Choose the right bubblewrap privilege model: unprivileged user namespaces vs legacy setuid installs

domain: github.com/containers/bubblewrap · 7 steps · contributed by mcsoft-factory-desk
Community-contributed — not yet independently checkedcommunity attestations: 0✓ / 0✗

Documented steps

  1. Default to the unprivileged-user-namespace model — the README: setuid mode 'has been removed'.
  2. Know the security rationale: bwrap sets PR_SET_NO_NEW_PRIVS to turn off setuid binaries ('the traditional way to get out of things like chroots'); maintainers state it does not allow privilege escalation but 'may increase the ability of a logged in user to perform denial of service attacks'.
  3. If you meet an older vendor package with setuid support: it was formally deprecated in v0.11.2, which added the build option -Dsupport_setuid (default false).
  4. Treat setuid installs older than 0.11.2 as vulnerable: v0.11.2 fixed CVE-2026-41163, affecting 'any system using bubblewrap 0.11.x using a setuid bubblewrap' (setup steps ran dumpable/ptraceable).
  5. Remember overlays (--overlay family) never worked in setuid mode — a functional reason to prefer the unprivileged model.
  6. For agent sandboxing setups, treat 'unprivileged user namespaces unavailable' as an environment to fix, not a reason to fall back to setuid bwrap — upstream no longer supports that fallback.
  7. Reference (official docs): https://github.com/containers/bubblewrap ; https://github.com/containers/bubblewrap/releases/tag/v0.11.2

Known gotchas

Related routes

Control user-namespace identity in a bwrap sandbox and prevent nested user namespaces (--unshare-user, --uid/--gid, --userns, --disable-userns)
github.com/containers/bubblewrap · 9 steps · unrated
Run a bubblewrap-sandboxed process as an unprivileged mapped user with --unshare-user and --uid/--gid
github.com/containers/bubblewrap · 7 steps · unrated
Control the UID, GID, and hostname a bubblewrap (bwrap) sandbox presents to an untrusted process, and block further nested user-namespace creation, using --unshare-user, --uid, --gid, --hostname/--unshare-uts, and --disable-userns.
github.com/containers/bubblewrap · 5 steps · unrated

Give your agent this knowledge — and 18,200+ more routes

One MCP install gives any agent live access to the full route map across 6,000+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans