qyliss changed the topic of #spectrum to: A compartmentalized operating system | https://spectrum-os.org/ | Logs: https://logs.spectrum-os.org/spectrum/
hexa- has quit [Quit: WeeChat 2.9]
hexa- has joined #spectrum
cole-h has quit [Quit: Goodbye]
cole-h has joined #spectrum
<aaronjanse> ^ First time I've seen <blink> in a slideshow
<aaronjanse> qyliss: I now realize I have exams soon, so I'll have to postpone contributing for another ~3 weeks :-/
cole-h has quit [Ping timeout: 245 seconds]
acertain has quit [Read error: Connection reset by peer]
raboof has quit [Read error: Connection reset by peer]
acertain has joined #spectrum
raboof has joined #spectrum
jryans has quit [Quit: authenticating]
jryans has joined #spectrum
edwtjo has joined #spectrum
edwtjo has joined #spectrum
edwtjo has quit [Changing host]
cole-h has joined #spectrum
hexa- has quit [Quit: WeeChat 2.9]
hexa- has joined #spectrum
pastbytes has joined #spectrum
ashkitten has quit [Quit: WeeChat 3.1]
ashkitten has joined #spectrum
<pie_> huh someone nixed sphinx https://github.com/ngi-nix/androsphinx
<pie_> i should try this sometime
<V> should have called it androsphnix
<V> huuuge missed opportunity there
<pie_> heh
<pie_> unrelated, stf just posted a small comparison table of minijail nsjail and bubblewrap https://ctrlc.hu/~stef/jails.txt "nsjail can do the most, but minijail is close and there's some things only it can do, bubblewrap can barely do anyting but in return its a fraction of the code."
TheJollyRoger has quit [Remote host closed the connection]
TheJollyRoger has joined #spectrum
<aaronjanse> I was playing a lot with user namespace sandboxing this weekend, hoping that it'd be easier than Spectrum's approach (spoiler: I don't think it is)
<aaronjanse> Having the capability to chroot allows you to escape a chroot jail. But applications such as Firefox and Chrome need chroot capability to do their own sandbox for javascript/whatever
<aaronjanse> Also, it's really easy to have an escape if applications can touch anything like dbus
<aaronjanse> Still, it looks like a very good step forward compared to the current state of affairs on Linux desktop