mirror of
https://github.com/ElementsProject/elements.git
synced 2026-08-16 13:01:19 +02:00
Remove the syscall sandbox
After initially being merged in #20487, it's no-longer clear that an internal syscall sandboxing mechanism is something that Bitcoin Core should have/maintain, especially when compared to better maintained/supported alterantives, i.e firejail. Note that given where it's used, the sandbox also gets dragged into the kernel. There is some related discussion in #24771. This should not require any sort of deprecation, as this was only ever an opt-in, experimental feature. Closes #24771.
This commit is contained in:
parent
b3db18a012
commit
32e2ffc393
28 changed files with 5 additions and 1175 deletions
|
|
@ -24,7 +24,6 @@
|
|||
#include <util/check.h>
|
||||
#include <util/exception.h>
|
||||
#include <util/strencodings.h>
|
||||
#include <util/syscall_sandbox.h>
|
||||
#include <util/syserror.h>
|
||||
#include <util/threadnames.h>
|
||||
#include <util/tokenpipe.h>
|
||||
|
|
@ -242,7 +241,6 @@ static bool AppInit(NodeContext& node)
|
|||
daemon_ep.Close();
|
||||
}
|
||||
#endif
|
||||
SetSyscallSandboxPolicy(SyscallSandboxPolicy::SHUTOFF);
|
||||
return fRet;
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue