52 Commits

Author SHA1 Message Date
cbl
42242ba1a7 disable pid ns
Signed-off-by: cbl <caobaolong5@huawei.com>
2024-05-21 14:45:59 +08:00
wangfeng
94c705818b Normalization rectification of sandbox model
Signed-off-by: wangfeng <wangfeng277@huawei.com>
2024-03-21 21:34:31 +08:00
zhongning5
b0be821519 enable appdata sandbox
Signed-off-by: zhongning5 <zhongning5@huawei.com>
2024-03-16 10:51:06 +08:00
c30043414
b174e909e8 pid namespace enable
Signed-off-by: c30043414 <caobaolong5@huawei.com>
2024-01-11 10:57:35 +08:00
zhushengle
dfc1410694 feat: 支持应用pid沙箱
Signed-off-by: zhushengle <zhushengle@huawei.com>
Change-Id: Iaa2d01052fe789596b19ecab6feb335844394f14
2023-11-22 11:01:15 +08:00
cheng_jinsong
8e6c98e08e build appdata sandbox
Signed-off-by: cheng_jinsong <chengjinsong2@huawei.com>
2023-05-06 14:47:48 +08:00
renzehua
0c536a242e Render sandbox switch is not enabled and this switch is not needed. Because when a app enabled sandbox, its render need enable sandbox too.
Signed-off-by: renzehua <renzehua3@huawei.com>
Change-Id: I75a62fe94a4a9f217a19e5a09ec9b53fc7fa277e
2023-03-01 09:53:20 +08:00
zhangfanfan2
6f7f881241
fix: 增加系统资源的沙箱路径
Signed-off-by: zhangfanfan2 <zhangfanfan2@huawei.com>
2023-02-16 10:13:22 +00:00
xiongjun_gitee
75e1e495f6 render process adds the /system/app/NWeb sandbox path
Signed-off-by: xiongjun_gitee <xiongjun28@huawei.com>
2023-02-14 16:47:15 +08:00
zhangkaixiang
a693223295 ad the share dir to sandbox
Signed-off-by: zhangkaixiang <zhangkaixiang5@huawei.com>
2023-02-13 17:03:21 +08:00
XUBO
2d4177dc22 add render relro feature
Signed-off-by: XUBO <xubomain@163.com>
2023-01-17 03:19:06 +00:00
zhang-daiyue
aab0703377 Add epfs mount for userfile_manager
Signed-off-by: zhang-daiyue <zhangdaiyue1@huawei.com>
Change-Id: I8770aa750db6fc0cbe3d33a363f7194322151ce6
2023-01-08 14:19:07 +00:00
openharmony_ci
46cf8051e8
!498 渲染进程沙箱支持渲染进程应用多开
Merge pull request !498 from 任泽华/render_sandbox_flagpoint
2023-01-04 02:02:45 +00:00
renzehua3@huawei.com
79ff1417b7 Signed-off-by: renzehua3@huawei.com <renzehua3@huawei.com>
Add flagsPoint control for rendering process's sandbox.
Change-Id: I5ccc31c4a59aa71be57a90176d4e6bac39f2fab8

Change-Id: I678f892686f31f27c7a8b4887e2f93387df1372e
2022-12-30 14:52:52 +08:00
lvjunmao
7b1a2ea9db fix render process gdb debug
Signed-off-by: lvjunmao <lvjunmao@huawei.com>
Change-Id: I4ee148a8c4ea89f16c87b4172cb26ecdfcdf5ec4
2022-12-29 19:35:54 +08:00
SEASON_SYSU
298b2cb753
update appdata-sandbox64.json.
Signed-off-by: SEASON_SYSU <liusicheng8@huawei.com>
2022-11-24 08:12:31 +00:00
tangzhigang1
2875eba73d systemUI沙箱配置
Signed-off-by: tangzhigang1 <tangzhigang7@huawei.com>
2022-11-24 10:56:16 +08:00
openharmony_ci
369cb90472
!467 hap包不解压web组件加载,修改render进程沙箱环境
Merge pull request !467 from xiongjun_gitee/master
2022-11-21 02:40:26 +00:00
dujingcheng@huawei.com
b668f3fe18 add ark-profile sanbox
Signed-off-by: dujingcheng@huawei.com <dujingcheng@huawei.com>
Change-Id: I62bbf2d083f19ce102185d02ef1aaa02e91a103b
2022-11-16 14:20:54 +08:00
xiongjun_gitee
ea77339a21 hap package is not decompressed
Signed-off-by: xiongjun_gitee <xiongjun28@huawei.com>
2022-11-14 16:00:01 +08:00
openharmony_ci
3eaea3109f
!464 Web渲染进程添加权限
Merge pull request !464 from pilipala195/master
2022-11-09 06:19:48 +00:00
yangguangzhao
575f0763f9 web render process add /system/bin access permission
Signed-off-by: yangguangzhao <yangguangzhao1@huawei.com>
2022-11-07 19:09:26 +08:00
Zheng Yongjun
a011235ad6 don't check el2 bind mount options
Signed-off-by: Zheng Yongjun <zhengyongjun3@huawei.com>
2022-11-03 23:00:41 +08:00
dujingcheng@huawei.com
0874a4b4b3 add data/local/ark-cache 64
Signed-off-by: dujingcheng@huawei.com <dujingcheng@huawei.com>
Change-Id: I6c82d75d229fbd9eff24629b6b6e71ccf6874de6
2022-10-24 21:52:11 +08:00
huangjie
e8f47d1018 overlay资源映射
Signed-off-by: huangjie <huangjie125@huawei.com>
2022-10-11 16:12:58 +08:00
openharmony_ci
81d960ed63
!394 挂载SystemResources.hap
Merge pull request !394 from maoziduanl/master
2022-10-11 01:30:33 +00:00
openharmony_ci
fc4ac6a59e
!428 渲染进程沙箱差异化
Merge pull request !428 from 任泽华/render_sandbox_different
2022-09-30 07:49:38 +00:00
renzehua3@huawei.com
0e2cb5bacb Signed-off-by: renzehua3@huawei.com <renzehua3@huawei.com>
Change-Id: I5a8ead048bf2c5957536503c16748e8a45586e5d

