by a specified user"?
Sandboxes are confined spaces that segregate software from your main system, you can create user accounts that are non root to the same effect
Bubblewrap and Firejail use Namespaces to only allow access to certain files etc., but if there's a bug in them or a bug in the window compositor a program can still do harm
Обсуждают сегодня