1.5 KiB
Elevation
Run a bash command outside the sandbox as the current user (not root). The command escapes the Landlock filesystem sandbox but does NOT gain superuser privileges.
What it does: Removes sandbox filesystem restrictions so the command can access paths the sandbox normally blocks (e.g., ~/.config/, /usr/lib64/, system directories). The command still runs as the logged-in user with that user's normal permissions.
What it does NOT do: It does not run as root. It does not sudo. If the target operation requires root (e.g., make install to /usr/), the user must handle privilege escalation themselves outside of this mechanism.
Trigger condition: a task requires filesystem access unavailable inside the sandbox — writing to paths outside the sandbox whitelist, reading protected config files, running commands that access restricted directories.
Calling convention:
execute_code: steps=[{code: "cp file.so /usr/lib64/qt6/plugins/kf6/ktexteditor/", elevated: true}]
Constraints:
- Briefly explain what the command does and why it needs elevation before running it.
elevated: trueis per-step — only apply to steps that need it.- Only bash is supported for elevated steps.
- Does NOT run as root. Cannot
apt install,make installto system dirs, or anything else requiring superuser unless the user has passwordless sudo configured. - May not be available on all systems; if absent, the step fails with "elevation not available".
- Blocks until the user approves or denies — this is expected, not an error.