← Back to context

Comment by 0c3ca83

3 hours ago

- Ghostty (fine, it's my terminal)

But your terminal shouldn't be accessing any files; you just need to be able to launch /bin/zsh or whatever you use as your shell. The shell needs to be able to access files, but its container doesn't.

Of course, you could go farther. For example, on OpenBSD, even /bin/ksh has been somewhat sandboxed; it can see most of the file system, but the things it can do have been limited:

  if (pledge("stdio rpath wpath cpath fattr flock getpw proc "
      "exec tty id", NULL) == -1) {

If you try to ls / for example it's going to pop up a request to access your disk, multiple times. It's rather annoying.

  • Why would ghostty try to access your disk when you run 'ls /'? ghostty isn't opening any files -- ls is.

macOS attributes shell commands to their parent app bundle.

  • That seems like a massive hole in the model that would make it very hard to lock down multi-process/privsep programs like sshd.

  • Indeed. It’s very inconvenient to ‘cd` and have to do the whole permission dance to read a file