@nixCraft I'm actually really surprised that containers wasn't a response. LXC, and more, Docker. Very useful, but so much drama around them in security discussions. Not saying it isn't warranted...
@nixCraft SELinux depending on the distros defaults. Things randomly not working and you do not know why. Spend hours of troubleshooting and crawling the web. Then it turnes out to be just something as simple as "sudo setsebool selinuxuser_execheap 1" and things are fixed 馃檮
@nixCraft aside from gcc constantly breaking builds with new default behavior, I'd say it's glibc. They cram so much extra functionality into libc.so that it's practically impossible to use any other libc without building an entire runtime with glibc set aside for these programs. If it's not a standardized part of the C library it doesn't belong in libc.so!