• 12 Posts
  • 22 Comments
Joined 7 months ago
cake
Cake day: January 29th, 2024

help-circle















  • Yes, that sandboxing works with graphical apps in addition to CLI apps and services, and there are several graphical applications that allow you to select connections for snapped apps, including KDE Discover.

    The SELinux implementation is primarily there to ensure that SELinux's enforcement doesn't break snapped apps, but a side effect of the different model compared to AppArmor's means that filesystem based sandboxing is only partial. And, of course, if the system has SELinux in permissive mode snapd won't force it into enforcing mod. Specific vary from system to system, but it means that the filesystem isolation isn't as good under SELinux as it is under AppArmor. Most of the sandboxing is done through cgroups, though, which is not dependent on whether one uses SELinux or AppArmor.









  • A less extreme version of what you said already happened across a lot of North America decades ago, and we're living with the consequences. In most cities, it's illegal to build anything other than detached houses on most of the land. There's an empty lot near me that's been undeveloped for a decade because the previous house burned down and the finances of building another detached house there didn't work out for the guy who owned it, but the city wouldn't let him build a duplex with the same footprint because it was "too dense for the character of the neighbourhood."

    Get involved in your local government. Tell your city council to stop living at the whims of landlords and to start legalising housing.