mirror of
https://github.com/google/sandboxed-api.git
synced 2024-03-22 13:11:30 +08:00
Adjust sandboxed_api default policy
PiperOrigin-RevId: 557762512 Change-Id: I600c8126ee09b8bab927013de25fcb836c78ac9a
This commit is contained in:
parent
f378d22405
commit
18c64ae10f
|
@ -70,21 +70,20 @@ void InitDefaultPolicyBuilder(sandbox2::PolicyBuilder* builder) {
|
||||||
.AllowHandleSignals()
|
.AllowHandleSignals()
|
||||||
.AllowSystemMalloc()
|
.AllowSystemMalloc()
|
||||||
.AllowSafeFcntl()
|
.AllowSafeFcntl()
|
||||||
.AllowSyscall(__NR_recvmsg)
|
.AllowGetPIDs()
|
||||||
.AllowSyscall(__NR_sendmsg)
|
|
||||||
.AllowSyscall(__NR_futex)
|
|
||||||
.AllowSyscall(__NR_close)
|
|
||||||
.AllowSyscall(__NR_lseek)
|
|
||||||
.AllowSyscall(__NR_getpid)
|
|
||||||
.AllowSyscall(__NR_getppid)
|
|
||||||
.AllowSyscall(__NR_gettid)
|
|
||||||
.AllowSleep()
|
.AllowSleep()
|
||||||
.AllowSyscall(__NR_uname)
|
.AllowReadlink()
|
||||||
.AllowSyscall(__NR_getrandom)
|
.AllowSyscalls({
|
||||||
.AllowSyscall(__NR_kill)
|
__NR_recvmsg,
|
||||||
.AllowSyscall(__NR_tgkill)
|
__NR_sendmsg,
|
||||||
.AllowSyscall(__NR_tkill)
|
__NR_futex,
|
||||||
.AllowReadlink();
|
__NR_close,
|
||||||
|
__NR_lseek,
|
||||||
|
__NR_uname,
|
||||||
|
__NR_kill,
|
||||||
|
__NR_tgkill,
|
||||||
|
__NR_tkill,
|
||||||
|
});
|
||||||
|
|
||||||
#ifdef __NR_arch_prctl // x86-64 only
|
#ifdef __NR_arch_prctl // x86-64 only
|
||||||
builder->AllowSyscall(__NR_arch_prctl);
|
builder->AllowSyscall(__NR_arch_prctl);
|
||||||
|
|
Loading…
Reference in New Issue
Block a user