Bug 1867898 - Use more clone() flags for Utility r=gcp

Differential Revision: https://phabricator.services.mozilla.com/D195847
This commit is contained in:
Alexandre Lissy 2024-05-29 06:28:55 +00:00
parent 84c3f34421
commit 28c259722c

View file

@ -319,6 +319,13 @@ void SandboxLaunch::Configure(GeckoProcessType aType, SandboxingKind aKind,
flags |= CLONE_NEWNET;
}
break;
case GeckoProcessType_Utility:
if (level >= 1) {
canChroot = true;
flags |= CLONE_NEWIPC;
flags |= CLONE_NEWNET;
}
break;
case GeckoProcessType_Content:
if (level >= 4) {
canChroot = true;