#1 2022-04-21 01:14:16

Registered: 2020-08-10
Posts: 22  

Firejail security concerns

11 months ago, the Alpine Linux team withdrew firejail from their repositories, citing security concerns with it:

This looks like it was a sudden thing, and is a little annoying because the suggested Bubblejail replacement is not working properly for me (Alpine v3.15.4; not edge).

Does anyone know if it is likely to vanish from Debian/Devuan for similar reasons?  If so, is there/will there be a good, KISS, easy-to-use alternative?

#2 2022-04-21 02:30:58

From: Clifton Hill, Victoria, AUS
Registered: 2016-11-30
Posts: 688  

You might possibly enjoy overlay-boot in Devuan's experimental repository.
It's a couple of scripts using unshare for namespace separation.

Add the following line to your sources.list for installing it

deb experimental main


#3 2022-04-25 13:30:47

From: London
Registered: 2019-03-24
Posts: 2,326  

dvnUsr wrote:

if it is likely to vanish from Debian/Devuan for similar reasons?

I wouldn't think so. Alpine place considerably more emphasis on security than Debian — they don't even apply the unprivileged user namespaces sysctl patch to their kernel, unlike Debian.

