Remove --as-pid-1 from the bwrap invocation
bwrap now runs its own small reaper as pid 1 inside the sandbox instead of execing the target command directly into that role. -e/--exec is unaffected: it resolves the real namespace-holding child dynamically via /proc rather than assuming any particular process identity, so it still joins the right namespaces with the extra reaper process in the tree. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Gv3s5jckJKzh6JkMoi2Akz
This commit is contained in:
+1
-7
@@ -188,7 +188,6 @@ std::vector<std::string> build_bwrap_args(const std::string& root,
|
|||||||
std::vector<std::string> args = {"bwrap", "--die-with-parent"};
|
std::vector<std::string> args = {"bwrap", "--die-with-parent"};
|
||||||
|
|
||||||
auto unshare_args = detect_bwrap_unshare_args();
|
auto unshare_args = detect_bwrap_unshare_args();
|
||||||
bool has_pid_ns = false;
|
|
||||||
bool has_uts_ns = false;
|
bool has_uts_ns = false;
|
||||||
for (const auto& arg : unshare_args) {
|
for (const auto& arg : unshare_args) {
|
||||||
// Not requested yet: without any network setup (slirp4netns or similar),
|
// Not requested yet: without any network setup (slirp4netns or similar),
|
||||||
@@ -200,15 +199,10 @@ std::vector<std::string> build_bwrap_args(const std::string& root,
|
|||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
args.push_back(arg);
|
args.push_back(arg);
|
||||||
if (arg == "--unshare-pid") {
|
if (arg == "--unshare-uts") {
|
||||||
has_pid_ns = true;
|
|
||||||
} else if (arg == "--unshare-uts") {
|
|
||||||
has_uts_ns = true;
|
has_uts_ns = true;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if (has_pid_ns) {
|
|
||||||
args.push_back("--as-pid-1");
|
|
||||||
}
|
|
||||||
|
|
||||||
if (hostname) {
|
if (hostname) {
|
||||||
// bwrap itself refuses --hostname without --unshare-uts, so this must be
|
// bwrap itself refuses --hostname without --unshare-uts, so this must be
|
||||||
|
|||||||
Reference in New Issue
Block a user