Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(29)

Side by Side Diff: services/service_manager/public/cpp/standalone_service/linux_sandbox.h

Issue 2557213002: Build services as standalone executables (Closed)
Patch Set: remove DCHECKs with side effects -_- Created 4 years ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 // Copyright 2015 The Chromium Authors. All rights reserved. 1 // Copyright 2015 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 #ifndef SERVICES_SERVICE_MANAGER_RUNNER_HOST_LINUX_SANDBOX_H_ 5 #ifndef SERVICES_SERVICE_MANAGER_PUBLIC_CPP_STANDALONE_SERVICE_LINUX_SANDBOX_H_
6 #define SERVICES_SERVICE_MANAGER_RUNNER_HOST_LINUX_SANDBOX_H_ 6 #define SERVICES_SERVICE_MANAGER_PUBLIC_CPP_STANDALONE_SERVICE_LINUX_SANDBOX_H_
7 7
8 #include <memory> 8 #include <memory>
9 9
10 #include "base/files/scoped_file.h" 10 #include "base/files/scoped_file.h"
11 #include "base/macros.h" 11 #include "base/macros.h"
12 #include "sandbox/linux/bpf_dsl/bpf_dsl.h" 12 #include "sandbox/linux/bpf_dsl/bpf_dsl.h"
13 #include "sandbox/linux/bpf_dsl/policy.h" 13 #include "sandbox/linux/bpf_dsl/policy.h"
14 #include "sandbox/linux/syscall_broker/broker_process.h" 14 #include "sandbox/linux/syscall_broker/broker_process.h"
15 15
16 namespace service_manager { 16 namespace service_manager {
17 17
18 // Encapsulates all tasks related to raising the sandbox for mojo runner. 18 // Encapsulates all tasks related to raising the sandbox for a standalone
19 // service.
19 class LinuxSandbox { 20 class LinuxSandbox {
20 public: 21 public:
21 explicit LinuxSandbox( 22 explicit LinuxSandbox(
22 const std::vector<sandbox::syscall_broker::BrokerFilePermission>& 23 const std::vector<sandbox::syscall_broker::BrokerFilePermission>&
23 permissions); 24 permissions);
24 ~LinuxSandbox(); 25 ~LinuxSandbox();
25 26
26 // Grabs a file descriptor to /proc. 27 // Grabs a file descriptor to /proc.
27 void Warmup(); 28 void Warmup();
28 29
(...skipping 12 matching lines...) Expand all
41 bool warmed_up_; 42 bool warmed_up_;
42 base::ScopedFD proc_fd_; 43 base::ScopedFD proc_fd_;
43 std::unique_ptr<sandbox::syscall_broker::BrokerProcess> broker_; 44 std::unique_ptr<sandbox::syscall_broker::BrokerProcess> broker_;
44 std::unique_ptr<sandbox::bpf_dsl::Policy> policy_; 45 std::unique_ptr<sandbox::bpf_dsl::Policy> policy_;
45 46
46 DISALLOW_COPY_AND_ASSIGN(LinuxSandbox); 47 DISALLOW_COPY_AND_ASSIGN(LinuxSandbox);
47 }; 48 };
48 49
49 } // namespace service_manager 50 } // namespace service_manager
50 51
51 #endif // SERVICES_SERVICE_MANAGER_RUNNER_HOST_LINUX_SANDBOX_H_ 52 #endif // SERVICES_SERVICE_MANAGER_PUBLIC_CPP_STANDALONE_SERVICE_LINUX_SANDBOX_ H_
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698