<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Sandboxing on Ownchain Systems</title>
    <link>https://ownchain.systems/tags/sandboxing/</link>
    <description>Recent content in Sandboxing on Ownchain Systems</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Sun, 30 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://ownchain.systems/tags/sandboxing/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CODEX-005: Sandboxing vs. Storage Vaults: Flatpak, AppImage, and Native Packaging</title>
      <link>https://ownchain.systems/codex/005-sanbox-storage-boundaries/</link>
      <pubDate>Sun, 30 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://ownchain.systems/codex/005-sanbox-storage-boundaries/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; Filesystem Security &amp;amp; Runtime Sandboxing&#xA;&lt;strong&gt;Status:&lt;/strong&gt; Implemented &amp;amp; Verified&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;executive-summary&#34;&gt;Executive Summary&lt;/h2&gt;&#xA;&lt;p&gt;This report analyzes permission boundaries, filesystem isolation, and execution failures encountered when integrating sandboxed application formats (Flatpak and AppImage) with external storage vaults (such as &lt;code&gt;/mnt/lacie&lt;/code&gt;). It details the diagnostic triage of permission denials, FUSE execution restrictions, and the decision to standardize core system tooling on native package management.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;threat-model--problem-statement&#34;&gt;Threat Model &amp;amp; Problem Statement&lt;/h2&gt;&#xA;&lt;p&gt;Application isolation frameworks (Flatpak, AppImage) provide sandboxing by restricting default access to the host filesystem. However, when operational workflows require direct access to designated storage mounts, isolated runtimes introduce specific operational failure modes:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
