Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(1064)

Issue 775943004: [Android] Get renderers working again under seccomp-bpf. (Closed)

Created:
6 years ago by Robert Sesek
Modified:
6 years ago
CC:
chromium-reviews, mkwst+moarreviews-renderer_chromium.org, darin-cc_chromium.org, jam, jln+watch_chromium.org, mlamouri+watch-content_chromium.org
Base URL:
https://chromium.googlesource.com/chromium/src.git@master
Project:
chromium
Visibility:
Public.

Description

[Android] Get renderers working again under seccomp-bpf. Android 5.0 added some additional prctl()s that are used by the framework. This also permits __NR_set_tid_address and fstat(). BUG=437067, 166704 R=jln@chromium.org Committed: https://crrev.com/0d1b63a26471e4c3ac8acd12276010b79affc26a Cr-Commit-Position: refs/heads/master@{#306895}

Patch Set 1 #

Patch Set 2 : Alternate approach #

Total comments: 4

Patch Set 3 : Address comments #

Unified diffs Side-by-side diffs Delta from patch set Stats (+20 lines, -1 line) Patch
M content/common/sandbox_linux/android/sandbox_bpf_base_policy_android.cc View 1 2 2 chunks +7 lines, -1 line 0 comments Download
M sandbox/linux/seccomp-bpf-helpers/syscall_parameters_restrictions.cc View 2 chunks +13 lines, -0 lines 0 comments Download

Messages

Total messages: 7 (1 generated)
Robert Sesek
There are two patch sets here, let me know which approach you prefer. I think ...
6 years ago (2014-12-03 21:13:57 UTC) #1
jln (very slow on Chromium)
lgtm * Yeah, it seems ok to allow fstatat given the current model. The drawback ...
6 years ago (2014-12-04 01:35:38 UTC) #2
Robert Sesek
https://codereview.chromium.org/775943004/diff/20001/content/common/sandbox_linux/android/sandbox_bpf_base_policy_android.cc File content/common/sandbox_linux/android/sandbox_bpf_base_policy_android.cc (right): https://codereview.chromium.org/775943004/diff/20001/content/common/sandbox_linux/android/sandbox_bpf_base_policy_android.cc#newcode43 content/common/sandbox_linux/android/sandbox_bpf_base_policy_android.cc:43: #if !ARCH_CPU_ARM64 On 2014/12/04 01:35:38, jln wrote: > Do ...
6 years ago (2014-12-04 17:56:59 UTC) #3
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/775943004/40001
6 years ago (2014-12-04 20:33:51 UTC) #5
commit-bot: I haz the power
Committed patchset #3 (id:40001)
6 years ago (2014-12-04 21:29:09 UTC) #6
commit-bot: I haz the power
6 years ago (2014-12-04 21:30:03 UTC) #7
Message was sent while issue was closed.
Patchset 3 (id:??) landed as
https://crrev.com/0d1b63a26471e4c3ac8acd12276010b79affc26a
Cr-Commit-Position: refs/heads/master@{#306895}

Powered by Google App Engine
This is Rietveld 408576698