New issue
Advanced search Search tips

Issue 715550 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Apr 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 1
Type: Feature



Sign in to add a comment

Enable ambient capabilities on Chrome OS

Project Member Reported by jorgelo@chromium.org, Apr 26 2017

Issue description

Minijail functionality has landed in b/32066154. Uprev Minijail and use it in at least one daemon.
 
Project Member

Comment 1 by bugdroid1@chromium.org, Apr 27 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromiumos/overlays/chromiumos-overlay/+/2466b8cbc4e29de8a3ea06632969eb0f8b66b789

commit 2466b8cbc4e29de8a3ea06632969eb0f8b66b789
Author: Jorge Lucangeli Obes <jorgelo@chromium.org>
Date: Thu Apr 27 22:02:20 2017

minijail: Uprev for ambient capabilities functionality.

f6058c3 (HEAD, m/master, aosp/master) Fix prctl() call.
351d986 Enable minijail to be in the VNDK
a6eb21a Implement initial ambient capabilities support.
0b20877 Refactor Minijail in preparation for ambient capabilities work.
ddb7970 minijail: reduce build warnings/errors
6a600a4 Linux: Change the default for seccomp soft-fail.
64efa55 Build 'libminijail_test' as BUILD_NATIVE_TEST.
3b52601 Add test config to libminijail_test, libminijail_unittest_gtest...
bce4ccb (tag: linux-v1, tag: linux-r1) Implement @include functionality for seccomp policy files.
185d47e Ignore 'parse_seccomp_policy'.
45932a5 syscall_filter: Refactor 'compile_file' out of 'compile_filter'.

BUG= chromium:715550 
TEST=Build image, test ambient cap functionality.
TEST=security_Minijail0

Change-Id: I83e6c9c3c16a9def4b53e867c9ca35f169db9137
Reviewed-on: https://chromium-review.googlesource.com/488761
Commit-Ready: Jorge Lucangeli Obes <jorgelo@chromium.org>
Tested-by: Jorge Lucangeli Obes <jorgelo@chromium.org>
Reviewed-by: Mike Frysinger <vapier@chromium.org>

[rename] https://crrev.com/2466b8cbc4e29de8a3ea06632969eb0f8b66b789/chromeos-base/chromeos-minijail/chromeos-minijail-0.0.1-r1478.ebuild

Status: Fixed (was: Started)

Comment 3 by dchan@chromium.org, Aug 1 2017

Labels: VerifyIn-61

Comment 4 by dchan@chromium.org, Jan 22 2018

Status: Archived (was: Fixed)

Comment 5 by vapier@chromium.org, Jun 21 2018

Components: OS>Systems>Minijail
Status: Fixed (was: Archived)

Sign in to add a comment