Description
Sandboxed processes can be launched through the setuid variant of Bubblewrap for systems that need that privilege model. It is useful only when the normal unprivileged setup is not suitable for the target environment.
This is a low-level sandboxing tool with elevated privilege implications. Use the setuid variant only when necessary, keep it updated, and understand the profiles or wrappers that depend on it.