Meeting Minutes, November 8, 2025
Here is the quick recap of what happend in Ilugc Monthly meet, Nov 8, 2025.
Intro
- Mohan welcomed participants
- Participants introduced themselves
Talk 0
- Mohan started explaining about process isolation
- Explained how file system isolation of a process traditionally achieved through
chrootfor long time in Unix based systems - Explained how modern linux have more types of process isolation including file system isolation using
namespaces - Explained different container systems like
lxc,systemd-nspawn,dockerandpodman - Showed that container images are nothing but
root file systempacked in a particular way - Explained what is
scratch containersand demonstrated how it can be used to reduce the container image

Talk 1
- Nihaal started explaining about basic security in Linux
- Explained how
Discretionary Access Control (DAC)traditionally used to protect files and directories in Unix based systems - Explained
Permission bitsin DAC and explained the drawbacks in DAC - Introduced audiance to
Mandatory Access Control (MAC)Policies and different way to implement MAC usingSecurity ModuleslikeAppArmor,Selinux - Explained about
AppArmorand how security gets implemented through itssecurity profile files - Explained about
SELinuxand how security get implemented throughsecurity context labelsusing file system’sextended attributes (xattrs)

After talks discussion
- More participants introduced themselves
- Mohan provided popular FOSS news from the last week
- Participants had lively discussion about
Debian apt Rust dependency,Archinstall script,gaming on linux,Gnome's Xorg decommissionetc. - Took group photo
- Windup
