All my Windows games that I launch from Lutris (which are most, since I tend to avoid Steam and prefer GOG) are launched by default inside a Firejail container configured amongst other things to have no networking enabled.
All you need to do for it is to setup a “command prefix” with firejail and its launch parameters at the Lutris level and it becomes the default one for all games.
So yeah, this runs Wine inside an actual security solution and since it’s setup at the level or the launcher I use, it does it for all the games I launch from it.
I guess not allowing flatpak wine to access anything that is not necessary is the easiest way to achieve it. No idea if it is also the most secure solution.
Isn’t a way possible to prevent z:/ mapping while creating wine prefix ?
It’s not just the drive letter mapping, Wine doesn’t make any attempt to secure software.
You can run Wine inside an actual security solution.
All my Windows games that I launch from Lutris (which are most, since I tend to avoid Steam and prefer GOG) are launched by default inside a Firejail container configured amongst other things to have no networking enabled.
All you need to do for it is to setup a “command prefix” with firejail and its launch parameters at the Lutris level and it becomes the default one for all games.
So yeah, this runs Wine inside an actual security solution and since it’s setup at the level or the launcher I use, it does it for all the games I launch from it.
I guess not allowing flatpak wine to access anything that is not necessary is the easiest way to achieve it. No idea if it is also the most secure solution.