Alexander Larsson
6bd603f683
persist directories: Pass using new bwrap --bind-fd option
...
Instead of passing a /proc/self/fd bind mount we use --bind-fd, which
has two advantages:
* bwrap closes the fd when used, so it doesn't leak into the started app
* bwrap ensures that what was mounted was the passed in fd (same dev/ino),
as there is a small (required) gap between symlink resolve and mount
where the target path could be replaced.
Please note that this change requires an updated version of bubblewrap.
Resolves: CVE-2024-42472, GHSA-7hgv-f2j8-xw87
[smcv: Make whitespace consistent]
Co-authored-by: Simon McVittie <smcv@collabora.com >
Signed-off-by: Simon McVittie <smcv@collabora.com >
2024-08-12 19:33:33 +01:00
..
2024-03-12 08:31:08 -05:00
2022-08-22 19:48:10 -07:00
2024-07-09 17:12:55 -03:00
2021-02-12 15:58:09 +01:00
2024-02-13 13:48:38 +00:00
2024-03-21 20:20:15 +00:00
2021-01-12 09:55:23 +01:00
2024-05-03 13:21:29 +01:00
2024-08-12 19:33:33 +01:00
2024-07-09 17:12:55 -03:00
2024-07-09 17:12:55 -03:00
2024-07-09 17:12:55 -03:00
2024-08-03 11:12:31 -05:00
2022-09-07 09:21:58 +02:00
2022-09-07 09:21:58 +02:00
2021-02-09 09:36:59 +01:00
2023-07-03 20:07:57 +02:00
2024-05-03 13:21:29 +01:00
2023-05-17 11:35:44 +01:00
2023-05-17 11:35:44 +01:00
2024-01-07 18:51:46 -06:00
2021-06-14 15:30:59 +01:00
2023-02-04 12:30:15 -06:00
2021-02-12 15:58:09 +01:00
2023-10-27 17:09:52 +01:00
2023-10-27 17:09:52 +01:00
2021-02-12 15:58:09 +01:00
2023-05-17 11:35:44 +01:00
2024-07-09 17:12:55 -03:00
2022-08-22 19:48:10 -07:00
2023-11-14 18:39:22 +00:00
2024-03-27 14:22:45 +00:00
2023-07-03 20:07:57 +02:00
2024-07-09 17:12:55 -03:00
2024-07-09 17:12:55 -03:00
2022-12-15 16:45:35 +00:00
2022-12-15 16:45:35 +00:00
2024-07-09 17:12:55 -03:00
2024-07-09 17:12:55 -03:00
2023-07-03 20:07:57 +02:00
2024-07-09 17:12:55 -03:00
2024-07-09 17:12:55 -03:00
2021-02-12 15:58:09 +01:00
2022-08-22 19:48:10 -07:00
2021-02-12 15:58:09 +01:00
2024-07-09 17:12:55 -03:00
2021-02-12 15:58:09 +01:00
2024-07-09 17:12:55 -03:00
2021-02-12 15:58:09 +01:00
2024-07-09 17:12:55 -03:00
2024-08-03 11:12:31 -05:00
2023-05-15 19:54:51 +01:00
2023-05-15 19:54:51 +01:00
2023-05-15 19:54:51 +01:00
2024-07-09 09:23:32 -03:00
2024-07-09 17:12:55 -03:00
2023-05-15 19:54:51 +01:00
2023-05-15 19:54:51 +01:00
2023-08-24 12:17:53 +02:00
2024-02-14 19:39:50 +00:00
2024-02-14 19:39:50 +00:00
2024-02-14 19:39:50 +00:00
2023-05-15 19:54:51 +01:00
2023-09-04 13:25:32 +01:00
2024-07-16 17:54:27 +01:00
2021-10-08 12:53:20 +02:00
2021-05-19 09:49:30 +02:00
2024-07-09 17:12:55 -03:00
2023-03-30 14:54:18 +02:00
2022-09-06 13:20:05 +02:00
2022-09-07 09:21:19 +02:00
2024-06-21 11:12:57 -03:00
2024-06-21 11:12:57 -03:00
2022-06-16 13:49:45 +02:00
2023-09-15 12:36:25 +01:00
2024-07-09 17:12:55 -03:00
2024-07-09 17:12:55 -03:00
2024-05-03 13:21:29 +01:00
2024-05-03 13:21:29 +01:00
2024-07-09 17:12:55 -03:00
2022-04-11 10:32:34 +02:00