Index: content/common/sandbox_linux/sandbox_bpf_base_policy_linux.h |
diff --git a/content/common/sandbox_bpf_base_policy_linux.h b/content/common/sandbox_linux/sandbox_bpf_base_policy_linux.h |
similarity index 68% |
rename from content/common/sandbox_bpf_base_policy_linux.h |
rename to content/common/sandbox_linux/sandbox_bpf_base_policy_linux.h |
index 8edba1dd37910adb05de734217170020a30cb2d9..037543ebc41799a325f61432d9d891008dc890e5 100644 |
--- a/content/common/sandbox_bpf_base_policy_linux.h |
+++ b/content/common/sandbox_linux/sandbox_bpf_base_policy_linux.h |
@@ -2,8 +2,8 @@ |
// Use of this source code is governed by a BSD-style license that can be |
// found in the LICENSE file. |
-#ifndef CONTENT_COMMON_SANDBOX_BPF_BASE_POLICY_LINUX_H_ |
-#define CONTENT_COMMON_SANDBOX_BPF_BASE_POLICY_LINUX_H_ |
+#ifndef CONTENT_COMMON_SANDBOX_LINUX_SANDBOX_BPF_BASE_POLICY_LINUX_H_ |
+#define CONTENT_COMMON_SANDBOX_LINUX_SANDBOX_BPF_BASE_POLICY_LINUX_H_ |
#include "base/basictypes.h" |
#include "base/memory/scoped_ptr.h" |
@@ -26,6 +26,13 @@ class SandboxBPFBasePolicy : public sandbox::SandboxBPFPolicy { |
virtual ErrorCode EvaluateSyscall(SandboxBPF* sandbox_compiler, |
int system_call_number) const OVERRIDE; |
+ // A policy can implement this hook to run code right before the policy |
+ // is passed to the SandboxBPF class and the sandbox is engaged. |
+ // If PreSandboxHook() returns true, the sandbox is guaranteed to be |
+ // engaged afterwards. |
+ // This will be used when enabling the sandbox though |
+ // SandboxSeccompBPF::StartSandbox(). |
+ virtual bool PreSandboxHook(); |
Robert Sesek
2013/12/12 21:33:48
nit: blank line before comment and after method
jln (very slow on Chromium)
2013/12/12 22:15:14
Done.
|
// Get the errno(3) to return for filesystem errors. |
static int GetFSDeniedErrno(); |
@@ -37,4 +44,4 @@ class SandboxBPFBasePolicy : public sandbox::SandboxBPFPolicy { |
} // namespace content |
-#endif // CONTENT_COMMON_SANDBOX_BPF_BASE_POLICY_LINUX_H_ |
+#endif // CONTENT_COMMON_SANDBOX_LINUX_SANDBOX_BPF_BASE_POLICY_LINUX_H_ |