Skip to content
This repository was archived by the owner on Mar 13, 2022. It is now read-only.
This repository was archived by the owner on Mar 13, 2022. It is now read-only.

Sandboxing #2

@sonnyp

Description

@sonnyp

I use the flatpak version of bottles but still, I think bottles could benefit from builtin sandboxing for the following reasons

  1. Get sandboxing support ala Steam or WebkitGTK even for non flatpak builds
  2. Let users define per bottles permissions, at runtime rather than the Bottles team guessing which permissions should be given by default to all bottles. See [Flatpak] Reduce filesystem permissions  Bottles#413

It is possible to run bubblewrap in flatpaks.
Steam makes use of this - see flathub/com.valvesoftware.Steam#642 (comment)

I don't think this should be high priority given that it's already possible to sandbox through the flatpak version but I would be interested in hearing your thoughts and if you think it's relevant to Bottles.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions