I wish every OS user logged in their isolated VM of the OS. This way, Adobe could install all their bloatware and take control of their user and I could keep ownership of my Apple’s computer
We were so close. Sigh.
The fact that VMs are necessary has shown how much OSes have failed. That we need to take an OS and package it into multiple VMs to get any real isolation is a problem that OSes should solve for.
The fact that VMs exist at all shows how much OSes have succeeded.
Systemd did the cgroups thing right. Apart from the v1/v2 thing, but if you can use only v2 then you do not need to think about it.
Containers would be a more appropriate solution, and even containers would be somewhat overkill. Simply using UNIX-style permissions and an application-specific UID could do. I think it is how it is done in Android.
That's a funny slip...