# Sandbox prevent file read?

**URL:** <https://mangoh.discourse.group/t/sandbox-prevent-file-read/6349>\
**Category:** mangOH Yellow\
**Created:** [March 15, 2021, 10:39pm UTC](https://mangoh.discourse.group/t/sandbox-prevent-file-read/6349 "2021-03-15T22:39:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jameswollaeger](https://avatars.discourse-cdn.com/v4/letter/j/e495f1/32.png) [@jameswollaeger](https://mangoh.discourse.group/u/jameswollaeger)\
**Post date:** [March 15, 2021, 10:39pm UTC](https://mangoh.discourse.group/t/sandbox-prevent-file-read/6349/1 "2021-03-15T22:39:12Z")

</div>

Hi,

I was trying to connect to a 3rd party MQTT server and had to add a private CA to the ca-certificates.crt file, so I added the cert and uploaded to the mangoh yellow board. But after that, I cannot connect as I’m getting the following errors:

Mar 15 17:29:39 swi-mdm9x28-wp user.notice kernel: [16173.861156] audit: type=1400 audit(1615847379.191:46): lsm=SMACK fn=smack\_inode\_getattr action=denied subject=“app.requestController” object=“admin” requested=r pid=17075 comm=“mqttClientServi” path=“pipe:[194068]” dev="pipe  
Mar 15 17:29:40 swi-mdm9x28-wp user.notice kernel: [16175.042740] audit: type=1400 audit(1615847380.371:47): lsm=SMACK fn=smack\_inode\_permission action=denied subject=“app.requestController” object=“admin” requested=x pid=17075 comm=“mqttClientServi” name=“ssl” dev=“ubifs” ino=  
Mar 15 17:29:41 swi-mdm9x28-wp user.notice kernel: [16176.044736] audit: type=1400 audit(1615847381.371:48): lsm=SMACK fn=smack\_inode\_permission action=denied subject=“app.requestController” object=“admin” requested=x pid=17075 comm=“mqttClientServi” name=“ssl” dev=“ubifs” ino=

Is this because the app cannot read the partition. I note that the original folder is mostly file links to a different location.

lrwxrwxrwx 1 root root 74 Mar 2 13:07 c089bbbd.0 → …/…/…/usr/share/ca-certificates/mozilla/thawte\_Primary\_Root\_CA\_-_G2.crt  
lrwxrwxrwx 1 root root 107 Mar 2 13:07 c0ff1f52.0 → …/…/…/usr/share/ca-certificates/mozilla/Verisign\_Class\_3\_Public\_Primary\_Certification\_Authority_-_G3.crt  
lrwxrwxrwx 1 root root 77 Mar 2 13:07 c28a8a30.0 → …/…/…/usr/share/ca-certificates/mozilla/D-TRUST\_Root\_Class\_3\_CA\_2\_2009.crt  
lrwxrwxrwx 1 root root 79 Mar 2 13:07 c47d9980.0 → …/…/…/usr/share/ca-certificates/mozilla/Chambers\_of\_Commerce\_Root_-\_2008.crt  
lrwxrwxrwx 1 root root 57 Mar 2 13:07 c5d3212a.0 → …/…/…/usr/share/ca-certificates/mozilla/PSCProcert.crt  
lrwxrwxrwx 1 root root 74 Mar 2 13:07 c9f83a1c.0 → …/…/…/usr/share/ca-certificates/mozilla/Comodo\_Secure\_Services\_root.crt  
-rwxrwxrwx 1 root root 234846 Mar 15 17:12 ca-certificates.crt  
lrwxrwxrwx 1 root root 80 Mar 2 13:07 ca6e4ad9.0 → …/…/…/usr/share/ca-certificates/mozilla/ePKI\_Root\_Certification\_Authority.crt  
lrwxrwxrwx 1 root root 81 Mar 2 13:07 cb59f961.0 → …/…/…/usr/share/ca-certificates/mozilla/Camerfirma\_Global\_Chambersign\_Root.crt  
lrwxrwxrwx 1 root root 67 Mar 2 13:07 cbeee9e2.0 → …/…/…/usr/share/ca-certificates/mozilla/GeoTrust\_Global\_CA\_2.crt

Is there a better way to approach adding the crt file, or do I simply need to give my app permission to go to a new directory? Thanks!

---

<div class="post-metadata">

**Author:** ![jyijyi](https://sea2.discourse-cdn.com/flex016/user_avatar/mangoh.discourse.group/jyijyi/32/997_2.png) [@jyijyi](https://mangoh.discourse.group/u/jyijyi)\
**Post date:** [March 16, 2021, 1:35am UTC](https://mangoh.discourse.group/t/sandbox-prevent-file-read/6349/2 "2021-03-16T01:35:35Z")

</div>

does it work when unsandboxed?

You might see here on how to change the permission for accessing file outside sandbox:

> **[How to write data to a file outside sandbox](https://forum.legato.io/t/how-to-write-data-to-a-file-outside-sandbox/246/12)**
>
> Hi Alegato, Could you please elaborate your answer a bit more? I’ve tried to create file outside sandbox and give app access to it in adef file, but it still says that my file is read only

---

<div class="post-metadata">

**Author:** ![jameswollaeger](https://avatars.discourse-cdn.com/v4/letter/j/e495f1/32.png) [@jameswollaeger](https://mangoh.discourse.group/u/jameswollaeger)\
**Post date:** [March 17, 2021, 2:18pm UTC](https://mangoh.discourse.group/t/sandbox-prevent-file-read/6349/3 "2021-03-17T14:18:02Z")

</div>

It does work when unsandboxed.

Ideally, I want to revert all changes in the USER1 partition. Can I do this without a linux physical PC? I only have a VM running here with ubuntu on it.

I found this post: [Unable to erase USER1 partition - #6 by tanoue - Legato Application Framework - Legato Forum](https://forum.legato.io/t/unable-to-erase-user1-partition/4750/6)

method2: “fdt2.exe” with .spk file can be run on a windows PC, but i dont think that if i use the spk file downloaded from [source.sierrawireless.com](http://source.sierrawireless.com) that its actually erasing the user partition?

---

<div class="post-metadata">

**Author:** ![jyijyi](https://sea2.discourse-cdn.com/flex016/user_avatar/mangoh.discourse.group/jyijyi/32/997_2.png) [@jyijyi](https://mangoh.discourse.group/u/jyijyi)\
**Post date:** [March 17, 2021, 3:01pm UTC](https://mangoh.discourse.group/t/sandbox-prevent-file-read/6349/4 "2021-03-17T15:01:20Z")

</div>

You need to downgrade your wp76 to r12 and use swiflash to erase user partition
