1
0
mirror of https://github.com/projectatomic/bubblewrap.git synced 2026-02-06 00:45:49 +01:00

34 Commits

Author SHA1 Message Date
Aaron Brooks
2c11c8a8e3 README.md: Fix "Docker pid 1 problem" URL
The URL schema of the target site has changed and now returns a 404 for the old URL. This URL accommodates the new URL scheme and points to the original content.

Signed-off-by: Aaron Brooks <aaron@brooks1.net>
2026-02-03 18:52:49 -05:00
Simon McVittie
2a552429ec Merge pull request #566 from TotalCaesar659/patch-1
Update URLs to HTTPS
2024-10-01 19:37:33 +01:00
Hugo Osvaldo Barrera
2834c01cab Remove autotools build system
Signed-off-by: Hugo Osvaldo Barrera <hugo@whynothugo.nl>
Signed-off-by: Simon McVittie <smcv@collabora.com>
2024-09-03 13:47:25 +01:00
Simon McVittie
526d6ebd74 Document some potential pitfalls in sandboxing
Signed-off-by: Simon Brand <simon.brand@postadigitale.de>
[smcv: Combine with #560, re-word]
Co-authored-by: Simon McVittie <smcv@collabora.com>
Signed-off-by: Simon McVittie <smcv@collabora.com>
2024-02-15 14:15:04 +00:00
Jonathan Wright
05ce287fba Add testing instructions to README.md
Signed-off-by: Jonathan Wright <quaggy@gmail.com>
2023-10-01 11:10:12 -07:00
Sebastian Pipping
2f9ce900d4 README.md: Mention --new-session in section "Sandboxing"
Signed-off-by: Sebastian Pipping <sebastian@pipping.org>
2023-04-03 09:52:37 +02:00
Sebastian Pipping
9a1d8b7217 README.md: Add --new-session to usage example
Signed-off-by: Sebastian Pipping <sebastian@pipping.org>
2023-04-03 09:52:37 +02:00
Sebastian Pipping
29f92713ce README.md: Improve readability of usage example
Signed-off-by: Sebastian Pipping <sebastian@pipping.org>
2023-04-03 09:52:37 +02:00
Simon McVittie
795eeee77e README, SECURITY: Clarify that bubblewrap does not define a security model
bubblewrap can provide a robust security boundary that severely limits
functionality, or it can provide full functionality without any attempt
at being a security boundary, or anything in between those extremes.
If a caller of bubblewrap chooses inappropriate command-line arguments
for their desired security model, then bubblewrap will not provide the
security model they are aiming for, but this is not a bubblewrap
vulnerability.

Apparently this isn't clear to everyone, so try to clarify.

The one place where bubblewrap *does* define some sort of security
policy for itself is when it's setuid root, in which case it's
responsible for preventing users from carrying out privilege escalation
attacks like CVE-2020-5291.

Resolves: https://github.com/containers/bubblewrap/issues/555
Signed-off-by: Simon McVittie <smcv@collabora.com>
2023-03-30 14:34:17 +02:00
TotalCaesar659
4518233eac Update URLs to HTTPS
Signed-off-by: TotalCaesar659 14265316+TotalCaesar659@users.noreply.github.com
2023-03-07 23:41:49 +03:00
Newbyte
29d1db4a18 Link to the last commit where xdg-app-helper.c existed
Right now this link just opens a "path not found" page, so let's fix that by linking to the last commit where it existed instead.

Signed-off-by: Newbyte <newbie13xd@gmail.com>
2022-03-23 20:35:54 +01:00
rusty-snake
798b87ce3a Add install instruction to README.md
Closes #315
Closes #363

Signed-off-by: rusty-snake <41237666+rusty-snake@users.noreply.github.com>
2022-03-22 17:01:28 +01:00
Simon McVittie
4914bc8a18 Use HEAD to refer to other projects' default branches in documentation
This makes the URL independent of the name they have chosen for their
default branches.

Signed-off-by: Simon McVittie <smcv@collabora.com>
2022-02-13 21:06:50 +00:00
Sönke Hahn
d29f50afdb Fix typo 2021-12-07 23:56:40 -05:00
Jakub Wilk
cc44544f8c Fix typos
Closes: #302
Approved by: smcv
2019-02-26 17:14:25 +00:00
Richard Maw
8fc5a96b3e Revert "README.md: Delete cat logo picture (not DFSG compliant)"
The source image is now public domain.

