bubble wrap is just doing the same cgroups work
Depending on the configuration, bubblewrap can substantially reduce the attack surface.
It doesn’t change the fact a malicious process is still attacking the same kernel , but it can reduce what it can do to that vm.
Depending on the configuration, bubblewrap can substantially reduce the attack surface.
It doesn’t change the fact a malicious process is still attacking the same kernel , but it can reduce what it can do to that vm.