Problem
In SandboxLaunchCommand (lib/core/extensions/sandbox/sandbox_launch_command.dart, lines 101–111, 162–175):
- Linux (bubblewrap):
final args = <String>[
'--unshare-all',
'--share-net',
'--die-with-parent',
'--new-session',
'--ro-bind', '/', '/',
'--bind', scratchPath, scratchPath,
'--chdir', scratchPath,
];
--ro-bind / / mounts the entire root filesystem read-only inside the container.
Combined with --share-net (which is required for database drivers to communicate with database servers), an untrusted or compromised extension driver can read:
~/.ssh/ (SSH private keys and known hosts)
~/.aws/credentials, ~/.config/gcloud/
~/.bash_history, ~/.zsh_history
- Local profile databases and browser session stores
and exfiltrate them over the network.
- macOS (Seatbelt / sandbox-exec):
(version 1)
(deny default)
(allow process*)
(allow sysctl-read)
(allow mach-lookup)
(allow network*)
(allow file-read*)
(allow file-write* (subpath "$scratchPath"))
(allow file-read*) allows reading every file across the host filesystem. Combined with (allow network*), any extension process can read and exfiltrate user files without restrictions.
Scope
- In Linux
bwrap configuration:
- Mount system library paths (
/usr, /lib, /lib64, /etc/ssl, /etc/resolv.conf, /dev, /proc) rather than full /, OR mask /home via --tmpfs /home (or --tmpfs $HOME), binding only the specific extension directory and scratch directory.
- In macOS Seatbelt profile:
- Replace global
(allow file-read*) with permissions restricted to system libraries and the extension bundle/scratch directory, explicitly denying (deny file-read* (subpath "/Users")) or sensitive home paths (~/.ssh, ~/Library/Keychains).
- Add tests in
sandbox_launch_command_test.dart verifying that host home directory read access is masked in both Linux and macOS launch commands.
Problem
In
SandboxLaunchCommand(lib/core/extensions/sandbox/sandbox_launch_command.dart, lines 101–111, 162–175):--ro-bind / /mounts the entire root filesystem read-only inside the container.Combined with
--share-net(which is required for database drivers to communicate with database servers), an untrusted or compromised extension driver can read:~/.ssh/(SSH private keys and known hosts)~/.aws/credentials,~/.config/gcloud/~/.bash_history,~/.zsh_historyand exfiltrate them over the network.
(allow file-read*)allows reading every file across the host filesystem. Combined with(allow network*), any extension process can read and exfiltrate user files without restrictions.Scope
bwrapconfiguration:/usr,/lib,/lib64,/etc/ssl,/etc/resolv.conf,/dev,/proc) rather than full/, OR mask/homevia--tmpfs /home(or--tmpfs $HOME), binding only the specific extension directory and scratch directory.(allow file-read*)with permissions restricted to system libraries and the extension bundle/scratch directory, explicitly denying(deny file-read* (subpath "/Users"))or sensitive home paths (~/.ssh,~/Library/Keychains).sandbox_launch_command_test.dartverifying that host home directory read access is masked in both Linux and macOS launch commands.