- Jan 31, 2023
-
-
Julien (jvoisin) Voisin authored
-
- Jan 28, 2023
-
-
Julien (jvoisin) Voisin authored
-
Julien (jvoisin) Voisin authored
-
- Aug 28, 2022
-
-
Julien (jvoisin) Voisin authored
-
- Aug 05, 2022
-
-
Julien (jvoisin) Voisin authored
-
- Nov 13, 2020
-
-
Julien (jvoisin) Voisin authored
This is now required by ffmpeg
-
Julien (jvoisin) Voisin authored
-
- Feb 11, 2020
-
- Dec 18, 2019
-
-
Ivy Fay authored
Mounting new, empty filesystem on /tmp makes impossible to use mat2 for manipulating files stored there. Especially it breaks running tests while creating package and using /tmp as temporary builddir which is common setup in Arch Linux: https://aur.archlinux.org/packages/mat2/#comment-721221
-
- Nov 26, 2019
-
-
Julien (jvoisin) Voisin authored
-
- Oct 12, 2019
-
-
Julien (jvoisin) Voisin authored
Due to bubblewrap's pickiness, mat2 can now be run without a sandbox, even if bubblewrap is installed.
-
- Oct 05, 2019
-
-
This mounts a new tmpfs on /tmp so any files residing there would be hidden from the sandbox. Many programs store some files in there that might be useful to an attacker. It also drops all capabilities incase it is ever run with extra capabilities for whatever reason.
-
- Sep 21, 2019
-
-
Julien (jvoisin) Voisin authored
On some machines (like mine), `/proc` has to be mounted. Also, since sandboxing with bubblewrap is best effort and assumes that an attacker doesn't have control outside of the file to clean, it's safe to __try__ to enable some bubblewrap features, and to silently fail otherwise.
-
- Feb 09, 2019
-
-
Julien (jvoisin) Voisin authored
-
Poncho authored
without /etc/ld.so.cache available in the sandbox, tests fail on gentoo with: /usr/bin/ffmpeg: error while loading shared libraries: libstdc++.so.6: cannot open shared object file: No such file or directory
-
- Feb 03, 2019
-