I want to run some plugins as separate processes in a sandbox, and I'm hoping for a cross-platform solution (or rather, Windows and Linux). Trying to adapt NaCl seems overkill and a huge amount of work and I'm not working on a browser anyway, yet other solutions I've seen seem to only be for Linux (specifically, <a href="">Vx32</a>). Windows' security tokens and mandatory integrity levels doesn't seem to be very fine-grained, as I want a security model of granting access to a whitelist of system calls and blocking or redirecting all others. Same thing with SE Linux which also has the disadvantage of being setup by a system admin rather than programmatically.

