An exciting development for this Linux app sandboxing and distribution tech. This would also help improve Google Chrome/Chromium support outside the likes of RPM and Debian based distributions with a cleaner packaging experience.
That’s what he said.



Flatpak does block userns. Apps on Android don’t get unprivileged user namespaces, and Chromium is at its strongest on Android. So I have to assume there is some way of making it secure inside an app sandbox.
I thought Chrome (and Vanadium on GrapheneOS) are usually preinstalled as system apps, does it have the same limitation?