Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This will also make a lot of difference once we can run lightweight, userspace kernels ("rump kernels").


> once we can run lightweight, userspace kernels ("rump kernels").

Er, didn't NetBSD accomplish that... like a decade ago, now? Or is FreeBSD looking into supporting rump kernels?


Yes, NetBSD did accomplish that, but I expect it to become more commonplace.


but question is, is this solution for people running software on other peoples computers ? or solution for running my own code on my own computer only ?


Does it matter? Running kernel pieces in userspace is useful in both directions (rather like docker), and in both cases we'd like it to run as quickly as possible.


For my particular case it's about something similar in purpose to sandboxing, but with providing the compartment (ie a process subtree) with an alternative kernel to talk to, to minimise the attack surface between that container and the host kernel.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: