On Linux, if the sandbox can't set itself up it now stops instead of silently running half-protected.
What's wrong with this entry?
The Linux seccomp helper used to log an error and return undefined, letting startup continue with the sandbox half-configured. It now throws.
- The error is still reported, then constructed and thrown so the caller cannot proceed.
- The message text was rewritten to name the embedded apply-seccomp helper.
- Only on the Linux seccomp sandbox path.
sandbox: failed to open /proc/self/exe
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox