Chromium Code Reviews
Descriptionmandoline: lock down the linux sandbox more.
Previously, the mandoline sandbox allowed all system calls except for
access()/open()/faccessat()/openat(). This patch now uses the baseline
sandboxing policy (which will error on many common syscalls and will
crash on unwhitelisted calls). Added a few syscalls that we need for the
compositor to the explicit allow list.
BUG=492524
Committed: https://crrev.com/6b21046b63481355378258b8a37d029a6a742ca1
Cr-Commit-Position: refs/heads/master@{#346469}
Patch Set 1 #
Total comments: 1
Patch Set 2 : Restrict getaffinity. #Messages
Total messages: 11 (4 generated)
|