[Bug 2011] sandbox selection needs some kind of fallback mechanism

bugzilla-daemon at bugzilla.mindrot.org bugzilla-daemon at bugzilla.mindrot.org
Fri Jun 1 10:42:05 EST 2012


Damien Miller <djm at mindrot.org> changed:

           What    |Removed                     |Added
                 CC|                            |djm at mindrot.org

--- Comment #5 from Damien Miller <djm at mindrot.org> 2012-06-01 10:42:05 EST ---
I think the proposed patch is a little over-complicated. The only
viable fallback path at the moment is to the rlimit pseudo-sandbox, so
let's allow that without fatal() for the seccomp case. Attachment #2160
implements this.

I'm happy to revisit this if we ever have a deeper stack of candidate
sandboxes for a platform.

Configure bugmail: https://bugzilla.mindrot.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching the assignee of the bug.
You are watching someone on the CC list of the bug.

More information about the openssh-bugs mailing list