Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 4cca1a6fbd865f91357509d42ad5254d30e8637b
      
https://github.com/WebKit/WebKit/commit/4cca1a6fbd865f91357509d42ad5254d30e8637b
  Author: Fujii Hironori <[email protected]>
  Date:   2026-09-27 (Sun, 27 Sep 2026)

  Changed paths:
    M Source/WebKit/UIProcess/Launcher/glib/FlatpakLauncher.cpp
    M Source/WebKit/UIProcess/Launcher/glib/ProcessLauncherGLib.cpp

  Log Message:
  -----------
  [GLib][Flatpak] Web processes are silently spawned without a sandbox if the 
app's working directory is not visible in the flatpak-spawn sub-sandbox
https://bugs.webkit.org/show_bug.cgi?id=325395

Reviewed by Patrick Griffis.

flatpak-spawn uses the caller's current working directory by default,
but the --sandbox sub-sandbox doesn't have the app's filesystem
permissions. If the app was started from such a directory,
isFlatpakSpawnUsable() failed with "bwrap: Can't chdir to ...", and
all web processes were spawned without a sandbox.

Pass --directory=/ to flatpak-spawn --sandbox both in
isFlatpakSpawnUsable() and flatpakSpawn(). --directory is supported
since flatpak-xdg-utils 1.0.1, which we already require.

Also log a warning when flatpak-spawn --sandbox is not usable.

* Source/WebKit/UIProcess/Launcher/glib/FlatpakLauncher.cpp:
(WebKit::flatpakSpawn):
* Source/WebKit/UIProcess/Launcher/glib/ProcessLauncherGLib.cpp:
(WebKit::isFlatpakSpawnUsable):

Co-Authored-By: Claude Opus 5.5 <[email protected]>
Canonical link: https://commits.webkit.org/322026@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to