fix(bwrap): bind CA directories at their resolved path - #183
Conversation
|
Thanks for the detailed report and a PR! Dropping the Before merging I'd like to confirm that certificates actually load inside the sandbox. devsandbox sh -c 'find -L /etc/ssl/certs /etc/pki/tls/certs -maxdepth 1 -type l | head'
devsandbox sh -c 'cat /etc/pki/tls/certs/ca-bundle.crt > /dev/null && echo ok'
devsandbox curl -sSI https://github.comThe first command lists broken links, so it should print nothing. If the others fail, the fix also needs to bind |
bubblewrap refuses to mount over a symlink destination, so on Fedora, where /etc/ssl/certs points at /etc/pki/tls/certs, every launch aborted with "bwrap: Can't mount on symlink destination /etc/ssl/certs". AddCABindings now binds the resolved target when a CA path is a symlink. The symlink is already visible in the sandbox through the /etc/ssl bind and resolves there, so certificates stay readable at both paths. Resolving the directory is not enough on its own: the certificate files inside it are symlinks too. On the Fedora/RHEL family /etc/pki/tls/certs holds ca-bundle.crt and the hashed *.0 names, all pointing into /etc/pki/ca-trust/extracted/, so /etc/pki/ca-trust is bound as well or they dangle and curl fails with "error setting certificate file". /etc/pki/tls is bound in place of /etc/pki/tls/certs so cert.pem comes along too. A CA path that exists but cannot be resolved now fails the launch instead of being skipped silently.
bec243b to
d5b5c6f
Compare
|
Thanks for your comment, I don't well understand theses parts and as you could presume, i use opencode / deepseek to code. |
|
Thank you for the contribution! |
bubblewrap refuses to mount over a symlink destination, so on Fedora, where /etc/ssl/certs points at /etc/pki/tls/certs, every launch aborted with "bwrap: Can't mount on symlink destination /etc/ssl/certs".
AddCABindings now binds the resolved target when a CA path is a symlink. The symlink is already visible in the sandbox through the /etc/ssl bind and resolves there, so certificates stay readable at both paths, and the target's own list entry means the mount is emitted once.
related to #181