1.8 KiB
Elevation
Run a bash command outside the sandbox as the current user (not root). The command escapes the Landlock filesystem sandbox but does NOT gain superuser privileges.
What it does: Removes sandbox filesystem restrictions so the command can access paths the sandbox normally blocks (e.g., ~/.config/, /usr/lib64/, system directories). The command still runs as the logged-in user with that user's normal permissions.
What it does NOT do: It does not run as root. It does not sudo. If the target operation requires root (e.g., make install to /usr/), the user must handle privilege escalation themselves outside of this mechanism.
Trigger condition: a command has already failed with a permission denied error inside the sandbox, proving that elevation is necessary. Do NOT use elevation preemptively.
Procedure:
- Always try without elevation first. Run the command normally inside the sandbox.
- Only if it fails with a permission/access error (e.g.,
Permission denied,No such file or directoryfor a path outside the sandbox), retry withelevated: true. - Never assume elevation is needed based on the path alone — the sandbox whitelist may already cover it.
Calling convention:
execute_code: steps=[{code: "cp file.so /usr/lib64/qt6/plugins/kf6/ktexteditor/", elevated: true}]
Constraints:
elevated: trueis per-step — only apply to steps that need it.- Only bash is supported for elevated steps.
- Does NOT run as root. Cannot
apt install,make installto system dirs, or anything else requiring superuser unless the user has passwordless sudo configured. - May not be available on all systems; if absent, the step fails with "elevation not available".
- Blocks until the user approves or denies — this is expected, not an error.