You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
allowlists: Create allowlist for DisableNamespaces.
This allows to control who is able to disable Linux namespaces via the policybuilder.
Namespaces are a core element of Sandbox2's security posture. We're therefore implementing a similar mechanism as existing for allowing to call all syscalls.
We also introduce a new location for all allowlist tokens to better manage the
code concerned with this functionality.
PiperOrigin-RevId: 721816939
Change-Id: Ic00b1ff9754afc779c4c5155d1ec3c059c3ff5c9
0 commit comments