Nimbin[12]?Administration / run_private

run_private Administration

Run app within a bubblewrap container
dependencies: bubblewrap
Synopsis
[OPTION]... [APP]... [APP ARGS]
DESCRIPTION
--wayland_display $WAYLAND-DISPLAY
--xdg_runtime_dir $XDG_RUNTIME_DIR
--bind_dirs /dir_a:/dir_b

wget https://git.christianimmanuel.de/scripts/raw/Administration/run_private && chmod 740 run_private
run_private 2.3 KB · 108 lines raw
#!/bin/bash


#################################################
### Run app within a bubblewrap container
### dependencies: bubblewrap
### Synopsis
###      [OPTION]... [APP]... [APP ARGS]
### DESCRIPTION
###      --wayland_display $WAYLAND-DISPLAY
###      --xdg_runtime_dir $XDG_RUNTIME_DIR
###      --bind_dirs /dir_a:/dir_b

set -euo pipefail

# Defaults
wayland_display=""
xdg_runtime_dir=""
bind_dirs=""

APP=""

# Parse named args
while (( $# )); do
    case "$1" in
        --wayland_display)
            wayland_display="$2"
            shift 2
            ;;
        --xdg_runtime_dir)
            xdg_runtime_dir="$2"
            shift 2
            ;;
        --bind_dirs)
            bind_dirs="$2"
            shift 2
            ;;
        --*)
            echo "Unknown option: $1" >&2
            exit 1
            ;;
        *)
            APP="$1"
            shift
            break
            ;;
    esac
done

APP_ARGS=("$@")

if [[ -z "$APP" ]]; then
    echo "Usage: $0 [-wayland_display <display>] [-xdg_runtime_dir <dir>] [-bind_dirs <dir1:dir2:...>] <app> [args...]" >&2
    exit 1
fi

APP_NAME="$(basename "$APP")"

tmpdir="$(mktemp -d /tmp/${APP_NAME}_sandbox.XXXXXX)"
chmod 700 "$tmpdir"
mkdir -p "$tmpdir"/{home,config,cache,downloads}

cleanup() {
    rm -rf "$tmpdir"
}
trap cleanup EXIT

bwrap_args=(
    --unshare-user
    --dev /dev
    --proc /proc
    --tmpfs /tmp
    --dir "$tmpdir/home"
    --dir "$tmpdir/config"
    --dir "$tmpdir/cache"
    --dir "$tmpdir/downloads"
    --setenv HOME "$tmpdir/home"
    --setenv XDG_CONFIG_HOME "$tmpdir/config"
    --setenv XDG_CACHE_HOME "$tmpdir/cache"
    --setenv XDG_DOWNLOAD_DIR "$tmpdir/downloads"
)

if [[ -n "$wayland_display" && -n "$xdg_runtime_dir" ]]; then
    bwrap_args+=(--bind "${xdg_runtime_dir}/${wayland_display}" "${xdg_runtime_dir}/${wayland_display}")
    bwrap_args+=(--setenv WAYLAND_DISPLAY "$wayland_display")
    bwrap_args+=(--setenv XDG_RUNTIME_DIR "$xdg_runtime_dir")
fi

bwrap_args+=(
    --ro-bind /usr /usr
    --ro-bind /lib /lib
    --ro-bind /lib64 /lib64
    --ro-bind /bin /bin
    --ro-bind /etc /etc
)

# Add extra bind dirs
if [[ -n "$bind_dirs" ]]; then
    IFS=':' read -r -a dirs <<< "$bind_dirs"
    for d in "${dirs[@]}"; do
        bwrap_args+=(--bind "$d" "$d")
    done
fi

bwrap_args+=("$APP")
bwrap_args+=("${APP_ARGS[@]}")

exec bwrap "${bwrap_args[@]}"