Sorry, not disabling SIP for something that I can already do without needing to nobble security policies (and have them reset/impossible due to MDM). If there was user/networking space in Darwin then maybe I'd be interested but...
> something that I can already do I would be very curious as to how you already run darwin containers. The only alternative is spinning a macOS VM (including relying on macOS CI machines as a remote job executor)
Something like namespaces or proper jails on darwin would be super cool, but not at the expense of other security measures and chroot-ish outcome imho. Maybe this works for some, but not me :)