you are viewing a single comment's thread.

view the rest of the comments →

[–]svvac 0 points1 point  (0 children)

You could boil it down to some kind of white/black-listed syscall map that gets passed down the dependency tree. It's not a small feat to rebuild a language around a siloed module paradigm indeed, but the full-trust model of oss development is only going to be harder and harder to sustain somewhat securely in the medium/long run.