@navi @GrapheneOS @lumi i'm working on bootstrapping build and packaging logic atm and sandboxing mechanisms like unshare paired with virtualization like overlayfs is a tool that enables surgical precision in constructing dependency graphs that don't make overly broad assumptions about the user environment, enabled by crafting OS interfaces to model the trust and access specific to my application context.