3 ms·
This seems to have similar or less features than bubblewrap, but requires Docker which loads huge images and wastes disk space. No Wayland, DBus, Pipewire, proc
by codedokode 5mo ago
This seems to have similar or less features than bubblewrap, but requires Docker which loads huge images and wastes disk space. No Wayland, DBus, Pipewire, proc, sys filtering. Furthermore, Docker docs explicitly says that it cannot be used for security sandboxing. Also, Docker is a huge binary, run as root, with lot of APIs and wide attack surface.
- ashishb 5mo ago> Also, Docker is a huge binary, run as root, with lot of APIs and wide attack surface. You can run it without root. And that's what you should do. > No Wayland, DBus, Pipewire, proc, sys filtering. Yeah, I don't need Wayland for CLI tools. For others, you get them inside Docker, isolated from the rest of the system. When I run `npm install`, I want isolation.