Install bubblewrap by default to make use of MAT2's sandboxing

Whonix should install bubblewrap by default. MAT2 uses bubblewrap for sandboxing and is automatically enabled if it is installed.

This currently won’t work though due to a bug (Whonix uses hidepid).

2 Likes

Will having the on fixed version installed break MAT2 startup? If not then we can incldue it.

1 Like

Yes, it likely will.

I’m not saying to include bubblewrap immediately. It can be included after the bug is fixed.

1 Like

I’ve submitted a pull request to bubblewrap that should fix the MAT2 issue.

It might take a while before it gets merged and then a longer while before it’s in Debian.

There are also some users encountering this bug https://0xacab.org/jvoisin/mat2/issues/121

2 Likes

although this bug not solved yet, bubblewrap now included anyway in WS (mat2 and libwebkit2gtk depends on bubblewrap).

1 Like

Bubblewrap can be disabled by using mat2’s --no-sandbox flag now if any errors occur.

1 Like
1 Like