Did the BSD jails provide enough isolation? Would memory from a process truly be isolated from another? How about FD’s?
Could there be side channel attacks? At what level?
Perhaps the whole kernel design needs to be revisited, which I assume is what’s being taken on by Fuchsia.