Snap

Canonical's Snap 2,571 packages an application as a compressed SquashFS image that snapd mounts read-only under /snap/<name>/<revision>, on top of a shared base snap such as core24. Each snap follows a channel (latest/stable, candidate, beta, edge) and refreshes automatically, four times a day by default. The kernel enforces confinement through AppArmor 454,622 and seccomp, and Canonical's hello-world snap includes a command, hello-world.evil, written to trip it.

Inspecting a snap and testing its confinement in WSLShell
snap info --verbose hello-world | grep -E 'tracking|confinement'
mount | grep 'hello-world/29'
snap debug confinement
hello-world.evil
Output
  confinement:       strict
tracking:     latest/stable
snapfuse on /snap/hello-world/29 type fuse.snapfuse (ro,nodev,relatime,user_id=0,group_id=0,all
  ow_other)
partial
Hello Evil World!
This example demonstrates the app confinement
You should see a permission denied error next
If you see this line the confinement is not working correctly, please file a bug

The snap declares strict confinement, yet the "evil" command reached its last line with no error: under WSL2 6 confinement is only partial, because the WSL kernel runs without AppArmor, and the image is mounted through snapfuse rather than the kernel's SquashFS driver. On a regular Ubuntu 225 machine the command ends with Permission denied. Snap's other trade-off is central control: snapd uses Canonical's Snap Store, whose server is not open source.