Skip to content

Investigate bubblewrap for sandboxing #152

Description

@probonopd

https://github.com/projectatomic/bubblewrap

To run an AppImage in a read-only sandbox so that it can only write to $HOME/.config/leafpad/ and $HOME/leafpad/:

# Get the sandbox
wget -c "https://github.com/probonopd/bubblewrap/releases/download/binary/bwrap"
# Get the AppImage to be run inside the sandbox
wget -c "https://bintray.com/probono/AppImages/download_file?file_path=Leafpad-0.8.17-x86_64.AppImage" -O Leafpad-0.8.17-x86_64.AppImage
# FUSE-mounting does not seem to work inside the sandbox
sudo mount Leafpad-0.8.17-x86_64.AppImage /mnt -o loop
chmod a+x ./bwrap
mkdir -p $HOME/leafpad/
mkdir -p $HOME/.config/leafpad/
./bwrap --ro-bind / / --dev /dev --bind  $HOME/.config/leafpad/ $HOME/.config/leafpad/ --bind  $HOME/leafpad/ $HOME/leafpad/ /mnt/AppRun
sudo umount /mnt

Works for me :-)

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions