Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(259)

Unified Diff: content/common/sandbox_init_linux.cc

Issue 10534049: Disable the seccomp filter GPU process sandbox by default on Chrome OS. (Closed) Base URL: http://git.chromium.org/chromium/src.git@master
Patch Set: Change flag name, move GPU info check to gpu_main.cc Created 8 years, 6 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « no previous file | content/gpu/gpu_main.cc » ('j') | content/gpu/gpu_main.cc » ('J')
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: content/common/sandbox_init_linux.cc
diff --git a/content/common/sandbox_init_linux.cc b/content/common/sandbox_init_linux.cc
index 1dd1554ff064ceaba55fdb10b49f07530b82a0e1..336c1736842485d0b3dc7df9f5f81601458fd44f 100644
--- a/content/common/sandbox_init_linux.cc
+++ b/content/common/sandbox_init_linux.cc
@@ -388,6 +388,15 @@ static void InstallFilter(const std::vector<struct sock_filter>& program) {
PLOG_IF(FATAL, ret != 0) << "Failed to install filter.";
}
+static bool ShouldEnableGPUSandbox() {
+#if defined(OS_CHROMEOS)
+ const CommandLine& command_line = *CommandLine::ForCurrentProcess();
+ return command_line.HasSwitch(switches::kEnableGPUSandbox);
+#else
+ return true;
Chris Evans 2012/06/08 07:13:57 return !command_line.HasSwitch(kDisable) -- see be
Jorge Lucangeli Obes 2012/06/11 20:23:04 Done.
+#endif
+}
+
} // anonymous namespace
namespace content {
@@ -412,7 +421,8 @@ void InitializeSandbox() {
std::vector<struct sock_filter> program;
EmitPreamble(&program);
- if (process_type == switches::kGpuProcess) {
+ if (process_type == switches::kGpuProcess &&
+ ShouldEnableGPUSandbox()) {
Chris Evans 2012/06/08 07:13:57 You want to do it above, otherwise you'll crash in
Jorge Lucangeli Obes 2012/06/11 20:23:04 Done.
ApplyGPUPolicy(&program);
EmitTrap(&program); // Default deny.
} else if (process_type == switches::kPpapiPluginProcess) {
@@ -442,4 +452,3 @@ void InitializeSandbox() {
} // namespace content
#endif
-
« no previous file with comments | « no previous file | content/gpu/gpu_main.cc » ('j') | content/gpu/gpu_main.cc » ('J')

Powered by Google App Engine
This is Rietveld 408576698