3 ms·
I'm running firejail now and It doesn't look like it runs as root.
by dj_gitmo 5y ago
I'm running firejail now and It doesn't look like it runs as root.
- anderspitman 5y agoCorrect, it is an SUID executable[0], as is bubblewrap. [0]: https://en.m.wikipedia.org/wiki/Setuid https://en.m.wikipedia.org/wiki/Setuid
- jwilk 5y agoThis is poorly documented, but if the kernel supports unprivileged user namespaces, bubblewrap works without suid.
- anderspitman 5y agoGood to know, thanks.
- yjftsjthsd-h 5y agoDoes/can firejail, or is that a difference?
- WhyNotHugo 5y agobubblewrap is only setuid if user namespaces are unavailable.