With systemd or firejail it's quite easy to do this sort of thing on linux.