| Index: components/nacl/loader/sandbox_linux/nacl_sandbox_linux.h
|
| diff --git a/components/nacl/loader/sandbox_linux/nacl_sandbox_linux.h b/components/nacl/loader/sandbox_linux/nacl_sandbox_linux.h
|
| index ab6262563870f67eeddb81bd7892d331876e080c..333f8405c8636e5ce1092170c5ca07935d0518bf 100644
|
| --- a/components/nacl/loader/sandbox_linux/nacl_sandbox_linux.h
|
| +++ b/components/nacl/loader/sandbox_linux/nacl_sandbox_linux.h
|
| @@ -7,6 +7,11 @@
|
|
|
| #include "base/files/scoped_file.h"
|
| #include "base/macros.h"
|
| +#include "base/memory/scoped_ptr.h"
|
| +
|
| +namespace sandbox {
|
| +class SetuidSandboxClient;
|
| +}
|
|
|
| namespace nacl {
|
|
|
| @@ -61,6 +66,8 @@ class NaClSandbox {
|
| bool layer_two_enabled() { return layer_two_enabled_; }
|
|
|
| private:
|
| + void CheckForExpectedNumberOfOpenFds();
|
| +
|
| bool layer_one_enabled_;
|
| bool layer_one_sealed_;
|
| bool layer_two_enabled_;
|
| @@ -68,6 +75,7 @@ class NaClSandbox {
|
| // |proc_fd_| must be released before the layer-1 sandbox is considered
|
| // enforcing.
|
| base::ScopedFD proc_fd_;
|
| + scoped_ptr<sandbox::SetuidSandboxClient> setuid_sandbox_client_;
|
| DISALLOW_COPY_AND_ASSIGN(NaClSandbox);
|
| };
|
|
|
|
|