Can a packaged app run headless Chromium with its sandbox on?
-
We are preparing a community package for Crawl4AI, which fetches web pages with a real headless Chromium and returns them as clean text for language models.
Chromium protects the host by running each page's renderer inside its own sandbox. On Linux that sandbox needs either unprivileged user namespaces or the setuid
chrome-sandboxhelper. When neither is available, the only way to start Chromium is--no-sandbox, and upstream's image ships exactly that flag, with a comment saying a renderer exploit can then reach the container.Upstream suggests two ways to turn the sandbox back on: allow unprivileged user namespaces on the host, or run the container with a custom seccomp profile. As far as we can tell, a package can do neither: the manifest has no seccomp setting, and host sysctls are outside the package.
A crawler is software that deliberately opens untrusted pages, so we would rather not ship it unsandboxed without asking first. Three questions:
-
Inside an app container on Cloudron 9.x, are unprivileged user namespaces (
unshare --user) allowed, or are they blocked by Docker's default seccomp profile or AppArmor on the host? -
Is
no-new-privilegesset on app containers? If not, would a setuidchrome-sandboxhelper be an acceptable route, or does the platform discourage setuid binaries in packages? -
How do existing apps that bundle Chromium handle this? Do they all run
--no-sandbox, and is that the accepted practice here?
If the answer is that
--no-sandboxis the only option, we plan to say so plainly in the app description, keep the API token mandatory, and rely on the container's own isolation. If there is a better route, we would like to use it.We can test whatever is suggested on our staging Cloudron and report back here.
-
-
Hello @loudlemur
Not sure if helpful, but @brutalbirdie did package https://git.cloudron.io/elias/browserless-cloudron-app/ which uses playwright chrome, msedge, chromium, firefox, webkit browsers.
If I remember correctly browserless runs all browsers inside docker with--no-sandbox -
Hello @loudlemur
Not sure if helpful, but @brutalbirdie did package https://git.cloudron.io/elias/browserless-cloudron-app/ which uses playwright chrome, msedge, chromium, firefox, webkit browsers.
If I remember correctly browserless runs all browsers inside docker with--no-sandbox
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login