Quote: the jail model substitutes namespace limits for security labels; semi-permeable partitioning of files, processes, and network; no super-user privileges; simple and efficient
[FreeBSD's] Jail offers semi-permeable partitioning of the file … inside the jail. … The jail model substitutes namespace limits for the … [efficient] implementation
Google-1Google-2