Modules
Structs
- Config for the sandbox to be created by [Minijail].
- Wrapper that cleans up a [Minijail] when it is dropped
Enums
- The user in the jail to run as.
Constants
- Most devices don’t need to open many fds.
- The max open files for jail warden, matching FD_RAW_FAILURE.
Functions
- Creates a [Minijail] instance which just changes the root using pivot_root(2) path and
max_open_files
usingRLIMIT_NOFILE
. - Creates [Minijail] for gpu processes.
- Creates a [Minijail] instance which creates a sandbox.
- Selectively bind mount drm nodes into
jail
based onrender_node_only
- Mirror-mount all the directories in
dirs
intojail
on a best-effort basis. - Mount proc in the sandbox.
- Creates a basic [Minijail] if
jail_config
is present.