3 ms·
Didn't AppImage solve the problem of no-sudo containerized apps already? I tried AppImage following a post on HN recently, all you need to do is download your d
by lighttower 10y ago
Didn't AppImage solve the problem of no-sudo containerized apps already? I tried AppImage following a post on HN recently, all you need to do is download your desired program, it's just one file, call it `filename` then `chmod a+x filename` and `./filename ` that's it. I can finally run Google Earth without crashes under Linux.
- jhasse 10y agoAFAIK AppImage's sandbox (Firejail) is very permissive and not enabled by default. Flatpak is more restrictive and also supports no-sudo installations.
- bkor 10y agoTo read more about Flatpak security system, please check https://blogs.gnome.org/alexl/ https://blogs.gnome.org/alexl/: https://blogs.gnome.org/alexl/2017/01/24/the-flatpak-security-model-part-3-the-long-game/ https://blogs.gnome.org/alexl/2017/01/24/the-flatpak-securit... https://blogs.gnome.org/alexl/2017/01/20/the-flatpak-security-model-part-2-who-needs-sandboxing-anyway/ https://blogs.gnome.org/alexl/2017/01/20/the-flatpak-securit... https://blogs.gnome.org/alexl/2017/01/18/the-flatpak-security-model-part-1-the-basics/ https://blogs.gnome.org/alexl/2017/01/18/the-flatpak-securit... Flatpak supports Portals. So it can be restrictive, then on a toolkit level it'll automatically allow certain things based upon user interaction. E.g. it'll securely allow a user to select a file. Therefore the sandboxed app gets access to that file. Practically, because some things are on a toolkit level sandboxing can take a bit longer. E.g. 'gimp' uses gtk+2.x, I'm guessing (though no clue), that the Portal is only for gtk+3.something. If you cannot nicely sandbox then meanwhile there's only one solution: almost no sandbox (e.g. still have access to the home directory.. which gives way too many options to break the sandbox).