Introducing oniux: Kernel-level Tor isolation for any Linux app

ensure you have following in your sysctl :

kernel.unprivileged_userns_clone = 1
kernel.apparmor_restrict_unprivileged_userns = 0