Skip to content

Commit 99c60f3

Browse files
Privacy Sandbox Teamcopybara-github
Privacy Sandbox Team
authored andcommitted
fix: Drop additional capabilities in the reloader.
Bug: NA Change-Id: Id0fe14c38b28e9ce3c459ba22031da63cd928b58 GitOrigin-RevId: 35e430df40018c721f1b335d667d7fe0721d5c79
1 parent b659f7d commit 99c60f3

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

src/roma/byob/container/run_workers.cc

+5
Original file line numberDiff line numberDiff line change
@@ -306,6 +306,11 @@ int ReloaderImpl(void* arg) {
306306
GetSourcesAndTargets(reloader_impl_arg.mounts)) {
307307
sources_and_targets_read_only.push_back({target, target});
308308
}
309+
CHECK_OK(SetPrctlOptions({{PR_CAPBSET_DROP, CAP_SYS_BOOT},
310+
{PR_CAPBSET_DROP, CAP_SYS_MODULE},
311+
{PR_CAPBSET_DROP, CAP_SYS_RAWIO},
312+
{PR_CAPBSET_DROP, CAP_MKNOD},
313+
{PR_CAPBSET_DROP, CAP_NET_ADMIN}}));
309314
while (true) {
310315
// Start a new worker.
311316
const std::string execution_token = GenerateUuid();

0 commit comments

Comments
 (0)