Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(918)

Issue 304083002: Don't use no_new_privs mode when running NM process on Linux (Closed)

Created:
6 years, 6 months ago by Sergey Ulanov
Modified:
6 years, 6 months ago
CC:
chromium-reviews, chromium-apps-reviews_chromium.org, extensions-reviews_chromium.org
Visibility:
Public.

Description

Don't use no_new_privs mode when running NM process on Linux BUG=378012 Committed: https://src.chromium.org/viewvc/chrome?view=rev&revision=273785

Patch Set 1 #

Total comments: 5

Patch Set 2 : #

Total comments: 2

Patch Set 3 : #

Patch Set 4 : #

Unified diffs Side-by-side diffs Delta from patch set Stats (+7 lines, -0 lines) Patch
M chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc View 1 2 3 2 chunks +7 lines, -0 lines 0 comments Download

Messages

Total messages: 23 (0 generated)
Sergey Ulanov
6 years, 6 months ago (2014-05-29 01:43:44 UTC) #1
Lambros
lgtm https://codereview.chromium.org/304083002/diff/1/chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc File chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc (right): https://codereview.chromium.org/304083002/diff/1/chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc#newcode78 chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc:78: // Don't use no_new_privs mode, e.g. in case ...
6 years, 6 months ago (2014-05-29 01:52:27 UTC) #2
Sergey Ulanov
https://codereview.chromium.org/304083002/diff/1/chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc File chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc (right): https://codereview.chromium.org/304083002/diff/1/chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc#newcode78 chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc:78: // Don't use no_new_privs mode, e.g. in case the ...
6 years, 6 months ago (2014-05-29 01:57:59 UTC) #3
Sergey Ulanov
The CQ bit was checked by sergeyu@chromium.org
6 years, 6 months ago (2014-05-29 02:20:38 UTC) #4
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-status.appspot.com/cq/sergeyu@chromium.org/304083002/1
6 years, 6 months ago (2014-05-29 02:24:51 UTC) #5
Robert Sesek
The CQ bit was unchecked by rsesek@chromium.org
6 years, 6 months ago (2014-05-29 02:41:32 UTC) #6
Robert Sesek
On 2014/05/29 02:41:32, rsesek wrote: > The CQ bit was unchecked by mailto:rsesek@chromium.org Please wait ...
6 years, 6 months ago (2014-05-29 02:42:42 UTC) #7
Sergey Ulanov
+jschuh, jln Robert, Security team did sign off on the design and implementation of Native ...
6 years, 6 months ago (2014-05-29 03:06:46 UTC) #8
Robert Sesek
On 2014/05/29 03:06:46, Sergey Ulanov wrote: > +jschuh, jln > > Robert, > Security team ...
6 years, 6 months ago (2014-05-29 19:17:58 UTC) #9
jln (very slow on Chromium)
Please be careful in the future to not disable security features without talking with security@chromium.org ...
6 years, 6 months ago (2014-05-29 19:18:57 UTC) #10
Sergey Ulanov
On 2014/05/29 19:18:57, jln wrote: > Please be careful in the future to not disable ...
6 years, 6 months ago (2014-05-29 19:57:39 UTC) #11
Sergey Ulanov
https://codereview.chromium.org/304083002/diff/1/chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc File chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc (right): https://codereview.chromium.org/304083002/diff/1/chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc#newcode79 chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc:79: options.allow_new_privs = true; On 2014/05/29 19:57:39, Sergey Ulanov wrote: ...
6 years, 6 months ago (2014-05-29 19:59:37 UTC) #12
jln (very slow on Chromium)
lgtm https://codereview.chromium.org/304083002/diff/20001/chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc File chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc (right): https://codereview.chromium.org/304083002/diff/20001/chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc#newcode14 chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc:14: #include "chrome/common/chrome_paths.h" #include "build/build_config.h"
6 years, 6 months ago (2014-05-29 20:51:59 UTC) #13
Robert Sesek
LGTM, thanks
6 years, 6 months ago (2014-05-29 20:52:11 UTC) #14
Sergey Ulanov
https://codereview.chromium.org/304083002/diff/20001/chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc File chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc (right): https://codereview.chromium.org/304083002/diff/20001/chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc#newcode14 chrome/browser/extensions/api/messaging/native_process_launcher_posix.cc:14: #include "chrome/common/chrome_paths.h" On 2014/05/29 20:52:00, jln wrote: > #include ...
6 years, 6 months ago (2014-05-29 21:14:52 UTC) #15
Sergey Ulanov
The CQ bit was checked by sergeyu@chromium.org
6 years, 6 months ago (2014-05-29 21:15:21 UTC) #16
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-status.appspot.com/cq/sergeyu@chromium.org/304083002/30001
6 years, 6 months ago (2014-05-29 21:16:22 UTC) #17
commit-bot: I haz the power
FYI, CQ is re-trying this CL (attempt #1). The failing builders are: mac_chromium_compile_dbg on tryserver.chromium ...
6 years, 6 months ago (2014-05-30 01:09:56 UTC) #18
commit-bot: I haz the power
The CQ bit was unchecked by commit-bot@chromium.org
6 years, 6 months ago (2014-05-30 01:38:11 UTC) #19
commit-bot: I haz the power
Try jobs failed on following builders: mac_gpu on tryserver.chromium.gpu (http://build.chromium.org/p/tryserver.chromium.gpu/builders/mac_gpu/builds/10791)
6 years, 6 months ago (2014-05-30 01:38:11 UTC) #20
Sergey Ulanov
The CQ bit was checked by sergeyu@chromium.org
6 years, 6 months ago (2014-05-30 05:09:22 UTC) #21
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-status.appspot.com/cq/sergeyu@chromium.org/304083002/50001
6 years, 6 months ago (2014-05-30 05:12:02 UTC) #22
commit-bot: I haz the power
6 years, 6 months ago (2014-05-30 10:24:33 UTC) #23
Message was sent while issue was closed.
Change committed as 273785

Powered by Google App Engine
This is Rietveld 408576698