[PATCH v2] proc: allow restricting /proc/pid/mem writes

Kees Cook keescook at chromium.org
Tue Mar 5 18:33:45 UTC 2024


On Tue, Mar 05, 2024 at 12:03:21PM +0100, Christian Brauner wrote:
> What btw, is the Linux sandbox on Chromium doing? Did they finally move
> away from SECCOMP_RET_TRAP to SECCOMP_RET_USER_NOTIF? I see:
> 
> https://issues.chromium.org/issues/40145101
> 
> What ever became of this?

I'm not entirely sure. I don't think it's been a priority lately
(obviously).

-- 
Kees Cook



More information about the Linux-security-module-archive mailing list