> Does Linux have mechanisms to guard against that?
Sure. ulimit or cgroups can.
Sure. ulimit or cgroups can.
But this thread is getting distracted. That's a separate issue, and the applications in question can still pollute all they want within their container.