Skip to content

fix(bwrap): bind CA directories at their resolved path - #183

Merged
zekker6 merged 1 commit into
zekker6:mainfrom
ErikAouizerate:fix/ca-symlink-mount-dest
Sep 30, 2026
Merged

zekker6 merged 1 commit into
zekker6:mainfrom
ErikAouizerate:fix/ca-symlink-mount-dest

Conversation

@ErikAouizerate

Copy link
Copy Markdown
Contributor

bubblewrap refuses to mount over a symlink destination, so on Fedora, where /etc/ssl/certs points at /etc/pki/tls/certs, every launch aborted with "bwrap: Can't mount on symlink destination /etc/ssl/certs".

AddCABindings now binds the resolved target when a CA path is a symlink. The symlink is already visible in the sandbox through the /etc/ssl bind and resolves there, so certificates stay readable at both paths, and the target's own list entry means the mount is emitted once.

related to #181

@zekker6

zekker6 commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Thanks for the detailed report and a PR!

Dropping the /etc/ssl/certs entry would also get the launch working on Fedora, but only because /etc/pki/tls/certs happens to be in the list already. A distro whose link points somewhere else would be left with a dangling symlink. One nit: when resolveMountRulePath fails, the path is skipped with no message. Please make sure error is being propagated and fails to start the sandbox instead.

Before merging I'd like to confirm that certificates actually load inside the sandbox. ls /etc/ssl/certs | wc -l also counts dangling symlinks. On Fedora, the entries in /etc/pki/tls/certs (such as ca-bundle.crt) point into /etc/pki/ca-trust/extracted/, and nothing binds that path. /etc/pki/tls/cert.pem isn't bound either. Can you run these with your fix applied?

devsandbox sh -c 'find -L /etc/ssl/certs /etc/pki/tls/certs -maxdepth 1 -type l | head'
devsandbox sh -c 'cat /etc/pki/tls/certs/ca-bundle.crt > /dev/null && echo ok'
devsandbox curl -sSI https://github.com

The first command lists broken links, so it should print nothing. If the others fail, the fix also needs to bind /etc/pki/ca-trust, and probably /etc/pki/tls in place of /etc/pki/tls/certs.

bubblewrap refuses to mount over a symlink destination, so on Fedora, where
/etc/ssl/certs points at /etc/pki/tls/certs, every launch aborted with
"bwrap: Can't mount on symlink destination /etc/ssl/certs".

AddCABindings now binds the resolved target when a CA path is a symlink. The
symlink is already visible in the sandbox through the /etc/ssl bind and
resolves there, so certificates stay readable at both paths.

Resolving the directory is not enough on its own: the certificate files inside
it are symlinks too. On the Fedora/RHEL family /etc/pki/tls/certs holds
ca-bundle.crt and the hashed *.0 names, all pointing into
/etc/pki/ca-trust/extracted/, so /etc/pki/ca-trust is bound as well or they
dangle and curl fails with "error setting certificate file". /etc/pki/tls is
bound in place of /etc/pki/tls/certs so cert.pem comes along too.

A CA path that exists but cannot be resolved now fails the launch instead of
being skipped silently.
@ErikAouizerate
ErikAouizerate force-pushed the fix/ca-symlink-mount-dest branch from bec243b to d5b5c6f Compare September 30, 2026 07:25
@ErikAouizerate

Copy link
Copy Markdown
Contributor Author

Thanks for your comment, I don't well understand theses parts and as you could presume, i use opencode / deepseek to code.
Hope is good this time.

@zekker6

zekker6 commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Thank you for the contribution!

@zekker6
zekker6 merged commit 479844c into zekker6:main Sep 30, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants