Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(258)

Side by Side Diff: content/common/sandbox_linux/bpf_gpu_policy_linux.cc

Issue 163433011: Clarify the process title of GPU broker process. (Closed) Base URL: https://git.chromium.org/chromium/src.git@master
Patch Set: Created 6 years, 10 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
« no previous file with comments | « no previous file | no next file » | no next file with comments »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
OLDNEW
1 // Copyright (c) 2013 The Chromium Authors. All rights reserved. 1 // Copyright (c) 2013 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 #include "content/common/sandbox_linux/bpf_gpu_policy_linux.h" 5 #include "content/common/sandbox_linux/bpf_gpu_policy_linux.h"
6 6
7 #include <dlfcn.h> 7 #include <dlfcn.h>
8 #include <errno.h> 8 #include <errno.h>
9 #include <fcntl.h> 9 #include <fcntl.h>
10 #include <sys/socket.h> 10 #include <sys/socket.h>
11 #include <sys/stat.h> 11 #include <sys/stat.h>
12 #include <sys/types.h> 12 #include <sys/types.h>
13 #include <unistd.h> 13 #include <unistd.h>
14 14
15 #include <string> 15 #include <string>
16 #include <vector> 16 #include <vector>
17 17
18 #include "base/command_line.h" 18 #include "base/command_line.h"
19 #include "base/compiler_specific.h" 19 #include "base/compiler_specific.h"
20 #include "base/logging.h" 20 #include "base/logging.h"
21 #include "base/memory/scoped_ptr.h" 21 #include "base/memory/scoped_ptr.h"
22 #include "build/build_config.h" 22 #include "build/build_config.h"
23 #include "content/common/sandbox_linux/sandbox_bpf_base_policy_linux.h" 23 #include "content/common/sandbox_linux/sandbox_bpf_base_policy_linux.h"
24 #include "content/common/sandbox_linux/sandbox_seccomp_bpf_linux.h" 24 #include "content/common/sandbox_linux/sandbox_seccomp_bpf_linux.h"
25 #include "content/common/set_process_title.h"
25 #include "content/public/common/content_switches.h" 26 #include "content/public/common/content_switches.h"
26 #include "sandbox/linux/seccomp-bpf-helpers/syscall_sets.h" 27 #include "sandbox/linux/seccomp-bpf-helpers/syscall_sets.h"
27 #include "sandbox/linux/seccomp-bpf/sandbox_bpf.h" 28 #include "sandbox/linux/seccomp-bpf/sandbox_bpf.h"
28 #include "sandbox/linux/services/broker_process.h" 29 #include "sandbox/linux/services/broker_process.h"
29 #include "sandbox/linux/services/linux_syscalls.h" 30 #include "sandbox/linux/services/linux_syscalls.h"
30 31
31 using sandbox::BrokerProcess; 32 using sandbox::BrokerProcess;
32 using sandbox::ErrorCode; 33 using sandbox::ErrorCode;
33 using sandbox::SandboxBPF; 34 using sandbox::SandboxBPF;
34 using sandbox::SyscallSets; 35 using sandbox::SyscallSets;
(...skipping 94 matching lines...) Expand 10 before | Expand all | Expand 10 after
129 switch (sysno) { 130 switch (sysno) {
130 case __NR_access: 131 case __NR_access:
131 case __NR_open: 132 case __NR_open:
132 case __NR_openat: 133 case __NR_openat:
133 return ErrorCode(ErrorCode::ERR_ALLOWED); 134 return ErrorCode(ErrorCode::ERR_ALLOWED);
134 default: 135 default:
135 return GpuProcessPolicy::EvaluateSyscall(sandbox, sysno); 136 return GpuProcessPolicy::EvaluateSyscall(sandbox, sysno);
136 } 137 }
137 } 138 }
138 139
140 static void UpdateProcessTitle() {
jln (very slow on Chromium) 2014/02/20 00:29:57 UpdateProcessTypeToGpuBroker() instead?
dshwang 2014/02/20 20:36:31 Done
141 CommandLine::StringVector exec = CommandLine::ForCurrentProcess()->GetArgs();
142 CommandLine::Reset();
143 CommandLine::Init(0, NULL);
144 CommandLine::ForCurrentProcess()->InitFromArgv(exec);
145 CommandLine::ForCurrentProcess()->AppendSwitchASCII(switches::kProcessType,
146 "gpu-broker");
147
148 // Update the process title. The argv was already cached by the call to
149 // SetProcessTitleFromCommandLine in content_main_runner.cc, so we can pass
Jorge Lucangeli Obes 2014/02/20 00:33:05 Is this comment still accurate?
dshwang 2014/02/20 20:36:31 Yes. but there is some logic jump. Browser process
150 // NULL here (we don't have the original argv at this point).
151 SetProcessTitleFromCommandLine(NULL);
152 }
153
139 bool EnableGpuBrokerPolicyCallback() { 154 bool EnableGpuBrokerPolicyCallback() {
jln (very slow on Chromium) 2014/02/20 00:29:57 Let's rename to GpuBrokerChildInitCallback or some
dshwang 2014/02/20 20:36:31 Done
155 UpdateProcessTitle();
140 return SandboxSeccompBPF::StartSandboxWithExternalPolicy( 156 return SandboxSeccompBPF::StartSandboxWithExternalPolicy(
141 scoped_ptr<sandbox::SandboxBPFPolicy>(new GpuBrokerProcessPolicy)); 157 scoped_ptr<sandbox::SandboxBPFPolicy>(new GpuBrokerProcessPolicy));
142 } 158 }
143 159
144 } // namespace 160 } // namespace
145 161
146 GpuProcessPolicy::GpuProcessPolicy() : broker_process_(NULL) {} 162 GpuProcessPolicy::GpuProcessPolicy() : broker_process_(NULL) {}
147 163
148 GpuProcessPolicy::~GpuProcessPolicy() {} 164 GpuProcessPolicy::~GpuProcessPolicy() {}
149 165
(...skipping 89 matching lines...) Expand 10 before | Expand all | Expand 10 after
239 write_whitelist_extra.end()); 255 write_whitelist_extra.end());
240 256
241 broker_process_ = new BrokerProcess(GetFSDeniedErrno(), 257 broker_process_ = new BrokerProcess(GetFSDeniedErrno(),
242 read_whitelist, 258 read_whitelist,
243 write_whitelist); 259 write_whitelist);
244 // Initialize the broker process and give it a sandbox callback. 260 // Initialize the broker process and give it a sandbox callback.
245 CHECK(broker_process_->Init(broker_sandboxer_callback)); 261 CHECK(broker_process_->Init(broker_sandboxer_callback));
246 } 262 }
247 263
248 } // namespace content 264 } // namespace content
OLDNEW
« no previous file with comments | « no previous file | no next file » | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698