9 bubblewrap
John Johansen edited this page 2021-10-16 20:37:26 +00:00

Related Documentation

Introduction

bubblewrap is an unprivileged application sandboxing tool. It uses linux namespaces, in particular Mount namespaces seccomp and no_new_privs to achieve and application sandbox.

AppArmor integration

Bubble wrap does not have any apparmor integration.

Affects on AppArmor mediation and policy

Mount namespace and pivot root.

no_new_privs