155
What do you use Waydroid for?
(sh.itjust.works)
From Wikipedia, the free encyclopedia
Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).
Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.
Community icon by Alpár-Etele Méder, licensed under CC BY 3.0
To make my system less secure lol
It is true that Waydroid isn't super secure. that being said, it is still just a mostly stock android (unless you download gapps). Root is not exposed to the container so unless an exploit is found it is reasonably secure. There are measures waydroid can take to make it more secure. but as it stands it's "not bad"
Android relies on SELinux for its app sandbox. On Fedora the Waydroid package has some SELinux rules, but not sure if they are as good.
Daniel Micay answered under a Waydroid issue and at least on Android I fully trust his knowledge.
I dont know about exposed root, but Waydroid uses LXC containers and not rootless Podman/Docker.
The best solution would either be:
as far as I know the SELinux container is configured, whether or not the distro uses it isn't up to waydroid but the packaging and host configuration. If there are issues with the SELinux implementation they need to be brought up.
Waydroid also supports apparmor for some protections when SELinux is not available. OFC it's not as good as selinux (and currently it's set in warning mode so it doesn't actually offer protections out of box, please we need people testing this) https://github.com/waydroid/waydroid/pull/906
If you want to use a VM, and anyone who needs a highish level of security should. Bliss OS is a much better option. Though it doesnt offer "native integration" with the host.