jabra-vold should use linux namespaces to isolate itself |
|||
Issue descriptioncan we run the daemon under linux namespaces to further isolate itself ? -e disables network access (i don't think jabra needs the network) -l enter a new IPC namespace (i don't think jabra needs shared memory) -v enter a new mount namespace (since jabra doesn't care about mounts) i don't think -p (pid) would work since jabra manages its own pid to start/stop itself
,
Mar 7 2017
,
Aug 1
|
|||
►
Sign in to add a comment |
|||
Comment 1 by h...@chromium.org
, Mar 7 2017Owner: ----