Effectively disable network access during the build
This starts a new network namespace without any connections to the outside. Bug: 122270019 Test: USE_GOMA=true m libc Test: treehugger Test: add rule to use /usr/bin/wget, fails after this change Change-Id: Iba262025ce0e4e3bef5c34c817cc678d6c61403b
This commit is contained in:
@@ -143,9 +143,6 @@ func (c *Cmd) wrapSandbox() {
|
|||||||
// For now, just map everything. Eventually we should limit this, especially to make most things readonly.
|
// For now, just map everything. Eventually we should limit this, especially to make most things readonly.
|
||||||
"-B", "/",
|
"-B", "/",
|
||||||
|
|
||||||
// Enable networking for now. TODO: remove
|
|
||||||
"-N",
|
|
||||||
|
|
||||||
// Disable newcgroup for now, since it may require newer kernels
|
// Disable newcgroup for now, since it may require newer kernels
|
||||||
// TODO: try out cgroups
|
// TODO: try out cgroups
|
||||||
"--disable_clone_newcgroup",
|
"--disable_clone_newcgroup",
|
||||||
|
Reference in New Issue
Block a user