Issue metadata
Sign in to add a comment
|
Use no-new-privs everywhere |
||||||||||||||||||||||
Issue descriptionno-new-privs is a good way to enforce process trees cannot elevate privilege. We have a way of verifying this in /proc/<pid>/status, so start using it more.
,
Jun 8 2017
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by bugdroid1@chromium.org
, Jun 8 2017