Is there a comparable thing for network access? Last I looked OpenSnitch seemed to be unmaintained, but looking just now it apparently has some commits on master recently again:
Is there a comparable thing for network access? Last I looked OpenSnitch seemed to be unmaintained, but looking just now it apparently has some commits on master recently again:
Works fine enough for untrusted non-gui SW, and trusted GUI SW, that I know will not try to hack my PC, but apps running inside it may be able to access stuff I don't want them to on my network (like Firefox).
cgroups may also work well for this without the need to use multiple UNIX users.
1. That the shell's user is "in" a location of the filesystem (cwd), and can move around it like you're an avatar navigating rooms.
2. That the shell can "only" do program invocation, such that even its basic primitives like 'cd' and '[' can be just themselves programs.
It's heretical, but, I don't think ls ought to be its own program. It's part of the shell, in particular part of my view of the filesystem. It's not really an app and I don't care if it happens to be implemented that way under the hood.
As a user, I want a shell that lets me navigate the system (possibly multiple sets of systems), with a consistent set of primitives. It can let me invoke applications, and I want an absolute and extremely tight set of controls over those applications, and very specific ways that they're allowed to talk to each other.
I'm running far off-topic but to your original point, I think "ls" isn't really the type of app we ought to be talking about here, just bake it into the shell...... ok I just want to abandon posix and work in new metaphors. That really is off-topic for discussions about a new Linux feature I guess.
"cd" is one of a few commands that basically must be built-ins no matter what, since it has to modify the environment of the shell itself. Any external command can only modify its own environment, not the shell's environment.