3 ms·
It isn't just linux namespaces, you have mounted namespaces, cgroups, seccomp filters etc... From what I remember it certainly isn't as simple as you present i
by kd913 3y ago
It isn't just linux namespaces, you have mounted namespaces, cgroups, seccomp filters etc...
From what I remember it certainly isn't as simple as you present it and additional features tends to involve additional surface area.
Other aspects in the past was that Firejail's approach to capabilities and namespaces enabled it to act as a setuid binary to gaining root privileges on the host.
Snaps I seem to recall had defined mounted namespaces that didn't need this privilege escalation. Their apparmor profiles are well defined and tunable via the connections mechanism. Although I seem to recall that too having some CVEs present.
In terms of trust though, I rather do trust snaps a lot more than firejail even if the latter is more tunable. I see that latter aspect as a downside, relative to snaps which already come confined and tuned.
There is also systemd itself which can be used in a similar way, and also has quite a nice tool for checking the exposure of a given sandbox.
- totallywrong 3y agoThe snap daemon runs as root, is a resources hog, and really only works well in Ubuntu. Oh and snaps in general suck sooo much, but that's of course just an opinion.
- ranger_danger 3y ago> I rather do trust snaps a lot starting with the Ubuntu 20.04 package base, the Chromium package is indeed empty and acting, without your consent, as a backdoor by connecting your computer to the Ubuntu Store. Applications in this store cannot be patched, or pinned. You can’t audit them, hold them, modify them or even point snap to a different store. You’ve as much empowerment with this as if you were using proprietary software, i.e. none. This is in effect similar to a commercial proprietary solution, but with two major differences: It runs as root, and it installs itself without asking you.
- kd913 3y agoI have pinned them, I have patched them, I have written versions of them including Thunderbird and Firefox along with my own theming ones. I know the reasons why canonical only keeps one store and it seems rather sane to me. Especially after hearing about the mess with PPAs. I can run within their environment and unpack their squashfs. The snap runtime is very plain in GitHub. Please stop sharing FUD.