Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Isn't landrun the preferred way to sandbox apps on linux these days instead?

https://github.com/Zouuup/landrun





Bubblewrap seems to be much more popular[^1], personally this is the first time I heard about landrun

[1]: https://repology.org/project/bubblewrap/information https://repology.org/project/landrun/information


bubblewrap is a lot more flexible: You can freely piece together the sandboxed filesystem environment from existing directories, tmpfs, files or data provided via a file descriptor. landrun, from what I understand only restricts what already exists. What is neat with landrun is the TCP port restrictions. This isn't possible with bubblewrap at the moment, although nothing really prevents bubblewrap from adding landlock support for those cases.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: