fix(mcp): disable the chromium sandbox for the bundled browser on linux - #42490
Conversation
An explicit browserName 'chromium' without a channel launches the same downloaded build as the 'chromium' and 'chrome-for-testing' channels, which has no setuid sandbox helper on linux. Fixes: microsoft#42452
| if (process.platform === 'linux') { | ||
| // Downloaded chromium builds (undefined channel, 'chromium', 'chrome-for-testing') lack the setuid sandbox helper on linux. | ||
| const { channel } = browser.launchOptions; | ||
| browser.launchOptions.chromiumSandbox = channel !== undefined && channel !== 'chromium' && channel !== 'chrome-for-testing'; |
There was a problem hiding this comment.
channel !== 'chrome-for-testing' <-- I would kick this out.
There was a problem hiding this comment.
It's in the same category. The downloaded builds ship chrome_sandbox, but it's extracted from a zip as -rwxr-xr-x user user and archives can't carry setuid root.
03a69df
into
microsoft:main
Test results for "MCP"1 failed 8307 passed, 1377 skipped Merge workflow run. |
|
Hi, I'm the Playwright bot and I took a first look at the CI failure here. 🟢 The one failure is a pre-existing flake — this PR is clearThe single red is DetailsPre-existing flake / infra
Triaged by the Playwright bot - agent run |
## What's New ### 🎉 New Tools - **`browser_webmcp_list` / `browser_webmcp_call`** — List and call the tools a page registers through the [WebMCP](https://webmachinelearning.github.io/webmcp/) API, letting the page do the work instead of driving its UI. When a page has WebMCP tools, the page status reports how many are available ([#42613](microsoft/playwright#42613)). WebMCP is experimental, see [WebMCP in Chrome](https://developer.chrome.com/docs/ai/webmcp) for how to enable it. ### Other Changes - New `--profile-dir-name <name>` option (env `PLAYWRIGHT_MCP_PROFILE_DIR_NAME`) selects the Chrome profile to connect to in extension mode when the extension is installed in several profiles, for example `"Profile 1"` ([#42527](microsoft/playwright#42527)) - Headless browsers launched by the server are now closed after one hour without tool calls; the next tool call launches a new one. Use `--idle-timeout <ms>` (config `timeouts.idle`, env `PLAYWRIGHT_MCP_IDLE_TIMEOUT`) to change the timeout, `0` disables it. Headed and attached browsers are not closed unless a timeout is set explicitly ([#42663](microsoft/playwright#42663), [#42676](microsoft/playwright#42676)) - `--image-responses` accepts `only`: a response that carries an image consists of the image parts alone, without the text part ([#42672](microsoft/playwright#42672)) ## Bug Fixes - `browser_close` returns an error when the browser context is shared (`--shared-browser-context`) instead of breaking the calling client's session. This supersedes the v0.0.80 change that dropped the backend after `browser_close` ([#42495](microsoft/playwright#42495)) - With `--shared-browser-context`, `browser_start_recording` / `browser_stop_recording` (opt-in via `--caps=devtools`) keep each client's recording separate instead of delivering one client's recorded actions to another ([#42622](microsoft/playwright#42622), [#42627](microsoft/playwright#42627)) - The file access check follows symlinks, so a symlink inside the workspace can no longer be used to read or write files outside the allowed roots ([#42628](microsoft/playwright#42628)) - Explicitly named output files in a nested directory (e.g. `sub/shot.png`) no longer fail with `ENOENT`; `browser_file_upload` and `browser_drop` resolve relative paths against the workspace root ([#42540](microsoft/playwright#42540)) - In extension mode with `PLAYWRIGHT_MCP_EXTENSION_TOKEN` set, a connection that never completes (e.g. the token belongs to another Chrome profile) now fails after 30 seconds with a hint instead of hanging the tool call forever ([#42525](microsoft/playwright#42525)) - Disable the Chromium sandbox by default on Linux for the bundled Chromium build, which lacks the setuid sandbox helper ([#42490](microsoft/playwright#42490))
## What's New ### 🎉 New Commands - **`webmcp-list` / `webmcp-call`** — List and call the tools a page registers through the [WebMCP](https://webmachinelearning.github.io/webmcp/) API, letting the page do the work instead of driving its UI. When a page has WebMCP tools, the page status reports how many are available ([#42613](microsoft/playwright#42613)). WebMCP is experimental, see [WebMCP in Chrome](https://developer.chrome.com/docs/ai/webmcp) for how to enable it. ### Other Changes - Headless sessions now shut down after one hour without commands, so a session an agent never closed no longer holds a browser; run `open` again to start a new one. Use `open --idle-timeout <ms>` (config `timeouts.idle`, env `PLAYWRIGHT_MCP_IDLE_TIMEOUT`) to change the timeout, `0` disables it. Headed browsers stay open, and attached browsers are only detached when `attach --idle-timeout <ms>` is set ([#42676](microsoft/playwright#42676)) - The skill includes a guide for attaching screenshots and videos to pull requests with `gh --attach` ([#42645](microsoft/playwright#42645)) ## Bug Fixes - Session daemons exit when their control socket is deleted or replaced, instead of staying alive with the browser ([#42454](microsoft/playwright#42454)) - Explicitly named output files in a nested directory (e.g. `screenshot --filename=sub/shot.png`) no longer fail with `ENOENT` ([#42540](microsoft/playwright#42540)) - Video chapters and screencast overlays are no longer hidden behind open dialogs and popovers ([#42642](microsoft/playwright#42642)) - `npx playwright test --debug=cli` works for tests that create more than one browser context and for every test in a worker, not just the first ([#42503](microsoft/playwright#42503)) - With `PLAYWRIGHT_MCP_EXTENSION_TOKEN` set, `attach --extension` fails after 30 seconds with a hint when the extension never connects (e.g. the token belongs to another Chrome profile) instead of hanging forever ([#42525](microsoft/playwright#42525)) - Disable the Chromium sandbox by default on Linux for the bundled Chromium build, which lacks the setuid sandbox helper ([#42490](microsoft/playwright#42490)) ## Upgrading ```bash npm install -g @playwright/cli@0.1.20 ```
Summary
browserName: 'chromium'resolves to the same downloaded build as thechromiumandchrome-for-testingchannels, so treat it the same when defaultingchromiumSandboxon linux.Fixes #42452