Closes: #294
Approved by: cgwalters
2018-10-04 13:02:52 +00:00
Marcos Paulo de Souza
4ff4c9286f README.md: Remove double dots
Signed-off-by: Marcos Paulo de Souza <marcos.souza.org@gmail.com>

Closes: #245
Approved by: giuseppe
2017-10-31 09:36:10 +00:00
Colin Walters
b9c564dbe0 README.md: Delete cat logo picture (not DFSG compliant)
The cat is cute, but let's not hinder adoption anywhere based on this. If
someone cares, we could probably project the Internet emergency logo into the
sky, requesting a cat picture with bubblewrap that is *also* DFSG compliant.

Closes: https://github.com/projectatomic/bubblewrap/issues/204

Closes: #206
Approved by: alexlarsson
2017-08-14 13:37:00 +00:00
Giuseppe Scrivano
8f3f0abe76 README.md: add bwrap-oci to the list of users
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>

Closes: #199
Approved by: cgwalters
2017-07-12 13:02:12 +00:00
Aleksa Sarai
06e9091570 README: update references to runC
Currently we are working on implementing rootless containers, where no
privileges are required during any part of the process of installing
runC or the management of containers. We are solving a different problem
to bubblewrap with this feature, in the hopes that users on machines
where they have no ability to create a setuid binary will be able to
still use containers.

Signed-off-by: Aleksa Sarai <asarai@suse.de>

Closes: #84
Approved by: cgwalters
2017-02-17 15:28:52 +00:00
Colin Walters
3a5c701988 README.md: Update with better one liner and more information
The `ro-bind /` thing was ill advised.

Closes: https://github.com/projectatomic/bubblewrap/issues/125

Closes: #127
Approved by: alexlarsson
2016-12-12 15:02:37 +00:00
Kenton Varda
f37abd142f Make notes on sandstorm.io somewhat more accurate
Sandstorm actually requires userns today; it doesn't use a setuid helper. I adjusted the text to reflect the e-mail conversation I had with @cgwalters a few months ago.
Closes: #89
Approved by: cgwalters
2016-10-13 14:54:07 +00:00
Tim Janik
625209e494 README.md: minor typo fixes
Closes: #80
Approved by: cgwalters
2016-06-22 22:39:36 +00:00
Matthias Clasen
426262db53 Update README.md
Replace some xdg-app references with flatpak.

Closes: #78
Approved by: alexlarsson
2016-06-21 11:26:26 +00:00
Mrunal Patel
d470be9650 Update example to use --tmpfs for /tmp
Signed-off-by: Mrunal Patel <mrunalp@gmail.com>

Closes: #58
Approved by: cgwalters
2016-05-06 18:23:28 +00:00
Colin Walters
4c18c78bf5 README.md: Note userns unavailablity in CentOS 7 and Debian Jessie
Let's be more explicit that we can target production distributions
today.

Closes: #54
Approved by: rhatdan
2016-05-06 13:43:14 +00:00
Colin Walters
8ced4fbe51 README.md: Note some related projects
Closes: #44
Approved by: rhatdan
2016-05-05 23:54:22 +00:00
Colin Walters
92fc223647 README: Link to CVE-2016-3135, describe vs userns better
Closes: #41
Approved by: rhatdan
2016-05-02 17:24:58 +00:00
Alexander Larsson
aedbc794d5 README: Add some documentation about the sandbox
Pull request: #24
Approved by: alexlarsson
2016-03-18 07:59:09 +00:00
Matthias Clasen
fa0aad59bb README.md: Add a missing word
Pull request: #22
Approved by: alexlarsson
2016-03-15 19:53:04 +00:00
Alexander Larsson
f80ec233d2 Remove empty line at end 2016-03-15 16:17:56 +01:00
Matthias Clasen
ab9ca6b3a2 Explain the name
Add a short explanation of the cute name, and add a cute picture
for extra credit.

Note: The url needs to be updated to point to the main repository
when this is merged.
2016-03-07 16:21:14 -05:00
Alexander Larsson
dc4b633323 Add usage examples to README 2016-03-07 10:41:54 +01:00
Colin Walters
02ee96adf8 README.md: Initial version 2016-03-04 15:44:19 -05:00