Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: enable setuid sandbox on linux (backport: 5-0-x) #17343

Conversation

trop[bot]
Copy link
Contributor

@trop trop bot commented Mar 11, 2019

Backport of #17269

See that PR for details.

Notes: Enabled the setuid sandbox on Linux, allowing Electron to launch sandboxed processes in environments that disable CLONE_NEWUSER for unprivileged users.

@electron-cation electron-cation bot added the new-pr 🌱 PR opened in the last 24 hours label Mar 11, 2019
@trop trop bot mentioned this pull request Mar 11, 2019
6 tasks
@trop trop bot added 5-0-x backport This is a backport PR labels Mar 11, 2019
@electron-cation electron-cation bot removed the new-pr 🌱 PR opened in the last 24 hours label Mar 11, 2019
@nornagon nornagon changed the title feat: enable setuid sandbox on linux (backport: 5-0-x) fix: enable setuid sandbox on linux (backport: 5-0-x) Mar 12, 2019
@nornagon
Copy link
Member

This isn't really a feat in that it doesn't add any new API surface. It fixes an issue with sandboxing that was exposed in 5-0-x related to the fact that we now enable mixed-sandbox mode by default.

Copy link
Member

@ckerr ckerr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For the record, @electron/wg-releases OK'ed this for 5-0-x in the 2019-03-13 meeting

Copy link
Member

@codebytere codebytere left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving on behalf of Releases WG

@codebytere codebytere merged commit 3e999ca into electron:5-0-x Mar 14, 2019
@release-clerk
Copy link

release-clerk bot commented Mar 14, 2019

Release Notes Persisted

Enabled the setuid sandbox on Linux, allowing Electron to launch sandboxed processes in environments that disable CLONE_NEWUSER for unprivileged users.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
5-0-x backport This is a backport PR
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants