WSL's Security Boundary: Linux Convenience Is Not a Separate Trust Zone
How Windows interop, mounted drives, networking, and enterprise policy actually shape WSL's threat model, and why it isn't a sandbox for untrusted code.
Conceptual, architectural explainers - how a subsystem actually works underneath.
How Windows interop, mounted drives, networking, and enterprise policy actually shape WSL's threat model, and why it isn't a sandbox for untrusted code.
How the Microsoft Store WSL package decouples updates from full Windows releases, and why that affects available features, policy, and troubleshooting.
Why enabling systemd in WSL does not guarantee daemon permanence, and how services should actually handle WSL's own lifecycle events.
Why WSL cannot expose arbitrary USB devices directly, and how Windows binding, USB/IP transport, and Linux drivers fit together in usbipd-win.
How WSLENV selectively crosses environment variables between Windows and WSL and translates paths without corrupting separators or leaking secrets.
Two genuinely different DOS executable formats, with real structural differences in how each loads into memory and why COM files had a strict 64K limit.
The clever reload-from-disk trick that let DOS's COMMAND.COM recover automatically after a large program overwrote its expendable transient portion.
FreeDOS's kernel is a from-scratch, clean-room reimplementation, and its authors' actual architecture choices differ deliberately from how MS-DOS was built.
How DOS users reclaimed conventional memory by relocating drivers and TSRs into unused upper memory gaps, which varied by machine and BIOS.
Why DOS ended up with three separate, incompatible ways to access memory beyond the conventional 640K barrier, and what each one was actually solving.