Re: [PATCH v2] proc: allow restricting /proc/pid/mem writes

From: Kees Cook
Date: Tue Mar 05 2024 - 13:34:10 EST


On Tue, Mar 05, 2024 at 12:03:21PM +0100, Christian Brauner wrote:
> What btw, is the Linux sandbox on Chromium doing? Did they finally move
> away from SECCOMP_RET_TRAP to SECCOMP_RET_USER_NOTIF? I see:
>
> https://issues.chromium.org/issues/40145101
>
> What ever became of this?

I'm not entirely sure. I don't think it's been a priority lately
(obviously).

--
Kees Cook