Locked-down defences#
The main isolation controls and the verification checks that inspect them. A passing check is evidence for its stated assertion, not a complete proof against every attack on that interface.
Defence → primitive → check#
Defence |
bwrap primitive |
Verify |
|---|---|---|
Sandbox is actually entered |
|
check 01 |
Setuid escalation blocked |
|
check 02 |
Home credentials masked |
|
check 03 |
Host env vars scrubbed |
|
checks 04, 05 |
No effective capabilities |
|
check 06 |
PID namespace (kill/ptrace scoping) |
|
check 07 |
SysV IPC namespace |
|
check 08 |
UTS namespace |
|
check 09 |
TIOCSTI terminal injection blocked |
|
check 10 |
VS Code IPC bridges masked |
|
check 11 |
User runtime dir masked |
|
check 12 |
Docker/Compose secrets masked |
|
check 13 |
|
|
check 14 |
|
|
check 15 |
Curated gitconfig in effect |
|
check 16 |
Chrome browser-extension RPC channel disabled |
shadow injects |
check 03 (regression manifests as browser dirs under |
Entry-point names stay the shadow’s (Invariant 1) |
|
check 22 |
Lateral-movement egress isolation |
netns + |
checks 19–20 inspect blackhole routes and representative destinations; a disabled jail is reported as a pass with a note |
Launch code cannot be redirected |
not a bwrap primitive: the shim runs |
CI only ( |
Reading the results#
Check 06 inspects effective capabilities (CapEff=0), not the bounding set.
Checks 19–20 inspect network routes but report a deliberately disabled jail
as a pass with a note. Read those notes before concluding that network
isolation is enabled.
Missing namespace or network-jail prerequisites cause launch to fail.
--die-with-parent also terminates bubblewrap when its parent dies.
See Architecture for the launch sequence and
Sandbox internals for the interpreter
and the entry-point guard.