New features:
- Add
--disable-userns
option to prevent the sandbox from creating its own nested user namespace (#488) - Add
--assert-userns-disabled
option to check that an existing userns was created with--disable-userns
(#488) - Give a clearer error message if the kernel doesn't have
CONFIG_SECCOMP
andCONFIG_SECCOMP_FILTER
(#550)
Bug fixes:
- Fix test failure with recent versions of
capsh
(#544) - Fix test failure since 0.7.0 when not using post-2013 GNU coreutils (#539)
- Fix test failure since 0.7.0 if bubblewrap is setuid (#539)
Known issues:
- Tests fail if run as root (#554)
$ sha256sum -b bubblewrap-0.8.0.tar.xz
957ad1149db9033db88e988b12bcebe349a445e1efc8a9b59ad2939a113d333a *bubblewrap-0.8.0.tar.xz