• Saprophyte@lemmy.world
    link
    fedilink
    arrow-up
    2
    arrow-down
    3
    ·
    21 hours ago

    Yes, it has different wine instances for each installed application, it uses a flatpak style separation to prevent them from accessing each other.

    • turdas@suppo.fi
      link
      fedilink
      arrow-up
      9
      ·
      18 hours ago

      The reason I’m asking is that separate wineprefixes will look like a “different wine instance” to a layman, but they’re not the same thing as a sandbox. Wine mounts the host filesystem under the Z: drive, and even beyond that there are probably ways to escape the Wine environment. For true sandboxing some additional layers will be required.

      • Saprophyte@lemmy.world
        link
        fedilink
        arrow-up
        3
        ·
        edit-2
        8 hours ago

        From a security standpoint, yes they can be broken out of, just like a docker or a virtual machine , but they use bubblewrap to isolate environments just like flatpaks. Malicious content aside they are just as isolated and sandboxed as a docker image or vm