On Linux, sandboxed writes land in the right place instead of being wrongly diverted into a temporary overlay.
What's wrong with this entry?
The bubblewrap argument builder tracks bound paths more accurately, so writes are not wrongly redirected into a temporary overlay.
- the realpath of each bound directory is also pushed when it differs from the given path
- a deny-only root is expanded into its top-level children, skipping
proc,devandsys - the ssh config drop-in directory is included when present
- these sets decide whether a would-be write path is already covered before a temporary overlay is created
- Linux only
/etc/ssh/ssh_config.d
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox