Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(503)

Side by Side Diff: content/public/common/sandbox_linux.h

Issue 758063005: Linux sandbox: report TSYNC status in chrome://sandbox (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: Created 6 years ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
« no previous file with comments | « content/common/sandbox_linux/sandbox_seccomp_bpf_linux.cc ('k') | no next file » | no next file with comments »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
OLDNEW
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 #ifndef CONTENT_PUBLIC_COMMON_SANDBOX_LINUX_H_ 5 #ifndef CONTENT_PUBLIC_COMMON_SANDBOX_LINUX_H_
6 #define CONTENT_PUBLIC_COMMON_SANDBOX_LINUX_H_ 6 #define CONTENT_PUBLIC_COMMON_SANDBOX_LINUX_H_
7 7
8 namespace content { 8 namespace content {
9 9
10 // These form a bitmask which describes the conditions of the Linux sandbox. 10 // These form a bitmask which describes the conditions of the Linux sandbox.
11 // Note: this doesn't strictly give you the current status, it states 11 // Note: this doesn't strictly give you the current status, it states
12 // what will be enabled when the relevant processes are initialized. 12 // what will be enabled when the relevant processes are initialized.
13 enum LinuxSandboxStatus { 13 enum LinuxSandboxStatus {
14 // SUID sandbox active. 14 // SUID sandbox active.
15 kSandboxLinuxSUID = 1 << 0, 15 kSandboxLinuxSUID = 1 << 0,
16 16
17 // SUID sandbox is using the PID namespace. 17 // SUID sandbox is using the PID namespace.
18 kSandboxLinuxPIDNS = 1 << 1, 18 kSandboxLinuxPIDNS = 1 << 1,
19 19
20 // SUID sandbox is using the network namespace. 20 // SUID sandbox is using the network namespace.
21 kSandboxLinuxNetNS = 1 << 2, 21 kSandboxLinuxNetNS = 1 << 2,
22 22
23 // seccomp-bpf sandbox active. 23 // seccomp-bpf sandbox active.
24 kSandboxLinuxSeccompBPF = 1 << 3, 24 kSandboxLinuxSeccompBPF = 1 << 3,
25 25
26 // The Yama LSM module is present and enforcing. 26 // The Yama LSM module is present and enforcing.
27 kSandboxLinuxYama = 1 << 4, 27 kSandboxLinuxYama = 1 << 4,
28 28
29 // seccomp-bpf sandbox is active and the kernel supports TSYNC.
30 kSandboxLinuxSeccompTSYNC = 1 << 5,
31
29 // A flag that denotes an invalid sandbox status. 32 // A flag that denotes an invalid sandbox status.
30 kSandboxLinuxInvalid = 1 << 31, 33 kSandboxLinuxInvalid = 1 << 31,
31 }; 34 };
32 35
33 } // namespace content 36 } // namespace content
34 37
35 #endif // CONTENT_PUBLIC_COMMON_SANDBOX_LINUX_H_ 38 #endif // CONTENT_PUBLIC_COMMON_SANDBOX_LINUX_H_
OLDNEW
« no previous file with comments | « content/common/sandbox_linux/sandbox_seccomp_bpf_linux.cc ('k') | no next file » | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698