Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(675)

Issue 2920353002: Add the V2 sandbox rules for renderer processes. (Closed)

Created:
3 years, 6 months ago by Greg K
Modified:
3 years, 6 months ago
CC:
chromium-reviews, jam, darin-cc_chromium.org
Target Ref:
refs/heads/master
Project:
chromium
Visibility:
Public.

Description

Add the V2 sandbox rules for renderer processes. Add the V2 sandbox rules, which eliminate the unsandboxed warmup phase in favor of explicitly enumerating resource access, to the tree. BUG=689306 Review-Url: https://codereview.chromium.org/2920353002 Cr-Commit-Position: refs/heads/master@{#478443} Committed: https://chromium.googlesource.com/chromium/src/+/147d8ebbba78a52af03a6ab1570af96536b4e1fa

Patch Set 1 #

Patch Set 2 : Add the rules file #

Total comments: 11

Patch Set 3 : Cleanup indentation and comments #

Patch Set 4 : Remove unused mach services #

Total comments: 2

Patch Set 5 : Fix last nit #

Unified diffs Side-by-side diffs Delta from patch set Stats (+145 lines, -0 lines) Patch
M content/content_resources.grd View 1 chunk +1 line, -0 lines 0 comments Download
A content/renderer/renderer_v2.sb View 1 2 3 4 1 chunk +144 lines, -0 lines 0 comments Download

Messages

Total messages: 20 (10 generated)
Greg K
rsesek@, PTAL. Are you OK with landing the V2 sandbox rules before they can actually ...
3 years, 6 months ago (2017-06-05 18:46:54 UTC) #2
Robert Sesek
I'm okay with landing the v2 rules now, but I think I'd like the TODOs ...
3 years, 6 months ago (2017-06-06 14:56:01 UTC) #7
Greg K
On 2017/06/06 14:56:01, Robert Sesek wrote: > I'm okay with landing the v2 rules now, ...
3 years, 6 months ago (2017-06-06 17:10:56 UTC) #8
Robert Sesek
On 2017/06/06 17:10:56, Greg K wrote: > I can't resolve the questions about mach-services until ...
3 years, 6 months ago (2017-06-06 17:20:49 UTC) #9
Greg K
https://codereview.chromium.org/2920353002/diff/20001/content/renderer/renderer_v2.sb File content/renderer/renderer_v2.sb (right): https://codereview.chromium.org/2920353002/diff/20001/content/renderer/renderer_v2.sb#newcode6 content/renderer/renderer_v2.sb:6: ; The top of this will be the V2 ...
3 years, 6 months ago (2017-06-09 20:51:20 UTC) #10
Avi (use Gerrit)
FYI drive-by content lgtm cool stuff!
3 years, 6 months ago (2017-06-09 20:58:17 UTC) #12
Robert Sesek
LGTM w/ a nit https://codereview.chromium.org/2920353002/diff/60001/content/renderer/renderer_v2.sb File content/renderer/renderer_v2.sb (right): https://codereview.chromium.org/2920353002/diff/60001/content/renderer/renderer_v2.sb#newcode106 content/renderer/renderer_v2.sb:106: (allow iokit-open (iokit-registry-entry-class "RootDomainUserClient")) Structure ...
3 years, 6 months ago (2017-06-09 21:44:49 UTC) #13
commit-bot: I haz the power
CQ is trying da patch. Follow status at: https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2920353002/80001
3 years, 6 months ago (2017-06-09 21:57:20 UTC) #16
Greg K
https://codereview.chromium.org/2920353002/diff/60001/content/renderer/renderer_v2.sb File content/renderer/renderer_v2.sb (right): https://codereview.chromium.org/2920353002/diff/60001/content/renderer/renderer_v2.sb#newcode106 content/renderer/renderer_v2.sb:106: (allow iokit-open (iokit-registry-entry-class "RootDomainUserClient")) On 2017/06/09 21:44:48, Robert Sesek ...
3 years, 6 months ago (2017-06-09 21:57:53 UTC) #17
commit-bot: I haz the power
3 years, 6 months ago (2017-06-09 23:09:22 UTC) #20
Message was sent while issue was closed.
Committed patchset #5 (id:80001) as
https://chromium.googlesource.com/chromium/src/+/147d8ebbba78a52af03a6ab1570a...

Powered by Google App Engine
This is Rietveld 408576698