Skip to content

ci: install bubblewrap for the extension sandbox tests - #1207

Merged
ZhuchkaTriplesix merged 1 commit into
devfrom
issue/skipped-sandbox-mysql-tests
Oct 9, 2026
Merged

ZhuchkaTriplesix merged 1 commit into
devfrom
issue/skipped-sandbox-mysql-tests

Conversation

@ZhuchkaTriplesix

@ZhuchkaTriplesix ZhuchkaTriplesix commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Why

e2e_extension_sandbox_security_test.dart checks that code inside bubblewrap cannot write to the host. It skips when bwrap is not usable, and CI never installed it, so the check never ran.

Change

  • bubblewrap is installed in the test job next to libsecret-1-dev.

Not verified locally

Tests were not run locally, per the project rule. Two outcomes are possible in CI:

  • The test runs and passes: the sandbox check is now active.
  • The test runs and fails: the sandbox lets a write through, or the runner blocks user namespaces. That is a finding to act on, not a reason to skip the test again.

The sandbox security tests skip when bwrap is missing, so the one check that
the sandbox stops a write to the host never ran in CI.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant