3 ms·
Note that VS Code is built on Electron and it is a pain to sandbox because Electron has (had?) SUID sandbox helper, and you cannot run SUID binaries in sandbox
by codedokode 5mo ago
Note that VS Code is built on Electron and it is a pain to sandbox because Electron has (had?) SUID sandbox helper, and you cannot run SUID binaries in sandbox easily. Sandboxing on Linux is extremely difficult task.
- jandrese 5mo agoIt feels so bad to see the "You need go give Chrome SUID Root for the sandbox to work". Setting a Web Browser SUID Root was an old joke about clueless users. It was the worst security screwup someone could imagine.
- duped 5mo agopodman seems to handle rootless namespaces just fine, minor caveat for some perf overhead but it's not the end of the world.
- internet101010 5mo agoAnd volumes. Volumes are not fun with podman. Ironically my team tried GitHub Codespaces and never looked back. Super cheap and uses DevContainers.
- unethical_ban 5mo agoWhat's the difference between Podman and docker for volumes? Other than needing to add Z to get volumes to mount with SELinux
- NewJazz 5mo agoMaybe permissions when going rootlesz?
- miki123211 5mo agoIf you're root on a system and use Docker volumes, you can always `sudo ls` and access those volumes outside of the container. If you're just a user running containers under Podman, it's more tricky.
- GCUMstlyHarmls 5mo ago`podman unshare && podman mount`
- NewJazz 5mo agoDon't build your ide on electron then.
- varun_ch 5mo agoElectron was invented to build an IDE on.
- HappMacDonald 5mo agoNothing about that guarantees that it is suitable to the purpose
- IshKebab 5mo ago> Sandboxing on Linux is extremely difficult task. Which is really insane when you think about it. Plan 9 had this sorted out decades ago.
- noir_lord 5mo agoWith no disrespect to the Linux kernel programmers who are vastly better than I’ll ever be. Plan 9 was designed, Linux accreted.