Fix seatbelt sandbox symlink handling for rules - #60
Open
joshvoigts wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem: When a file like
~/.gitconfigis a symlink (e.g., pointing into a Dropbox folder), the seatbelt sandbox's path normalization was resolving through symlinks viacanonicalize(). This meant the path written into the sandbox policy would be the target path rather than the symlink path the user specified, causing the rule to not match correctly.Changes:
normalize_path_for_sandboxnow usescanonicalize_preserving_symlinksinstead ofcanonicalize(), so symlink paths stay as-is when written into the seatbelt policy. This means a user-specified path like~/.gitconfig(a symlink) remains that way in the policy and matches correctly.canonicalize_glob_static_prefix_for_sandbox(used for deny rules) continues to usecanonicalize()to resolve through symlinks. This ensures the deny regex matches the actual target regardless of how the user refers to it.FileSystemAccessMode::Nonefallback: Fix due to an upstream change.Additional thoughts
Not sure if it would be worth opening a PR upstream as well...