Skip to content

Directory at /proc/{PID}/root doesn't match root of the sandbox #589

Description

@StandingPadAnimations

While debugging some issues related to portals (flatpak/xdg-desktop-portal#1076), it seems like the root folder in /proc/{PID} (where PID is the PID of the command ran by bwrap) doesn't match what is expected in the sandboxed environment, which causes issues when trying to use portals.

For instance, I have a .flatpak-info file in the root folder of the sandboxed environment (required for portals to work correctly), but said file does not appear in the root folder of /proc/{PID}.

Of course the program still reports the filesystem correctly, but other programs like xdg-desktop-portal will behave differently then intended

Activity

  1. rusty-snake commented on Aug 22, 2023

    @rusty-snake
    Contributor

    WFM

    Can you give more STR like bwrap command (as minimal as reproducible at best) and how you find the pid.

    bwrap --unshare-all --share-net --symlink usr/lib /lib --symlink usr/lib64 /lib64 --symlink usr/bin /bin --symlink usr/sbin /sbin --ro-bind /usr /usr --ro-bind /etc /etc --dev /dev --proc /proc --dir /tmp --new-session --ro-bind-data 3 /.flatpak-info bash 3<<EOF 
    [Application]
    name=org.mozilla.firefox
    EOF
    $ ps -efH
    [...]
    rusty-snake    380653  [...]         bwrap --unshare-all --share-net --symlink usr/lib /lib --symlink usr/lib64 /lib64 --symlink usr/bin /bin --symlink usr/sbin /sbin --ro-bind /usr /usr --ro-bind /etc /etc --dev /d
    rusty-snake    380654  [...]           bwrap --unshare-all --share-net --symlink usr/lib /lib --symlink usr/lib64 /lib64 --symlink usr/bin /bin --symlink usr/sbin /sbin --ro-bind /usr /usr --ro-bind /etc /etc --dev 
    rusty-snake    380655  [...]             bash
                   ^^^^^^
    [...]
    $ cat /proc/380655/root/.flatpak-info
    [Application]
    name=org.mozilla.firefox

    required for portals to work correctly

    • required for portals to work correctly with flatpaks
    • for everything else that is not a flatpak, it is a hacky workaround to make one thing work and break two others or break your system (e.g. "if I copy it to my root directory as .flatpak-info, well things start getting funny with my desktop").
    • Just to be clear that this is not something officially supported or recommended by the x-d-p authors.
  2. StandingPadAnimations commented on Aug 22, 2023

    @StandingPadAnimations
    Author

    Closing this since I realized it was user error

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions