clean and well-defined expansion (beware of per-test re-expansion)
configurable names of in/out files (independent of $PROBLEM)
paranoidly check file mode/owner before running the sandbox
+
+Isolate
+~~~~~~~
+Make the list of bind-mounts configurable (some of them even read-only)
+Virtual /dev
+Installation
+Test: ptrace self
+Test: SIGSTOP
+Test: ping-pong timing attacks
+Test: big static memory
+Doc: avoid AS randomization
+Doc: avoid cpufreq