Security/Sandbox: Difference between revisions

Jump to navigation Jump to search
Don't repeat all restrictions at every level
(Don't repeat all restrictions at every level)
Line 327: Line 327:
|-
|-
| Level 2 ||
| Level 2 ||
* Many syscalls, including process creation
* Everything from level 1
* Write access to the filesystem
* Write access to the filesystem
** Excludes shared memory, tempdir, video hardware
** Excludes shared memory, tempdir, video hardware
|-
|-
| Level 3 ||  
| Level 3 ||  
* Many syscalls, including process creation
* Everything from level 1-2
* Write access to the filesystem
** Excludes shared memory, tempdir, video hardware
* Read access to most of the filesystem
* Read access to most of the filesystem
** Excludes themes/GTK configuration, fonts, shared data and libraries
** Excludes themes/GTK configuration, fonts, shared data and libraries
|-
|-
| Level 4 ||
| Level 4 ||
* Everything from level 1-3
* Network access including local sockets
* Network access including local sockets
** Excludes X11 socket
** Excludes X11 socket
Confirmed users
334

edits

Navigation menu