Change-Id: I7f9666700bc7c1112660b5c9202d62c9e40fc806
2022-09-29 17:00:52 +08:00
ljc
41dff15690 remove redundant setting of sandbox settings
Signed-off-by: ljc <chengjinsong2@huawei.com>
2022-09-19 14:17:34 +08:00
martin
4b5dde30e2 add asan to sandbox
Signed-off-by: martin <dxd_09101011@163.com>
2022-09-10 00:03:04 +08:00
huangjie
139c0963c8 挂载SystemResources.hap
Signed-off-by: huangjie <huangjie125@huawei.com>
2022-09-03 14:38:18 +08:00
lyj_love_code
da6bbc3275 add hiviewx and betaclub to sanbox
Signed-off-by: lyj_love_code <liangyujian2@huawei.com>
2022-08-20 16:19:28 +08:00
HuaQingSiMeng
1b648b30e4 Map backup's home dir into the sandbox
Signed-off-by: HuaQingSiMeng <qiukaiqing@huawei.com>
2022-08-05 11:19:32 +08:00
Vincent Peng
d10650a47d make app separation work
Signed-off-by: Vincent Peng <vincentyh@hotmail.com>
2022-08-01 14:30:58 +08:00
Zheng Yongjun
25e5bd8cf9 Add more vendor support to fix app not works well in some devices.
Signed-off-by: Zheng Yongjun <zhengyongjun3@huawei.com>
2022-07-18 21:12:30 +08:00
zourongchun
9af8b852d3 fix https video play
Signed-off-by: zourongchun <zourongchun@huawei.com>
2022-07-13 15:58:44 +08:00
Michael
c5e1295e7b hmdfs sandbox add userid
Signed-off-by: Michael <xianghengliang1@huawei.com>
2022-07-08 16:56:27 +08:00
Zheng Yongjun
a1eb5a1d58 关闭相机在某些设备上的沙箱
Signed-off-by: Zheng Yongjun <zhengyongjun3@huawei.com>
2022-07-07 14:46:30 +08:00
Zheng Yongjun
b542ff0562 使能appspawn识别DLP_MANAGER孵化参数并且实现特殊挂载
1,识别DLP_MANAGER的参数并实现特殊挂载
2,过滤WPS应用特殊情况下的数据目录挂载
3,增加对于wps应用的配置参数样例

Signed-off-by: Zheng Yongjun <zhengyongjun3@huawei.com>
2022-06-29 17:35:32 +08:00
openharmony_ci
c7968b2249
!275 add file access framework
Merge pull request !275 from wangjianqiang/master
2022-06-25 11:44:58 +00:00
wangjianqiang
a04ef649e1 clean question
Signed-off-by: wangjianqiang <wangjianqiang19@huawei.com>
2022-06-22 20:52:13 +08:00
wangjianqiang
07b16e51a0 add file access framework
Signed-off-by: wangjianqiang <wangjianqiang19@huawei.com>
2022-06-21 21:28:18 +08:00
Lihong Kou
b1b9f87ea1 medialibrary: remove unused hap sandbox config
Signed-off-by: Lihong Kou <koulihong@huawei.com>
Change-Id: Ia2297c16a0a2fc965b938c2288c22461c1c7ee67
2022-06-20 19:34:47 +08:00
openharmony_ci
3d3636c4fa
!250 沙盒64位增加/system/lib目录
Merge pull request !250 from Mupceet/appspawn_sandbox
2022-06-07 08:03:42 +00:00
Zheng Yongjun
af36e0c2d7 修改dlp应用的包名信息
Signed-off-by: Zheng Yongjun <zhengyongjun3@huawei.com>
2022-06-06 10:06:40 +08:00
Mupceet
3bedb56cd9 appspawn: add directoty /system/lib by mount /system/lib
Signed-off-by: Mupceet <laiguizhong@huawei.com>
Change-Id: I614d418939260c2ea6a454e815ba66ee67cc956a
2022-06-01 17:24:46 +08:00
Qilong Zhang
eb28f39c30 appspwan:add new medialibrary hap
Signed-off-by: Qilong Zhang <zhangqilong3@huawei.com>
Change-Id: I92e7ee4ced0d7e38468c7c4d279dd49906ad3f6f
2022-06-01 10:37:10 +08:00
openharmony_ci
90fa58d140
!233 增加应用沙箱挂载时的公共挂载机制
Merge pull request !233 from zyj-alex/zhengyongjun/fix-common
2022-05-24 08:37:24 +00:00
Zheng Yongjun
66c9f9ce01 增加对特殊应用进行特殊场景处理的公共框架
Signed-off-by: Zheng Yongjun <zhengyongjun3@huawei.com>
2022-05-24 10:55:05 +08:00
andrewhw
1f889e8d54 add /vendor/lib64/chipsetsdk to sandbox path
Signed-off-by: andrewhw <zhangzhao62@huawei.com>
Change-Id: I52499a72b0198dd2c57459e34fa2426465bbd41e
2022-05-23 14:44:03 +08:00