SandBox Mode? Why is it useful?

Seriously. On the surface it looks like a really bad idea – basically an ad hoc, *more* privileged version of user shave.