Bug 1362537 - Re-disallow accept4 in Linux content processes. r?gcp draft
authorJed Davis <jld@mozilla.com>
Tue, 27 Jun 2017 14:52:25 -0700
changeset 600935 4e232b8995dabd54b495ecd8b2cd99646281b182
parent 595682 58c5151bfd62de934b2286dbd664e69886270e28
child 635125 9db5f6ebdcb86d286860339354929e81f1de8070
push id65910
push userbmo:jld@mozilla.com
push dateTue, 27 Jun 2017 22:11:44 +0000
reviewersgcp
bugs1362537
milestone56.0a1
Bug 1362537 - Re-disallow accept4 in Linux content processes. r?gcp MozReview-Commit-ID: Gml8lR1Heu1
security/sandbox/linux/SandboxFilter.cpp
--- a/security/sandbox/linux/SandboxFilter.cpp
+++ b/security/sandbox/linux/SandboxFilter.cpp
@@ -552,17 +552,16 @@ public:
 #ifdef ANDROID
     case SYS_SOCKET:
       return Some(Error(EACCES));
 #else // #ifdef DESKTOP
     case SYS_RECV:
     case SYS_SEND:
     case SYS_SOCKET: // DANGEROUS
     case SYS_CONNECT: // DANGEROUS
-    case SYS_ACCEPT4: // Used by a11y; see bug 1361238
     case SYS_GETSOCKOPT:
     case SYS_SETSOCKOPT:
     case SYS_GETSOCKNAME:
     case SYS_GETPEERNAME:
     case SYS_SHUTDOWN:
       return Some(Allow());
 #endif
     default: