Its reasuring, knowing that any potentially spawned process is also sandboxed to the same environment and while it doesn’t isolate (in terms of e.g. Docker) it does contain it to less risky (with correct set up) part of the system.
A big bonus to it, is that it provides basic profile versions for the whole plethora of programs which can be simply expanded/adjusted with custom user profile.
Its reasuring, knowing that any potentially spawned process is also sandboxed to the same environment and while it doesn’t isolate (in terms of e.g. Docker) it does contain it to less risky (with correct set up) part of the system.
A big bonus to it, is that it provides basic profile versions for the whole plethora of programs which can be simply expanded/adjusted with custom user profile.