docs: Update README regarding setuid and user namespaces - #790
maruixin-kls wants to merge 1 commit into
Conversation
smcv
left a comment
There was a problem hiding this comment.
No, the paragraph you're deleting is still true, and is important contextual information.
Historically, bubblewrap did support being setuid root, and this has had a significant impact on its design. The fact that this is no longer available/supported doesn't change the fact that older versions of bubblewrap did have this behaviour.
In particular, this means that bubblewrap must continue to "fail closed" if someone mistakenly makes it setuid.
|
#743 is specifically about the "Related project comparison: xxx" sections of the readme, which weren't altered by this PR. |
|
So, for clarification's sake, @smcv , you'd prefer me to rewrite the project examples to show that we aren't reliant on setuid anymore? Or would you prefer deletion(like firejail, for example, is not a direct comparison anymore) |
Fixes #743
The README currently contains outdated information suggesting that
setuidis the primary method for operation. This PR updates the text to clarify thatbubblewrapnow primarily relies on unprivileged user namespaces, aligning the documentation with the current implementation.