• InnerScientist@lemmy.world
    link
    fedilink
    arrow-up
    5
    ·
    27 days ago

    Define “sandboxed”

    Application can only access a limited part of the system? = use flatpak or build a container/VM image using the nix pkgs.

    Application can be uninstalled completely and has separate libraries? I prefer nix.

  • thedeadwalking4242@lemmy.world
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    27 days ago

    Nix apps are not sandboxed and you have no control of what resources they have access to or don’t, unless you wrap them with some other program

    • LalSalaamComrade@lemmy.ml
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      27 days ago

      They can be isolated because Nix has in-built support for three different levels of sandboxing - virtual machines, containers as well as ephemeral shells.