I had Firefox, Thunderbird, Pidgin and a few others running in complete isolation from the base system, and from each other. I even had a separate Firefox jail that was only allowed to get out via a Tor socks proxy to avoid leaks (more of an experiment than a necessity, to be fair).
Communication between jails was done via commonly mounted nullfs. I have also setup QoS via PF for each of them.
They were all running on the host’s Xorg, which was probably also the weakness of this setup.
It was a pretty sweet setup, but required quite a bit of effort to maintain, even tho I automated most of the stuff.
Now I use macOS, and I would like more control over what apps do what. I’m not particularly impressed with the direction of the UI (it also doesn’t bother me terribly), but I welcome the finer grained security control.
References:
[0]: https://en.wikipedia.org/wiki/FreeBSD_jail
[1]: https://www.freebsd.org/cgi/man.cgi?query=jail&sektion=8&for...