3 ms·
Check also https://github.com/wrr/drop https://github.com/wrr/drop which is a higher-level tool than bwrap. It allows you to make such isolated sandboxes with m
by mixedbit 6mo ago
Check also https://github.com/wrr/drop https://github.com/wrr/drop which is a higher-level tool than bwrap. It allows you to make such isolated sandboxes with minimal configuration.
- stratos123 6mo agoThis looks nice but I wouldn't trust a very fresh tool to do security correctly. As a higher-level alternative to bwrap, I sometimes use `flatpak run --filesystem=$PWD --command=bash org.freedesktop.Platform`. This is kind of an abuse of flatpaks but works just fine to make a sandbox. And unlike bwrap, it has sane defaults (no extra permissions, not even network, though it does allow xdg-desktop-portal).
- OJFord 6mo agoShame it's not a bit more mature, it does look like more the sort of thing I want. I use firejail a bit, but it's a bit awkward really. To be honest - and I can't really believe I'm saying it - what I really want is something more like Android permissions. (Except more granular file permissions, which Android doesn't do at all well.) Like: start with nothing, app is requesting x access, allow it this time; oh alright fine always allow it. Central place to manage it later. Etc.