Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(199)

Issue 1264463005: mandoline sandbox: prewarm libraries before we raise the sandbox. (Closed)

Created:
5 years, 4 months ago by Elliot Glaysher
Modified:
5 years, 4 months ago
CC:
chromium-reviews, qsr+mojo_chromium.org, viettrungluu+watch_chromium.org, penghuang+watch-mandoline_chromium.org, rickyz (no longer on Chrome), yzshen+watch_chromium.org, abarth-chromium, Aaron Boodman, darin (slow to review), ben+mojo_chromium.org
Base URL:
https://chromium.googlesource.com/chromium/src.git@master
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

mandoline sandbox: prewarm libraries before we raise the sandbox. That was quick. This moves back to a world where we don't perform dlopen() in the sandbox. As is, we actually load other shared objects from our build directories (html_viewer.mojo depends on libmedia_library.so, for example), and the useage of things like base::SysInfo is too pervasive throughout chrome to reasonably not so this. BUG=492524 Committed: https://crrev.com/25d8872d321ede78e50868d362eb2f278ebe0bf0 Cr-Commit-Position: refs/heads/master@{#340989}

Patch Set 1 #

Total comments: 1

Patch Set 2 : Fix gn check #

Patch Set 3 : Fix gn check part 2 #

Patch Set 4 : Move LinuxSandbox to mojo/runner/. #

Patch Set 5 : Move application loading to ChildProcessMain(). #

Patch Set 6 : Further cleanup to untouch these files. #

Patch Set 7 : And Android, too! #

Total comments: 4

Patch Set 8 : Add security checks to LinuxSandbox::Warmup() #

Unified diffs Side-by-side diffs Delta from patch set Stats (+113 lines, -276 lines) Patch
M mandoline/app/desktop/BUILD.gn View 1 2 3 4 1 chunk +0 lines, -9 lines 0 comments Download
M mandoline/app/desktop/linux_sandbox.h View 1 2 3 1 chunk +0 lines, -52 lines 0 comments Download
M mandoline/app/desktop/linux_sandbox.cc View 1 2 3 1 chunk +0 lines, -145 lines 0 comments Download
M mandoline/app/desktop/main.cc View 1 2 3 4 1 chunk +0 lines, -23 lines 0 comments Download
M mandoline/services/core_services/main.cc View 1 chunk +24 lines, -0 lines 0 comments Download
M mojo/runner/BUILD.gn View 1 2 3 4 1 chunk +9 lines, -1 line 0 comments Download
M mojo/runner/child_process.cc View 1 2 3 4 5 9 chunks +64 lines, -23 lines 0 comments Download
M mojo/runner/child_process.mojom View 1 chunk +2 lines, -4 lines 0 comments Download
M mojo/runner/child_process_host.cc View 2 chunks +4 lines, -1 line 0 comments Download
A + mojo/runner/linux_sandbox.h View 1 2 3 3 chunks +3 lines, -7 lines 0 comments Download
A + mojo/runner/linux_sandbox.cc View 1 2 3 4 5 6 7 3 chunks +7 lines, -11 lines 0 comments Download

Messages

Total messages: 10 (3 generated)
Elliot Glaysher
Things I found after landing the non-warming patch yesterday: - Our build system makes shared ...
5 years, 4 months ago (2015-07-29 17:36:38 UTC) #2
jam
lgtm
5 years, 4 months ago (2015-07-29 20:16:08 UTC) #3
jln (very slow on Chromium)
Quick lgtm, but some suggestion for refactor (but can happen in another CL). https://codereview.chromium.org/1264463005/diff/120001/mandoline/services/core_services/main.cc File ...
5 years, 4 months ago (2015-07-29 20:28:04 UTC) #4
Elliot Glaysher
https://codereview.chromium.org/1264463005/diff/120001/mandoline/services/core_services/main.cc File mandoline/services/core_services/main.cc (right): https://codereview.chromium.org/1264463005/diff/120001/mandoline/services/core_services/main.cc#newcode18 mandoline/services/core_services/main.cc:18: base::RandUint64(); On 2015/07/29 20:28:04, jln wrote: > Do we ...
5 years, 4 months ago (2015-07-29 21:08:32 UTC) #5
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/1264463005/140001 View timeline at https://chromium-cq-status.appspot.com/patch-timeline/1264463005/140001
5 years, 4 months ago (2015-07-29 21:08:56 UTC) #8
commit-bot: I haz the power
Committed patchset #8 (id:140001)
5 years, 4 months ago (2015-07-29 21:24:23 UTC) #9
commit-bot: I haz the power
5 years, 4 months ago (2015-07-29 21:25:07 UTC) #10
Message was sent while issue was closed.
Patchset 8 (id:??) landed as
https://crrev.com/25d8872d321ede78e50868d362eb2f278ebe0bf0
Cr-Commit-Position: refs/heads/master@{#340989}

Powered by Google App Engine
This is Rietveld 408576698