Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(1872)

Unified Diff: content/common/sandbox_linux/sandbox_bpf_base_policy_linux.h

Issue 99133015: Linux Sandbox: split the GPU policies to their own file. (Closed) Base URL: svn://svn.chromium.org/chrome/trunk/src
Patch Set: Remove obsolete InitGpuBrokerProcess argument. Created 7 years ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: content/common/sandbox_linux/sandbox_bpf_base_policy_linux.h
diff --git a/content/common/sandbox_bpf_base_policy_linux.h b/content/common/sandbox_linux/sandbox_bpf_base_policy_linux.h
similarity index 68%
rename from content/common/sandbox_bpf_base_policy_linux.h
rename to content/common/sandbox_linux/sandbox_bpf_base_policy_linux.h
index 8edba1dd37910adb05de734217170020a30cb2d9..037543ebc41799a325f61432d9d891008dc890e5 100644
--- a/content/common/sandbox_bpf_base_policy_linux.h
+++ b/content/common/sandbox_linux/sandbox_bpf_base_policy_linux.h
@@ -2,8 +2,8 @@
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.
-#ifndef CONTENT_COMMON_SANDBOX_BPF_BASE_POLICY_LINUX_H_
-#define CONTENT_COMMON_SANDBOX_BPF_BASE_POLICY_LINUX_H_
+#ifndef CONTENT_COMMON_SANDBOX_LINUX_SANDBOX_BPF_BASE_POLICY_LINUX_H_
+#define CONTENT_COMMON_SANDBOX_LINUX_SANDBOX_BPF_BASE_POLICY_LINUX_H_
#include "base/basictypes.h"
#include "base/memory/scoped_ptr.h"
@@ -26,6 +26,13 @@ class SandboxBPFBasePolicy : public sandbox::SandboxBPFPolicy {
virtual ErrorCode EvaluateSyscall(SandboxBPF* sandbox_compiler,
int system_call_number) const OVERRIDE;
+ // A policy can implement this hook to run code right before the policy
+ // is passed to the SandboxBPF class and the sandbox is engaged.
+ // If PreSandboxHook() returns true, the sandbox is guaranteed to be
+ // engaged afterwards.
+ // This will be used when enabling the sandbox though
+ // SandboxSeccompBPF::StartSandbox().
+ virtual bool PreSandboxHook();
Robert Sesek 2013/12/12 21:33:48 nit: blank line before comment and after method
jln (very slow on Chromium) 2013/12/12 22:15:14 Done.
// Get the errno(3) to return for filesystem errors.
static int GetFSDeniedErrno();
@@ -37,4 +44,4 @@ class SandboxBPFBasePolicy : public sandbox::SandboxBPFPolicy {
} // namespace content
-#endif // CONTENT_COMMON_SANDBOX_BPF_BASE_POLICY_LINUX_H_
+#endif // CONTENT_COMMON_SANDBOX_LINUX_SANDBOX_BPF_BASE_POLICY_LINUX_H_

Powered by Google App Engine
This is Rietveld 408576698