>the best security feature we have to sandbox programs>takes hours to configure per programI want to kill myself, apparmor sisters
>>108816446Try vibe configuring it.
>>108816446Use systemd-nspawn instead.
>>108816581looks like it's on my leveltank yew big sis
@grok write an apparmor config for this app please
>>108816446SELinux > AppArmor
>>108816690>>108816690If he can't figure out apparmor he's definitely not going to figure out SELinux.
>>108816690SELinux is the ultimate corporate busywork.Policies can be so idiotically complex, it's unreal.
>>108816690Literal NSAware
>>108816690nice try NSA
>>108816446>bestnot even close. just use namespaces.
There are plenty of pre-configured profileshttps://github.com/roddhjav/apparmor.d
>>108816446I always preferred tomoyo for systemwide hardending and firejail for specific/situational suff, i only use apparmor because my distro ships it already enabled.
>>108816690if he already whinges about apparmour config then he's gonna cry rivers about selinux config.
>>108816690SELinux seems to be more complete in the kernel whereas apparmor has missing parts, but from a configuration standpoint, I think apparmor is significantly more granular by default...
>>108816581>systemd-NSApawn
>>108816446You don't need more than seccomp/namespaces/landlock.seccomp == OpenBSD pledge()namespaces+landlock == OpenBSD unveil()The Linux implementations are inferior to OpenBSD obviously, but they serve the same purpose.
>>108816690>NSAlinux
Selinux mogs it.
>>108821360>t.
>>108821370Lazy cunt.
>>108821382>Lazy cunt.
>>108816446Just use namespaces... podman for CLI shit and daemons and flatpak for UI shit are perfect and shield you from the usual UNIX retardism of "if an attacker excutes one malicious line of code, your entire computer is fucked".AppArmor and SELinux are archaic attempts to make the old, non-sandboxed model work.
>>108821406>flatpak for UI shitThe thing is, I want to run an AppImage built with electron. This limits the options I have. I don't think this will work
>>108821334He probably does for GUI applications
zump