[Desktop-packages] [Bug 1847092] Re: Sandboxing Chromium Snap without FireJail

2019-10-08 Thread Olivier Tilloy
The root filesystem that the chromium snap sees is the one provided by the core18 snap. Exceptions granted by the connected interfaces can be inspected by reading the generated apparmor profile, stored at /var/lib/snapd/apparmor/profiles/snap.chromium.chromium. -- You received this bug notificat

[Desktop-packages] [Bug 1847092] Re: Sandboxing Chromium Snap without FireJail

2019-10-07 Thread Lonnie Lee Best
If you disconnect home, what portions of the file system does Chromium have access to? ** Description changed: I'm a Firefox user who uses Chromium for certain google websites. I like to run Chromium in a sandbox so that the "Downloads" folder is the only file system location Chromium ca

[Desktop-packages] [Bug 1847092] Re: Sandboxing Chromium Snap without FireJail

2019-10-07 Thread Olivier Tilloy
As suggested by user ajgringo619 on askubuntu, disconnecting the home interface would get you close to what you're after. However to my knowledge there's no way to selectively connect certain folders in the home directory, such as ~/Downloads. Note that if you disconnect the home interface, you wi

[Desktop-packages] [Bug 1847092] Re: Sandboxing Chromium Snap without FireJail

2019-10-07 Thread Lonnie Lee Best
** Description changed: I'm a Firefox user who uses Chromium for certain google websites. I like to run Chromium in a sandbox so that the "Downloads" folder is the only file system location Chromium can see. - In Ubuntu 19.04, I could achieve this like: + In Ubuntu 19.04, I could achie