In Debian there is no such thing as stackable wrappers.
A wrapper in this context is defined as a minimal script that automatically prepends something in front of a program that the user wants to run.
Here are some examples of commands to prepend:
* firejail firefox
* torsocks gpg
* LD_PRELOAD="$LD_PRELOAD":libeatmydata.so rsync
* bindp, timeprivacy and probably a lot more
* probably quite some dpkg diversions used for that purpose
One can have one wrapper using dpkg-diversions / symlinks but it's getting harder to stack these wrappers. Specifically harder if these wrappers are supposed to be installed by different packages.
* dpkg diversions / symlinks:
** one can only have one dpkg diversion per command
** when using a dpkg-diversion for lets say curl to prepend torsocks then one can no longer use 'killall curl' but must use 'killall curl.dpkg-diversion-extension'
** these can break various things such as AppArmor profiles
** other weird things can happen, for example
*** '~/.local/share/Ricochet/ricochet/ricochet.json' becomes
* '.desktop' files
** '.desktop' files aren't a solution, since these do not work for applications started from a terminal emulator or virtual terminal.
** Not allowed for packages.
** Firejail currently uses /usr/local, but the user has to manually run firecfg, because automatically running it would be a Debian policy violation because writing to /usr/local is not allowed for packages.
* leaving it to the user
** Beginner users can't be expected to start a terminal every time they want to launch a program. This usability problem can be a hurdle for widespread adoption.
* amend PATH environment variable
** firejail wrappers will be installed to /usr/lib/firejail/ folder, i.e for example /usr/lib/firejail/firefox
** invent a drop-in folder to amend the path variable like /etc/path.d or so. For example:
*** would result in PATH being set to:
** by calling for example firefox, first the firejail wrapper /usr/lib/firejail/firefox would run, remove itself (/usr/lib/firejail/) from PATH, prepend firejail and run firefox, perhaps another user specific wrapper in /usr/local/bin/firefox could be run that finally runs the real firefox program in /usr/bin/firefox.
real world example:
* We at Whonix would like to prepend both, torssocks (for stream isolation) as well as firejail (as containment), in front of gpg
* Appending commands may also be useful. For example the user could add a wrapper that adds default command line parameters.
* firejail - Feature Request: Automatically starting programs under firejail - https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=822693
* improve draft
* send to debian-devel mailing list
* discuss on debian-devel