• turdas@suppo.fi
    link
    fedilink
    arrow-up
    9
    ·
    22 hours ago

    The reason I’m asking is that separate wineprefixes will look like a “different wine instance” to a layman, but they’re not the same thing as a sandbox. Wine mounts the host filesystem under the Z: drive, and even beyond that there are probably ways to escape the Wine environment. For true sandboxing some additional layers will be required.

    • Saprophyte@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      13 hours ago

      From a security standpoint, yes they can be broken out of, just like a docker or a virtual machine , but they use bubblewrap to isolate environments just like flatpaks. Malicious content aside they are just as isolated and sandboxed as a docker image or vm