Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(1131)

Unified Diff: mandoline/app/desktop/main.cc

Issue 1264463005: mandoline sandbox: prewarm libraries before we raise the sandbox. (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: And Android, too! Created 5 years, 5 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: mandoline/app/desktop/main.cc
diff --git a/mandoline/app/desktop/main.cc b/mandoline/app/desktop/main.cc
index c01b36bed1b06b9c437ba00fc3a7827f78eb3656..59a5d907201855338e06a7c1561716cd10fb780a 100644
--- a/mandoline/app/desktop/main.cc
+++ b/mandoline/app/desktop/main.cc
@@ -9,37 +9,14 @@
#include "mandoline/app/desktop/launcher_process.h"
#include "mojo/runner/child_process.h"
#include "mojo/runner/init.h"
-#include "mojo/runner/native_application_support.h"
#include "mojo/runner/switches.h"
#include "mojo/shell/native_runner.h"
-#if defined(OS_LINUX) && !defined(OS_ANDROID)
-#include "mandoline/app/desktop/linux_sandbox.h"
-#endif
-
int main(int argc, char** argv) {
base::CommandLine::Init(argc, argv);
const base::CommandLine& command_line =
*base::CommandLine::ForCurrentProcess();
-#if defined(OS_LINUX) && !defined(OS_ANDROID)
- using sandbox::syscall_broker::BrokerFilePermission;
- scoped_ptr<mandoline::LinuxSandbox> sandbox;
- if (command_line.HasSwitch(switches::kChildProcess) &&
- command_line.HasSwitch(switches::kEnableSandbox)) {
- std::vector<BrokerFilePermission> permissions =
- mandoline::LinuxSandbox::GetPermissions();
- permissions.push_back(BrokerFilePermission::ReadOnly(
- command_line.GetSwitchValueNative(switches::kChildProcess)));
-
- sandbox.reset(new mandoline::LinuxSandbox(permissions));
- sandbox->Warmup();
- sandbox->EngageNamespaceSandbox();
- sandbox->EngageSeccompSandbox();
- sandbox->Seal();
- }
-#endif
-
base::AtExitManager at_exit;
mojo::runner::InitializeLogging();
mojo::runner::WaitForDebuggerIfNecessary();

Powered by Google App Engine
This is Rietveld 408576698