gecko-dev/security/sandbox
Jed Davis 0daa28d9cb Bug 1294286 - Filter clock IDs in clock_getres sandbox rule. r=gcp
The clockid_t type on Linux has a space of values with encode a pid and
refer to various measures of another process's CPU usage; clock_getres
would, thereby, allow probing whether other processes exist.  This is
a relatively small information leak into the sandboxes, but there's no
reason to allow it.

Differential Revision: https://phabricator.services.mozilla.com/D54081

--HG--
extra : moz-landing-system : lando
2019-11-21 08:02:06 +00:00
..
chromium Bug 1591117 - Report ENOSYS on statx, but allow membarrier. r=jld 2019-11-07 09:21:51 +00:00
chromium-shim Bug 1565848: Revert latest change to MITIGATION_DLL_SEARCH_ORDER. r=aklotz 2019-07-25 17:44:24 +00:00
common Bug 1585732 - use staticprefs for media.cubeb.sandbox, r=haik 2019-10-29 23:33:45 +00:00
linux Bug 1294286 - Filter clock IDs in clock_getres sandbox rule. r=gcp 2019-11-21 08:02:06 +00:00
mac Bug 1587962 - [10.15] "Use keyboard navigation" and "jump to spot" scrolling preferences do not work r=spohl 2019-10-23 19:56:56 +00:00
test Bug 1586888 - Test security/sandbox/test/browser_content_sandbox_fs.js has failures on macOS Catalina r=gcp 2019-10-29 10:45:43 +00:00
win Bug 1580742: Allow sandboxed x86 GMP process to duplicate crashreporter handle to the arm64 main process. r=handyman 2019-11-06 20:25:59 +00:00
moz.build Bug 1552160 Part 1: Roll-up of chromium sandbox update and mozilla patches to get a running browser. r=jld,aklotz,tjr,bobowen 2019-06-12 11:10:48 +01:00