• Saprophyte@lemmy.world
    link
    fedilink
    arrow-up
    3
    arrow-down
    4
    ·
    2 days ago

    Yes, it has different wine instances for each installed application, it uses a flatpak style separation to prevent them from accessing each other.

    • bootleg@sh.itjust.works
      link
      fedilink
      arrow-up
      2
      ·
      8 hours ago

      It doesn’t have any containerization between instances. There is an experimental opt-in setting for it but it’s completely broken. It’s just sandboxed because of flatpak.

    • turdas@suppo.fi
      link
      fedilink
      arrow-up
      9
      ·
      1 day ago

      The reason I’m asking is that separate wineprefixes will look like a “different wine instance” to a layman, but they’re not the same thing as a sandbox. Wine mounts the host filesystem under the Z: drive, and even beyond that there are probably ways to escape the Wine environment. For true sandboxing some additional layers will be required.

      • Saprophyte@lemmy.world
        link
        fedilink
        arrow-up
        4
        arrow-down
        1
        ·
        edit-2
        1 day ago

        From a security standpoint, yes they can be broken out of, just like a docker or a virtual machine , but they use bubblewrap to isolate environments just like flatpaks. Malicious content aside they are just as isolated and sandboxed as a docker image or vm