dottorblaster,
@dottorblaster@fosstodon.org avatar

Goodie of the day by @janvhs: sandboxed npm install

podman run -it --rm --userns keep-id -w /usr/local/src/_ -v ./:/usr/local/src/_:Z docker.io/library/node:alpine npm install  
janvhs,
@janvhs@hachyderm.io avatar

@dottorblaster actually reworking it / writing a cli to use bubblewrap and on mac sandbox-exec, so you can use your native host :D

dottorblaster,
@dottorblaster@fosstodon.org avatar

@janvhs only grrr reactions at mac os

janl,
@janl@narrativ.es avatar

@dottorblaster @janvhs macOS can do this natively, no containers required. https://github.com/berstend/node-safe (apologies for linking to a thing with a maga slogan)

janvhs,
@janvhs@hachyderm.io avatar

@janl @dottorblaster yeah that’s using “sandbox-exec”. Basically the same thing as bubblewrap just using scheme as config lol

janl,
@janl@narrativ.es avatar

@janvhs @dottorblaster yeah I laughed out hard when I saw the config. Somebody at Apple must be reeeeeally proud of themselves. And I applaud them for getting this shipped ;D

My unsubstantiated theory is that they have some sort of static theory prover for this, so they can prove their rules are safe.

janvhs,
@janvhs@hachyderm.io avatar

@janl @dottorblaster yeah haha I just love seeing S-expressions in random places. That’s a really good theory, especially because it feeds into my theory, why you can’t statically link executables on mac.

janl,
@janl@narrativ.es avatar

@janvhs @dottorblaster that’s something else tho. You can totally statically link, just not against system libs.

janvhs,
@janvhs@hachyderm.io avatar

@janl @dottorblaster nope, there is no crt0.a, so everything has to link against libSystem or what it’s called. @engler and I learned that the hard way haha

(sure you can link libraries statically but not a completely static executable)

janl,
@janl@narrativ.es avatar

@janvhs @dottorblaster @engler ah, that’s what you mean. Yup yup yup.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • GTA5RPClips
  • Durango
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • ngwrru68w68
  • tacticalgear
  • JUstTest
  • osvaldo12
  • tester
  • cubers
  • cisconetworking
  • mdbf
  • ethstaker
  • modclub
  • Leos
  • anitta
  • normalnudes
  • megavids
  • provamag3
  • lostlight
  • All magazines