Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm running firejail now and It doesn't look like it runs as root.


Correct, it is an SUID executable[0], as is bubblewrap.

[0]: https://en.m.wikipedia.org/wiki/Setuid


This is poorly documented, but if the kernel supports unprivileged user namespaces, bubblewrap works without suid.


Does/can firejail, or is that a difference?


Good to know, thanks.


bubblewrap is only setuid if user namespaces are unavailable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: