Google's Chromium sandbox
Google's Chromium sandbox
Posted Aug 19, 2009 23:36 UTC (Wed) by ncm (guest, #165)Parent article: Google's Chromium sandbox
Couldn't another process use ptrace to perform memory allocations and similar system calls on behalf of the restricted one, as gdb does? The restricted thread can actually be stopped during the call, making it unable to do anything to interfere. The secure thread would just be a two-instruction halt loop, then.
