i think linux needs to have the ability to deny a program access to specific files or devices without resorting to containers or something