Gentoo Archives: gentoo-hardened

From: "Paweł Hajdan
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] www-client/chromium SELinux sandbox
Date: Thu, 12 Apr 2012 05:10:31
Message-Id: 4F86637C.9060000@gentoo.org
In Reply to: Re: [gentoo-hardened] www-client/chromium SELinux sandbox by "Paweł Hajdan
1 On 4/10/12 10:10 PM, "Paweł Hajdan, Jr." wrote:
2 > Chromium can be compiled to be SELinux-aware, and it forks itself (and
3 > doesn't call exec - so that the underlying files can be updated in-place
4 > without disrupting running browsers; this is because Chromium has
5 > multi-process architecture and browser<->renderer IPC protocol changes
6 > between versions).
7
8 chromium-20.x (now in the cvs tree, hard masked) has selinux USE flag.
9 You can compile it yourself with USE=selinux and experiment with it, if
10 you want.
11
12 Feedback is welcome as always. :)

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies