sloonz.github.io

MonkderZweite, to privacy in Sandboxing Applications with Bubblewrap: Securing a Basic Shell | sloonz's blog

I use bubblejail.

possiblylinux127,

What’s bubble jail?

MonkderZweite,
Syn_Attck,

tl;dr easier wrapper for bubblewrap (with GUI)

MonkderZweite,

And presets.

Syn_Attck,

It certainly looks like what I’d use if I had a use for it. Do you know if it’s compatible with Debian-based distros or only arch?

MonkderZweite,

Seems like you have to compile. I use it only for Steam (on Arch) for now (with a symlink to .local/share/Steam for some modloaders). Though, somehow no Qt app runs on my notebook, but setup via cli was fine too.

shirro, (edited ) to linux in Sandboxing Applications with Bubblewrap: Securing a Basic Shell

I was setting up a modded minecraft launcher for the family to use and and I have trust issues with the modding ecosystem and kids installing random jar files. I used bwrap and it works really well. The launcher uses wayland, minecraft typically X, needs dri access for opengl, pipewire, input devices, networking and dns resolve to connect to servers etc. Doesn’t need filesystem access to much other than some shared libs (ro) and a directory in .config. There is a bit of trial and error involved and making the bwrap robust to differences between desktops (different sockets for dns or mdns resolvers) and makes me appreciate apps packaged as flatpak as this level of sandboxing should be standardised for all distributed apps. Half the stuff in AUR should be bwrapped IMO.

Throwaway1234, to linux in Sandboxing Applications with Bubblewrap: Securing a Basic Shell

Does anyone happen to know if bubblewrap is more powerful than bubblejail (or vice versa). Or how they differ in the first place (beyond CLI vs GUI)?

dsemy,

bubblejail is based on bubblewrap.

iiGxC, to linux in Sandboxing Applications with Bubblewrap: Securing a Basic Shell

I’ve been meaning to set up sandboxing, this is super helpful! Thanks

  • All
  • Subscribed
  • Moderated
  • Favorites
  • fightinggames
  • All magazines