Skip to content

Conversation

@WavyEbuilder
Copy link
Contributor

Upstream no longer supports the SELinux sandbox[1], so no dyntrans is attempted, making this domain redundent. It's been long enough now that it is reasonable to drop this domain.

[1] https://github.com/chromium/chromium/blob/0f8100c82dc431809d866e5d0218cbe3c482b20c/sandbox/linux/README.md?plain=1#L31

Upstream no longer supports the SELinux sandbox[1], so no dyntrans is
attempted, making this domain redundent. It's been long enough now that
it is reasonable to drop this domain.

[1] https://github.com/chromium/chromium/blob/0f8100c82dc431809d866e5d0218cbe3c482b20c/sandbox/linux/README.md?plain=1#L31

Signed-off-by: Rahul Sandhu <[email protected]>
@WavyEbuilder
Copy link
Contributor Author

WavyEbuilder commented Nov 8, 2025

I should note that this shouldn't really cause breakage: the policy doesn't seem to work as is on either X11 or Wayland boxes running the latest version of chrome for me. More patches to come.

@0xC0ncord
Copy link
Contributor

LGTM. Sure enough I don't see this domain getting used by Chrome 142 at all. Seems unfortunate in my opinion but there's nothing we can do here to preserve the separate domain---the renderer process is just chrome with different arguments.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants