immersive.ex...@gmail.com writes: > Thanks! > > So it sounds like you're saying selinux is the only meaningful thing to try? > Or do people ever bother to place qemu in chroot jails?? > > I seem to have gotten the impression that people use qemu-static to do this, > but it appears to be more for offering secured access of a guest folder > to the host OS;
The qemu-static + chroot approach is mainly to avoid doing complex path manipulation between host/guest file-systems AFAICT. > not so much for security... > <snip> -- Alex Bennée