ladybird/Services/ImageDecoder
Andreas Kling ba87a32626 LibSandbox: Add reusable sandbox building blocks
Move the Linux no_new_privs, Landlock, and seccomp policy plumbing
into LibSandbox so individual services can describe the privileges they
need without copying the BPF and kernel feature detection machinery.

Keep ImageDecoder's sandbox policy service-local by composing the new
building blocks in SandboxLinux.cpp. This preserves the existing syscall
allowlist while making the policy easier to audit and reuse.
2026-06-09 19:35:09 +02:00
..
CMakeLists.txt LibSandbox: Add reusable sandbox building blocks 2026-06-09 19:35:09 +02:00
ConnectionFromClient.cpp ImageDecoder: Decode images on ThreadPool 2026-06-05 20:00:12 +02:00
ConnectionFromClient.h ImageDecoder: Decode images on ThreadPool 2026-06-05 20:00:12 +02:00
Forward.h Everywhere: Hoist the Services folder to the top-level 2024-11-10 12:50:45 +01:00
ImageDecoderClient.ipc LibImageDecoderClient: Remove sync id fetch from async decode request 2026-02-28 00:04:06 -06:00
ImageDecoderServer.ipc LibIPC+LibWeb+LibWebView+Services: Add IPC::TransportHandle 2026-03-12 20:32:55 +01:00
LeakSanitizer.cpp ImageDecoder: Disable LSan in the sandboxed helper 2026-06-09 19:35:09 +02:00
main.cpp ImageDecoder: Sandbox the process on Linux 2026-06-09 19:35:09 +02:00
Sandbox.h ImageDecoder: Sandbox the process on Linux 2026-06-09 19:35:09 +02:00
SandboxLinux.cpp LibSandbox: Add reusable sandbox building blocks 2026-06-09 19:35:09 +02:00
SandboxUnimplemented.cpp ImageDecoder: Sandbox the process on Linux 2026-06-09 19:35:09 +02:00