New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 853873 link

Starred by 1 user

Issue metadata

Status: Started
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Fuchsia
Pri: 3
Type: Feature



Sign in to add a comment

Harmonize the sandbox memory limit across platforms

Project Member Reported by palmer@chromium.org, Jun 18 2018

Issue description

We limit RLIMIT_DATA on e.g. Linux. We should use the same limit on all platforms that support such a limit. (On Windows the working set size in the Job API is the closest equivalent.) Define this limit in a shared header.
 

Comment 1 by palmer@chromium.org, Jun 27 2018

Status: Started (was: Assigned)
Project Member

Comment 2 by bugdroid1@chromium.org, Jul 10

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/17b41949b785cb505750e0b65e9f441391283ef4

commit 17b41949b785cb505750e0b65e9f441391283ef4
Author: Chris Palmer <palmer@chromium.org>
Date: Tue Jul 10 00:38:48 2018

Harmonize the sandbox memory limit across platforms.

...to the extent possible. This involves lowering 64-bit Linux' limit from 8
GiB to 4, to match Windows.

Note that in the process of writing a previous version of this CL, we learned
that macOS apparently does not enforce RLIMIT_DATA, so we continue to not have a
limit on that platform. (The same goes for RLIMIT_AS, which we previously knew
about.)

Bug: 853873,459158
Change-Id: I5a2a76b4c98a0862c16ce121572c4b2b0f910b44
Reviewed-on: https://chromium-review.googlesource.com/1130235
Reviewed-by: Robert Sesek <rsesek@chromium.org>
Reviewed-by: Will Harris <wfh@chromium.org>
Commit-Queue: Will Harris <wfh@chromium.org>
Cr-Commit-Position: refs/heads/master@{#573557}
[modify] https://crrev.com/17b41949b785cb505750e0b65e9f441391283ef4/sandbox/BUILD.gn
[add] https://crrev.com/17b41949b785cb505750e0b65e9f441391283ef4/sandbox/constants.h
[modify] https://crrev.com/17b41949b785cb505750e0b65e9f441391283ef4/sandbox/win/BUILD.gn
[modify] https://crrev.com/17b41949b785cb505750e0b65e9f441391283ef4/services/service_manager/sandbox/BUILD.gn
[modify] https://crrev.com/17b41949b785cb505750e0b65e9f441391283ef4/services/service_manager/sandbox/DEPS
[modify] https://crrev.com/17b41949b785cb505750e0b65e9f441391283ef4/services/service_manager/sandbox/linux/sandbox_linux.cc
[modify] https://crrev.com/17b41949b785cb505750e0b65e9f441391283ef4/services/service_manager/sandbox/win/sandbox_win.cc

Labels: -OS-Mac
Looks like we can't do anything for macOS.

TODO: Figure out Fuchsia.

Sign in to add a comment