<Foxboron> gchristensen: that is a very nice list honestly
<andi-> very nice list, yet another time I am reminded of our lack of apparmor/selinux/… profiles :/
<gchristensen> :)
<gchristensen> we will always be imperfect it is the state of the w orld
<ckauhaus> vulnix-1.8.0 is out
<ckauhaus> contains a few bug fixes and builds on master
<ckauhaus> preparing a PR to update vulnix on master
<pie___> \o/
<andi-> in case someone wants to read a nice recap of the runc/proc/self/exe issue. LWN published an article on it:
<ckauhaus> is there anything we can do to mitigate this problem on behalf of NixOS?
<andi-> there is no problem for us since the binary is read-only
<andi-> I have a PoC (Actually two versions) here that closely follows either of the linked apporaches and fail to exploit the issue on my NixOS machiens.
<ckauhaus> :-)
<andi-> i believe graham also did some testing and came to the same conclusion.
<pie____> are contianers basically a theoretically worse microkernels
<pie____> *containers
<MichaelRaskin> Just no
<MichaelRaskin> FUSE/CUSE seems somewhat closer to microkernelisation
<ckauhaus> MichaelRaskin: thanks for merging btw
<ckauhaus> Quite a bit of stuff this time - I've started to include 19.03
