Linux sandbox write paths now match both literal and resolved forms, so symlinked directories behave consistently.
What's wrong with this entry?
On Linux, sandbox write paths have trailing slashes stripped before binding, with a bare / preserved, and allowed write paths are matched against both their literal and fully resolved forms so symlinked directories are shadowed consistently.
- Applies to the bubblewrap sandbox only.
- The path lists, including directories considered for read-denial, are now computed on demand rather than upfront.
allowedWritePathsBothForms
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox