x

Alternatives sandboxes to plain chroot

Bubblewrap (bwrap)

Has security sandboxing features, and is used by Flatpak. Better than chroot.

TODO: How to use

Faketree

Saw a medium article related to use in EDA.

Concepts

  • unshare
    • Used to set namespaces and make them unavailable to main system
  • Kernel namespaces
  • Generic Sandboxes
    • Flatpak
      • Uses bwrap, etc.
      • Has runtimes
      • Flatseal can manage permissions
    • AppImages
Left-click: follow link, Right-click: select node, Scroll: zoom
x