Bubblewrap: Unprivileged sandboxing tool for Linux
github.com
github.com
Bubblewrap is aware of this, yet their documentation gives no indication that this flag is necessary to produce a secure sandbox. In --help, the documentation of --new-session is simply "Create a new terminal session," which severely understates its importance.
It's frustrating to have such a useful tool be knowingly easy to misuse.
[1]: https://undeadly.org/cgi?action=article;sid=20170701132619
I would be fine having to rewrite my apps to take advantage of some fancy capabilities-based security paradigm, but give me realistic APIs to do so.
I'm currently experimenting with shipping apps as QEMU VMs, packaging QEMU and a minimal kernel with the app. It works surprisingly well, even on Windows with full x86 emulation. And with their newish WHPX API (basically kvm for Windows) the future might be really exciting.
EDIT: Someone on the Firejail thread says bubblewrap can be compiled non-SUID and that's the common usage these days. I need to look into this more.
Currently I'm not banking on it though and focusing my testing assuming full emulation on older hardware.
If you're interested in collaborating on this feel free to email me or open a thread over on
EDIT: Also, Firecracker seems to have more steam behind it than crosvm. I really wish it ran on Windows. That said, QEMU does have a microvm mode[0] that looks very interesting.
That said, if you're using userNS then certainly the main executable should not be privileged, only some specialized helpers. And of course it should use caps instead of suid.
Even though the documentation claims that "[y]ou are unlikely to use it directly from the commandline, although that is possible," I use it as a helper tool in this mode very frequently.
This can be very useful for debugging since, for example, you can `bwrap --ro-bind / / --tmpfs ~ $SHELL` to get a "clean" shell in which you can isolate yourself from the effect of configuration dotfiles and can even `--ro-bind my-hosts /etc/hosts` to simulate certain system-level state (without requiring a full VM, heavier container, or root access.)
Of course, I've also written some simple shell scripts around `bwrap` to make this all a bit simpler (since this quickly reaches `qemu`-levels of argv proliferation.)
You're welcome.
Bubblewrap: Unprivileged sandboxing tool - https://news.ycombinator.com/item?id=12241971 - Aug 2016 (8 comments)
I see there are a few usage examples [1] out there. Are there any bigger collections of examples that people have run across?
> Firejail is similar to Flatpak before bubblewrap was split out
I imagine it as some kind of GUI with “boxes”, each defining a “workspace” with specified permissions (access to that and that folder, network, etc), such that the user could easily drag and drop apps into new workspaces.
This way, I could have a “banking” workspace just containing, say, firefox, and a “work” workspace with, say, firefox and thunderbird and whatever, etc. The “workspaces” would by default be as unprivileged as possible, with the possibility to give access to folders, or even maybe to use unionfs or similar to combine the views of different workspaces.
For ease of use, I could assign a color or icon to each workspace, and the manager would automatically generate desktop files so that I would easily be able to spot “banking firefox” from “work firefox”.
I feel like with bubblewrap, this is only a short python GUI away, and would be super helpful to strengthen security on linux, even more so for non-technically inclined, or lazy people.
[Edit:] If someone wants to discuss things further and even maybe try and write a “MVP”, I'd be happy to try.
EDIT: I'm happy to discuss how to use Wayland with proper isolation and 3D! (and some frame-decoration)
Haven't tried reading about this with wayland.
It's easier to use Wayland. Additionally, Toolbox does not sandbox the application.
So you either get the entire filesystem or no file access? Isn't this a huge dealbreaker for almost everything?
It seems like bubblewrap uses a mount namespace created by the current user which would allow controlling access without any special checks.
Having ways to impose limits on memory would be nice too.