I've been saying that for a while. We need a viable third option.
But it is not easy, and it takes a huge amount of effort. As others have said, theres SailfishOS, Ubuntu Touch, PostmarketOS and a few others.
I'm not sure which one is in a better position to become that third alternative we need, but this year I'm experimenting with all of them on different devices, to try to understand where they stand.
Yes, there's SailfishOS, there's Ubuntu Touch, and a couple more. It would be nice if one of them could gain traction so people can have a third choice.
Nono has been my daily driver since the start of the year. It's not a perfect sandbox -- that's for sure. For example, the default network rules let you escape via a global TMUX server. But it is extremely practical. It gives me enough guarantees to feel confident about running in YOLO mode. So far nothing has gone awry.
Eg, if used with Colima in macOS, it means I can run a devcontainer in an isolated VM and Nono inside the devcontainer can restrict a lot what can and cannot be done.
You get credentials proxying and network outbound limits.
As you as your Go build fails because you haven't put the local cache dir in the "allowed directories", you'll understand how painful this is, as well as most tools based on bubblewrap/sandbox-exec. There is a difference between a clean environment with standard setup vs a layer on top of everyone's existing tools/setup, especially in a enterprise environment.
(I'm sure you can spend time to come up with a proper bubblewrap configuration that allows go build to succeed, but it's probably not worth the effort.)
But it is not easy, and it takes a huge amount of effort. As others have said, theres SailfishOS, Ubuntu Touch, PostmarketOS and a few others.
I'm not sure which one is in a better position to become that third alternative we need, but this year I'm experimenting with all of them on different devices, to try to understand where they stand.
"posted from an Ubuntu Touch mobile device"
reply