3 ms·
Here is something I'd like to have in fedora (or desktop linux in general): A sort of “workspace manager” using bubblewrap for isolating user-defined groups of
by rosetremiere 5y ago
Here is something I'd like to have in fedora (or desktop linux in general): A sort of “workspace manager” using bubblewrap for isolating user-defined groups of applications and file hierarchy.
I imagine it as some kind of GUI with “boxes”, each defining a “workspace” with specified permissions (access to that and that folder, network, etc), such that the user could easily drag and drop apps into new workspaces.
This way, I could have a “banking” workspace just containing, say, firefox, and a “work” workspace with, say, firefox and thunderbird and whatever, etc. The “workspaces” would by default be as unprivileged as possible, with the possibility to give access to folders, or even maybe to use unionfs or similar to combine the views of different workspaces.
For ease of use, I could assign a color or icon to each workspace, and the manager would automatically generate desktop files so that I would easily be able to spot “banking firefox” from “work firefox”.
I feel like with bubblewrap, this is only a short python GUI away, and would be super helpful to strengthen security on linux, even more so for non-technically inclined, or lazy people.
[Edit:] If someone wants to discuss things further and even maybe try and write a “MVP”, I'd be happy to try.
- seanhunter 5y agoThis is almost exactly the concept behind qubes-os except it uses the xen hypervisor instead of bubblewrap and vms for boxes. https://www.qubes-os.org/ https://www.qubes-os.org/
- rosetremiere 5y agoRight. I'm being a bit less ambitious here: I've recommended fedora to plenty of (non-tech) people around me, and fedora presumably already has all the necessary tools to add such a simple “workspace manager” without much disruption. It would provide an easy intuitive step-up in terms of security, starting from something people already know.
- fock 5y agoFirst problem is that proper (incl. X11...) isolation costs you 3D (so not great for Firefox). Otherwise there is "toolbox" by Fedora, which you could surely combine with Xephyr for a wine-like, more isolated experience. I do that with a shell-only workflow (though on my HiDPI-machines I still have to patch Xephyr to scale the output (which is pretty easy using its GL-backend tbh, but I need to refine my amateur C dabblings to release that). EDIT: I'm happy to discuss how to use Wayland with proper isolation and 3D! (and some frame-decoration)
- rosetremiere 5y agoI didn't know about "toolbox": it seems close to what I want. About 3D, does calling a program through `bwrap` disable opengl or something?
- fock 5y agowell, depending on what you do, you usually need access to the dri-device, the X11-driver and X11 (socket). This is relatively insecure I suppose because it exposes a giant attack-surface. Everything trying to mitigate this (short of running VNC) unfortunately still has some, but I would expect noone targets these broad-spectrum. An interesting thing to do would be to run with VGL and a quadro/...-GPU which allows partitioning into different rendering devices. Haven't tried reading about this with wayland.
- PausGreat 5y ago> Xephyr It's easier to use Wayland. Additionally, Toolbox does not sandbox the application.
- fock 5y agoThen how will wayland tell me, which container a window comes from? (besides that, most software I use in containers is very much preeee-wayland). Thanks for the correction on toolbox, I know remember again, why I have my own bwrap-wrapper.