Use unshare by default in linux to protect access
Abierto
area:platform-linux
- Lenguaje dominante
- Shell
- Estrellas
- 11.2k
- Forks
- 1.9k
- Merge medio
- 14 h 16 min
- PR fusionados (30 d)
- 6
Descripción
### Describe the feature or problem you'd like to solve
The tool should never have any kind of write access to places the users have not ack'ed for
### Proposed solution
I'm currently running copilot using bubblewrap to ensure it only works where I want via:
```sh
bwrap --ro-bind / / \
--bind "$PWD" "$PWD" \
--bind /tmp /tmp \
--bind "$HOME/.copilot" "$HOME/.copilot" \
--dev /dev \
--proc /proc \
--unshare-all \
copilot
```
This is something that the tool should do by default
### Example prompts or workflows
_No response_
### Additional context
_No response_
Guía de contribución
Evaluación
Este issue todavía no se ha evaluado.