Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #229407 > unrolled thread

Electron apps in Debian with --no-sandbox

Started bybuckwheatpancake <buckwheatpancake@protonmail.com>
First post2020-12-07 07:20 +0100
Last post2020-12-07 08:10 +0100
Articles 2 — 2 participants

Back to article view | Back to linux.debian.user


Contents

  Electron apps in Debian with --no-sandbox buckwheatpancake <buckwheatpancake@protonmail.com> - 2020-12-07 07:20 +0100
    Re: Electron apps in Debian with --no-sandbox Sven Hartge <sven@svenhartge.de> - 2020-12-07 08:10 +0100

#229407 — Electron apps in Debian with --no-sandbox

Frombuckwheatpancake <buckwheatpancake@protonmail.com>
Date2020-12-07 07:20 +0100
SubjectElectron apps in Debian with --no-sandbox
Message-ID<Bji2l-4ht-5@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

So, Electron stuff in Debian comes with this annoying thing where it tells you chrome-sandbox (in various applications) needs to be owned by root and have mode 4755. If you set that, it just tells you the same, with another file. I've taken to running these things with the --no-sandbox option, because I don't know what the solution is... is this safe or recommended?

[toc] | [next] | [standalone]


#229408

FromSven Hartge <sven@svenhartge.de>
Date2020-12-07 08:10 +0100
Message-ID<BjiOK-4MI-9@gated-at.bofh.it>
In reply to#229407
buckwheatpancake <buckwheatpancake@protonmail.com> wrote:

> So, Electron stuff in Debian comes with this annoying thing where it tells you chrome-sandbox (in various applications) needs to be owned by root and have mode 4755. If you set that, it just tells you the same, with another file. I've taken to running these things with the --no-sandbox option, because I don't know what the solution is... is this safe or recommended?

You are hitting https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=898446
and the fact that the Debian Kernel is patched to disable creation of
user namespaces from non-privileged process.

The canonically correct solution here is to do the following, as root:


echo 'kernel.unprivileged_userns_clone=1' > /etc/sysctl.d/00-local-userns.conf
service procps restart

That should resolve this problem for now, until Debian concludes their
discussion in the linked bug and enables this feature per default, as
most other distributions already do.

Grüße,
Sven.

-- 
Sigmentation fault. Core dumped.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web