Elektrine lite

← Feed

@june@ublog.kimapr.net

Post #2071690

2026-05-06 04:36 UTC

@stilic @navi this doesnt really explain or help anything other than making a blind assumption that bubblewrap can do everything there, and there still isnt an example.

Replies (1)

  • @stilic@social.oss.zone 2026-05-06 04:48

    @june@ublog.kimapr.net @navi@social.vlhl.dev Well this is coming from a security researcher who knows a lot about Linux security issues so I think they know what they're doing unless someone proves me wrong or smth Bubblewrap is pretty much able to do around 90% of the stuff systemd already does in terms of sandboxing without having to get its features reimplemented in the init system itself There are use cases for sandboxing a whole bootstrap process (https://github.com/fosslinux/live-bootstrap) or just building a few packages in an isolated environment (as done by a few package build systems), so I'm pretty sure that is sufficient on its own along with seccomp Bubblewrap has a large amount of CLI options if you have specific requirements in mind, it's very polyvalent Even ChromeOS has a tool for similar purposes (https://google.github.io/minijail/)

    Open ##2192993