Xdg-App Announced For Desktop App Sandboxing

Written by Michael Larabel in GNOME on 24 June 2015 at 09:25 AM EDT. 19 Comments
GNOME
Alexander Larsson has formally announced xdg-app today as the desktop app sandboxing system for GNOME environments.

Larsson announced, "xdg-app is a desktop and distribution-independent application bundling and system for Linux. It uses user namespaces and the kernel container technologies to run applications in a sandboxed environment without any kind of root privileges or setuid required. It also features a user-space dbus filter with policies that are compatible with kdbus."

Xdg-app is still under active development but reached a state where more Linux users can begin trying it out. Larsson has been working on this project for months with sandboxing GNOME apps and back in February reaching the point of the first fully-sandboxed app using this open-source stack.

Over on the GNOME Wiki are more details on their sandboxed apps stack. Their tech stack relies on cgroups, namespaces, SELinux, KDBUS, and Wayland.
Related News
About The Author
Michael Larabel

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week