Revert "Use EACCES over EPERM for broker process denied errno" This reverts commit 0d437e022154a5a5509d1232deec787b2a0fa5ea. Reason for revert: Breaks Lacros. [343589:343589:0726/205512.291579:FATAL:sandbox_seccomp_bpf_linux.cc(239)] Check failed: BPFBasePolicy::GetFSDeniedErrno() == (*__errno_location ()) (1 vs. 13) #0 0x7fa2e2e3a8af base::debug::CollectStackTrace() #1 0x7fa2e2baee0a base::debug::StackTrace::StackTrace() #2 0x7fa2e2baedc5 base::debug::StackTrace::StackTrace() #3 0x7fa2e2bfe239 logging::LogMessage::~LogMessage() #4 0x7fa2e2bfe959 logging::LogMessage::~LogMessage() #5 0x7fa2e2b6e5eb logging::CheckError::~CheckError() #6 0x7fa2cc927b2f sandbox::policy::SandboxSeccompBPF::RunSandboxSanityChecks() #7 0x7fa2cc91fc71 sandbox::policy::SandboxLinux::StartSeccompBPF() #8 0x7fa2cc9206fd sandbox::policy::SandboxLinux::InitializeSandbox() #9 0x7fa2d83e65a3 content::(anonymous namespace)::StartSandboxLinux() #10 0x7fa2d83e62b9 content::(anonymous namespace)::ContentSandboxHelper::EnsureSandboxInitialized() #11 0x7fa2a32de13e gpu::GpuInit::InitializeAndStartSandbox() #12 0x7fa2d83e5ca0 content::GpuMain() #13 0x7fa2dbd8a5ad content::RunZygote() #14 0x7fa2dbd8aa3a content::RunOtherNamedProcessTypeMain() #15 0x7fa2dbd8b7b4 content::ContentMainRunnerImpl::Run() #16 0x7fa2dbd889ae content::RunContentProcess() #17 0x7fa2dbd892fd content::ContentMain() #18 0x5588c3250966 ChromeMain #19 0x5588c3250812 main #20 0x7fa2a56aed0a __libc_start_main #21 0x5588c325072a _start To repro the failure, follow go/lacros-build and build linux Lacros. Lacros can't be launched with the failure above. Original change's description: > Use EACCES over EPERM for broker process denied errno > > When dlopen is called without an absolute path, it looks in a number > of search paths for the requested library (e.g. /lib64/libfoo.so, > /usr/lib/libfoo.so). Often, these files don't exist and the > corresponding openat syscall should return ENOENT, but because of > the GPU sandbox, the syscall returns EPERM instead [1]. glibc's > implementation of dlopen, however, early-exits when it sees an > unexpected errno [2] and terminates without attempting the remaining > search paths. Thus, even if the library *is* allowlisted in a later > path, dlopen will still exit with a failure. > > This CL fixes this issue by changing the denied errno to EACCES for > the broker process. > > Bug: 1233028 > Change-Id: I192098eb072f2ee6fb18aa7da3d1998f8328149f > Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/3054490 > Reviewed-by: Matthew Denton <mpdenton@chromium.org> > Reviewed-by: Robert Sesek <rsesek@chromium.org> > Commit-Queue: Brian Ho <hob@chromium.org> > Cr-Commit-Position: refs/heads/master@{#905330} Bug: 1233028 Change-Id: I111ff2bf802615e1299aee7feb88471d49a238e7 No-Presubmit: true No-Tree-Checks: true No-Try: true Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/3055402 Bot-Commit: Rubber Stamper <rubber-stamper@appspot.gserviceaccount.com> Commit-Queue: Victor Vianna <victorvianna@google.com> Owners-Override: Victor Vianna <victorvianna@google.com> Cr-Commit-Position: refs/heads/master@{#905685}
Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.
The project's web site is https://www.chromium.org.
To check out the source code locally, don't use git clone! Instead, follow the instructions on how to get the code.
Documentation in the source is rooted in docs/README.md.
Learn how to Get Around the Chromium Source Code Directory Structure .
For historical reasons, there are some small top level directories. Now the guidance is that new top level directories are for product (e.g. Chrome, Android WebView, Ash). Even if these products have multiple executables, the code should be in subdirectories of the product.
If you found a bug, please file it at https://crbug.com/new.