Guide on how to use firejail and Xpra to securely sandbox Linux applications, including no-network trivial example, more complicated example of an AppImage-based chat program setup with no root, private namespaces and X11 session, convenient use of ready profiles, client-server sandboxing for local and remote X11 desktops, other tips and tricks, some mild ranting, and more