Hey there,
After disappearing and thinking for a while about how to have some kind of support for GNU/Linux sandboxes with seamless integration to the window manager. I've thought a lot about how the Qubes approach does it using shared memory and Xorg messages but this doesn't work over the network, so I'm starting to wonder if it'd be better to just use something like Xpra. I'm not sure how big the TCB of it is versus just passing X messages, but it shouldn't really be that bad if you only give it access to files shared with the sandboxed system, meaning it'd be counterproductive to break in to Xpra.
Xpra also plans a Wayland port which might map well. Thoughts?
Jookia.