<ckauhaus>
is there anything we can do to mitigate this problem on behalf of NixOS?
<andi->
there is no problem for us since the binary is read-only
<andi->
I have a PoC (Actually two versions) here that closely follows either of the linked apporaches and fail to exploit the issue on my NixOS machiens.
<ckauhaus>
:-)
<andi->
i believe graham also did some testing and came to the same conclusion.
<pie____>
are contianers basically a theoretically worse microkernels
<pie____>
*containers
<MichaelRaskin>
Just no
<MichaelRaskin>
FUSE/CUSE seems somewhat closer to microkernelisation