3 ms·
Hmm, let me think a bit about how to respond to your first paragraph. But meanwhile, I'm curious about point 3 as you seem to have facts that I lack -- when a
by kikoreis 6y ago
Hmm, let me think a bit about how to respond to your first paragraph.
But meanwhile, I'm curious about point 3 as you seem to have facts that I lack -- when a confined snap refresh runs through snapd, is the upgrade payload not executed entirely in userspace within the sandbox? I haven't looked at the code, but my understanding of the model is that the snap can only modify its own writable areas (and do stuff like add a symlink to /snap/bin, though that's also limited). So a snap update could't, for instance, modify arbitrary files, nor read restricted ones. Whereas a dpkg install can do anything as root. Can you help clarify?