logoalt Hacker News

akdev1ltoday at 12:44 AM1 replyview on HN

If a sandbox is optional then it is not really a good sandbox

naturally even flatpak on Linux suffers from this as legacy software simply doesn’t have a concept of permission models and this cannot be bolted on after the fact


Replies

okanattoday at 12:50 AM

The containers are literally the "bolting on". You need to give the illusion of the software is running under a full OS but you can actually mount the system directories as read-only.

show 2 replies