Conversation
Notices
-
clacke: inhibited exhausted pixie dream boy πΈπͺππ°ππ (clacke@libranet.de)'s status on Sunday, 07-Jul-2019 01:27:26 EDT clacke: inhibited exhausted pixie dream boy πΈπͺππ°ππ > NetBSD allows transparently mounting an untrusted file system image by running the kernel driver in a rump kernel in userspace. The driver is thus isolated and any damage that a malicious file system image can directly cause is restricted to a userspace process. From a user perspective, mounting with the -o rump option is the only change required
Wow.
wiki.netbsd.org/rumpkernel/