Skip to content

PVF worker: apply sandboxing per-process #600

Closed
paritytech/polkadot
#7580
@mrcnski

Description

@mrcnski

Currently we apply sandboxing per-thread, when it should be per-process. This shouldn't be a big change, we just need sandboxing exceptions for the artifacts/cache directories.

This should be a priority. Without it, the sandboxing we have with landlock is not really secure.

Related

This is also a blocker for paritytech/polkadot#7334.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions