Skip to content

cover non-dumpable sandbox startup - #105

Merged
zhenthebuilder merged 2 commits into
mainfrom
fix/non-dumpable-sandbox-startup
Sep 11, 2026
Merged

cover non-dumpable sandbox startup#105
zhenthebuilder merged 2 commits into
mainfrom
fix/non-dumpable-sandbox-startup

Conversation

@zhenthebuilder

Copy link
Copy Markdown
Contributor

Avoid unnecessary cwd and dirfd resolution for absolute open/openat paths and add regression coverage. The current regression suite still has failures; this branch is not ready to merge.

Assisted-by: Replit

Avoid unnecessary cwd and dirfd resolution for absolute open/openat paths and add regression coverage. The current regression suite still has failures; this branch is not ready to merge.

Assisted-by: Replit
Complete the trusted AppArmor-on-exec setup before tracing the child so inherited non-dumpability does not block shell startup. Keep dumpability and file enforcement unchanged, replace the insufficient absolute-path workaround, and add shared-setup regression coverage with isolated test fixtures.

Assisted-by: Replit
@zhenthebuilder
zhenthebuilder merged commit 2c1b59c into main Sep 11, 2026
13 checks passed
@zhenthebuilder
zhenthebuilder deleted the fix/non-dumpable-sandbox-startup branch September 11, 2026 20:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants