Systrace for Mac OS X
Niels Provos writes in that he has added Mac OS X support for Systrace, a sandboxing/application confinement tool that can be used to increase application and service security. It installs a new kernel to support /dev/systrace and the Systrace application, and a Cocoa frontend.
My only qualm is where is this kernel coming from and why is there no other way to run this then with a specially built kernel. Im sorry to say, but I can't just trust anything that replaces my kernel, no matter who it comes from when that person isn't my OS vendor.
Is it impossible to get teh same thing done with a kernel extension?
-"I'm one of those Mac people that will break a bottle on the bar and hold it to your throat for bad-mouthing my system"