this post was submitted on 20 Jun 2023
9 points (100.0% liked)
Arch Linux
7791 readers
5 users here now
The beloved lightweight distro
founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I don't have any experience with Bubblewrap. Is it what people tend to use instead of its alternatives? Have you had a look at Firejail? I think it does what you are trying to achieve and has a lot of these preconfigured scripts for a variety of the applications you might use (they call them profiles). https://wiki.archlinux.org/title/Firejail From the archwiki:
It also has support for use in conjunction with Apparmor: https://wiki.archlinux.org/title/Firejail#Enable_AppArmor_support
Note: A lot of applications won't have any read or write access anywhere but
/home/$USER/Downloads
. So one example from me would be that I copied the Firefox profile from/etc/firejail/firefox.local
to/home/$USER/firejail/firefox.local
and edited the latter to allow Firefox access to/home/$USER/Pictures
for the sake of convenience when saving a picture.Just my two cents in case you are not dead set on Bubblewrap.