Thank you for reporting this bug.

This problem is something we’ve been investigating for a while internally. We 
need to improve the user experience around installing snaps when we know the 
sandbox confinement is not what we designed it for. Right now the consequence 
of that is that large chunk of the sandbox is disabled and we claim (as seen by 
“snap debug confinement”) that the confinement is *partial*. We’d like to 
improve the language around that and use more of the available features, even 
if some specific bits are missing. In this case we could still use the file, 
path based confinement as long as we can clearly communicate to the user that 
installed applications are not strictly confined in some sense, here it would 
be, I believe fine-grained DBus mediation that is missing.

The bottom line, we acknowledge the bug and are looking at best options for 
snapd 2.41.

Reply via email to