Have a specific exit code for when sandboxing is not possible
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 45/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- c, linux
- Domain
- cli, operating-systems, security
Research direction
Start by tracing bwrap's handling of failed clone syscalls and how it currently returns exit code 1. Define a distinct exit code for sandboxing-unavailable failures, preserve other failure behavior, and verify the resulting status through the relevant command paths.
Written by the indexing model from the issue text.
Description
Since there are a bunch of environments where sandboxing doesn't work like in a libgnome-desktop sandbox or some CIs, we want to do opportunistic sandboxing. We are now doing this in glycin by testing if bwrap was called with SIGSYS (happens in CIs) or if it's STDERR contains a string indicating that spawning failed due to failing to create namespace glycin!295.
While there is no clear answer to what "sandboxing not being available" means, at least for the failed clone syscalls it would be good to have a more specific exit code than just 1. Following the 128+n convention would be one option.
- Dominant language
- C
- Stars
- 8.9k
- Forks
- 391
- Avg merge
- 17h 45m
- Merged PRs (30d)
- 10
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from containers/bubblewrap
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
containers/bubblewrap#813 · 1 reaction ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
containers/bubblewrap#767 · 2 comments ·
Maintainers usually reply within 1 day
-
Related project comparisons in README.md are outdatedMay be free again A pull request for this issue was closed without being merged. Open
Difficulty 1/5 Under an hour Newbie friendliness 88/100
containers/bubblewrap#743 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
containers/bubblewrap#298 · 4 comments · 5 reactions ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 52/100
containers/bubblewrap#811 ·
Maintainers usually reply within 1 day
All issues in containers/bubblewrap
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
UNIVERSE-HPC/course-material#283 ·
-
bug C/C++ code
Difficulty 1/5 Under an hour Newbie friendliness 78/100
webarkit/WebARKitLib#85 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 75/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 72/100