servo/gaol

Unshare network on Linux

Opened this issue · 0 comments

The "fake" root user inside the new namespace can configure interfaces and set up iptables.

See also what Sandstorm does to route all network traffic inside the sandbox through a broker. This would be a cool capability in Servo, although it's probably not something we want by default.