Plus, you have various [LSM]s as a safety net. Android was an early adopter of SELinux, and latest releases still use it.
I distinctly remember ad companies using various tricks like reading /proc and the like to try and get information about what applications are running on a phone and what servers they are communicating with without asking for perms (it's fixed now, but it used to be a thing years ago). This is the kind of stuff that fuchsia should, in theory, prevent.
Refer to Genode Handbook for a decent definition and examples.
seL4 is formally proven to enforce capabilities.
Genode is, and should be reasonably easy to test on a regular PC, via bootable usb stick.
It can be quite confusing to use at first, as capabilities have GUI representation.
There's a blog[0] and some introductory video[1].
Can it be forced to?
> it loses all permissions normally associated with its controlling user, with the exception of "capabilities" it already has in the form of file descriptors.
What if we want to grant an app already running a new capability on the fly? E.g. I imagine a case of user opening a file in a GUI app as an OS-level file selection dialog getting invoked (provided the app already has a capability to invoke it, as by the manifest) and producing a capability for the app to access the file the user choosse in an explicitly specified (RO or R/W) mode.