Remove the syscall sandbox - #27896
Merged
Merged
Conversation
After initially being merged in bitcoin#20487, it's no-longer clear that an internal syscall sandboxing mechanism is something that Bitcoin Core should have/maintain, especially when compared to better maintained/supported alterantives, i.e firejail. Note that given where it's used, the sandbox also gets dragged into the kernel. There is some related discussion in bitcoin#24771. This should not require any sort of deprecation, as this was only ever an opt-in, experimental feature. Closes bitcoin#24771.
Contributor
|
The following sections might be updated with supplementary metadata relevant to reviewers and maintainers. ReviewsSee the guideline for information on the review process.
If your review is incorrectly listed, please react with 👎 to this comment and the bot will ignore it on the next update. ConflictsReviewers, this pull request conflicts with the following ones:
If you consider this pull request important, please also help to review the conflicting pull requests. Ideally, start with the one that should be merged first. |
This was referenced Jun 16, 2023
Member
|
Concept ACK 🟥🟥🟥 |
This was referenced Jun 16, 2023
Member
|
Concept ACK. |
dergoegge
approved these changes
Jun 26, 2023
Contributor
|
crACK 32e2ffc Nit: We may want to remove |
Contributor
Member
|
ACK 32e2ffc The syscall sandbox has a rather significant maintenance burden for rather limited benefit. |
fanquake
added a commit
to fanquake/oss-fuzz
that referenced
this pull request
Nov 7, 2023
This has been removed upstream: bitcoin/bitcoin#27896.
DavidKorczynski
pushed a commit
to google/oss-fuzz
that referenced
this pull request
Nov 7, 2023
This has been removed upstream: bitcoin/bitcoin#27896.
4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
After initially being merged in #20487, it's no-longer clear that an internal syscall sandboxing mechanism is something that Bitcoin Core should have/maintain, especially when compared to better maintained/supported alterantives, i.e firejail.
There is more related discussion in #24771.
Note that given where it's used, the sandbox also gets dragged into the kernel.
If it's removed, this should not require any sort of deprecation, as this was only ever an opt-in, experimental feature.
Closes #24771.