The Linux sandbox skips pointless blocking mounts, so sandboxed runs start with less overhead.
What's wrong with this entry?
The bubblewrap argument builder now recognises when a non-existent deny path already sits inside a read-only denied directory and stops adding a mount to block it.
- new bookkeeping tracks write roots and their realpaths, deny directories and their realpaths, and a map of deny paths per allowed root
- in the redundant case it no longer mounts
/dev/nullor an empty temp dir to prevent creation, and logs that the path is already uncreatable - Linux sandbox only
Skipping non-existent deny path inside a read-only denied directory (already uncreatable)
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox