3 ms·
Neither of these things are possible in a sandboxed browser: the syscalls are blocked, and the filesystem isn't (fully) accessible.
by rockdoe 4y ago
Neither of these things are possible in a sandboxed browser: the syscalls are blocked, and the filesystem isn't (fully) accessible.
- tinus_hn 4y agoWhat is the mechanism for this kind of sandboxing?
- staticassertion 4y agoNamespaces let you create isolated views of the file system, isolated views of processes (ex: if you are in a new pid namespace and run 'ps' you only see yourself), users, network interfaces, etc. I'm not sure what Firefox does, I believe they use the Chromium sandbox, and I'm way out of date on that. It used to do some filesystem setup like hardened chroots, but I would assume that's been supplanted by fs namespacing.
- tinus_hn 4y agoLooks cool, I clearly haven’t kept up with this.
- pcwalton 4y agoGoogle [seccomp bpf].