<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[No SUID-sandbox]]></title><description><![CDATA[<p dir="auto">Hi.</p>
<p dir="auto">I have asked this question at <a href="https://productforums.google.com/forum/#!category-topic/chrome/linux/X4f_Cb1jcj4" target="_blank" rel="noopener noreferrer nofollow ugc">Google Product Forums › Google Chrome Help Forum</a>, but did not get a real answer, so I try here as well.</p>
<p dir="auto">Using Opera 31.0.1857.0 developer on Ubuntu 15.04 64-bit, browser://sandbox/ reports:</p>
<p dir="auto">Sandbox Status</p>
<p dir="auto">SUID Sandbox	Nej</p>
<p dir="auto">Namespace Sandbox	Ja</p>
<p dir="auto">PID namespaces	Ja</p>
<p dir="auto">Network namespaces	Ja</p>
<p dir="auto">Seccomp-BPF sandbox	Ja</p>
<p dir="auto">Seccomp-BPF sandbox supports TSYNC	Ja</p>
<p dir="auto">Yama LSM enforcing	Ja</p>
<p dir="auto">You are adequately sandboxed.</p>
<p dir="auto">This is new with Chromium 42: SUID Sandbox disabled and Namespace Sandbox added. Is Namespace Sandbox supposed to replace SUID Sandbox, or why is SUID disabled?</p>
<p dir="auto">Thanks. <img src="https://forums.opera.com/assets/plugins/nodebb-plugin-emoji/emoji/emoji-one/1f427.png?v=2nadm76gohp" class="not-responsive emoji emoji-emoji-one emoji--penguin" title=":penguin:" alt="🐧" /></p>
]]></description><link>https://forums.opera.com/topic/9692/no-suid-sandbox</link><generator>RSS for Node</generator><lastBuildDate>Mon, 08 Jun 2026 06:13:53 GMT</lastBuildDate><atom:link href="https://forums.opera.com/topic/9692.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 07 May 2015 17:01:40 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to No SUID-sandbox on Sun, 17 May 2015 18:33:54 GMT]]></title><description><![CDATA[<p dir="auto"><a href="https://code.google.com/p/chromium/wiki/LinuxSandboxing" target="_blank" rel="noopener noreferrer nofollow ugc">LinuxSandboxing</a> was updated 12 May. The new version of the document adds:</p>
<p dir="auto">“The namespace sandbox <a href="https://code.google.com/p/chromium/issues/detail?id=312380" target="_blank" rel="noopener noreferrer nofollow ugc">aims to replace the setuid sandbox</a>. It has the advantage of not requiring a setuid binary. It's based on (unprivileged) <a href="https://lwn.net/Articles/531114/" target="_blank" rel="noopener noreferrer nofollow ugc">user namespaces</a> in the Linux kernel. It generally requires a kernel &gt;= 3.10, although it may work with 3.8 if certain patches are backported.</p>
<p dir="auto">Starting with M-43, if the kernel supports it, unprivileged namespaces are used instead of the setuid sandbox. Starting with M-44, certain processes run <a href="https://code.google.com/p/chromium/issues/detail?id=460972" target="_blank" rel="noopener noreferrer nofollow ugc">in their own PID namespace</a>, which isolates them better.”</p>
<p dir="auto">So the answer is that SUID is disabled because the new Namespace Sandbox replaces it (if possible).</p>
<p dir="auto"><img src="https://forums.opera.com/assets/plugins/nodebb-plugin-emoji/emoji/emoji-one/1f427.png?v=2nadm76gohp" class="not-responsive emoji emoji-emoji-one emoji--penguin" title=":penguin:" alt="🐧" /></p>
]]></description><link>https://forums.opera.com/post/75315</link><guid isPermaLink="true">https://forums.opera.com/post/75315</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Sun, 17 May 2015 18:33:54 GMT</pubDate></item><item><title><![CDATA[Reply to No SUID-sandbox on Thu, 07 May 2015 19:20:52 GMT]]></title><description><![CDATA[<p dir="auto">Hi and thank you for the reply. <img src="https://forums.opera.com/assets/plugins/nodebb-plugin-emoji/emoji/emoji-one/1f642.png?v=2nadm76gohp" class="not-responsive emoji emoji-emoji-one emoji--slightly_smiling_face" title=":)" alt="🙂" /></p>
<p dir="auto">It said “You are adequately sandboxed.” also when there was only SUID, PID namespaces and Network namespaces, before Seccomp-BPF (when legacy Seccomp was disabled by default) and before Yama. <img src="https://forums.opera.com/assets/plugins/nodebb-plugin-emoji/emoji/emoji-one/1f609.png?v=2nadm76gohp" class="not-responsive emoji emoji-emoji-one emoji--winking_face" title=";)" alt="😉" /></p>
<p dir="auto">So Namespace Sandbox can be seen as a replacement for SUID?</p>
<p dir="auto">The changelog¹ for Chromium (where SUID is called “setuid”) isn’t very clear (to me), and the documentation² is outdated.</p>
<p dir="auto">¹ <a href="https://chromium.googlesource.com/chromium/src/+log/41.0.2272.0..42.0.2311.0?pretty=fuller&amp;n=10000" target="_blank" rel="noopener noreferrer nofollow ugc">https://chromium.googlesource.com/chromium/src/+log/41.0.2272.0..42.0.2311.0?pretty=fuller&amp;n=10000</a></p>
<p dir="auto">² <a href="https://code.google.com/p/chromium/wiki/LinuxSandboxing" target="_blank" rel="noopener noreferrer nofollow ugc">https://code.google.com/p/chromium/wiki/LinuxSandboxing</a></p>
<p dir="auto">Sorry to read the P.P.S. <img src="https://forums.opera.com/assets/plugins/nodebb-plugin-emoji/emoji/emoji-one/1f61e.png?v=2nadm76gohp" class="not-responsive emoji emoji-emoji-one emoji--disappointed_face" title=":(" alt="😞" /></p>
]]></description><link>https://forums.opera.com/post/74426</link><guid isPermaLink="true">https://forums.opera.com/post/74426</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Thu, 07 May 2015 19:20:52 GMT</pubDate></item><item><title><![CDATA[Reply to No SUID-sandbox on Thu, 07 May 2015 18:27:12 GMT]]></title><description><![CDATA[<p dir="auto">The key point is</p>
<blockquote>
<p dir="auto">You are adequately sandboxed.</p>
</blockquote>
<p dir="auto">SUID sandbox is not needed if your kernel supports the other required features (kernels of 3.17 or newer almost always will and some older kernels if they have been suitably patched by your distro).</p>
<p dir="auto">P.S. The sandbox is still SUID in post install of packaging because not everyone has a suitable kernel.</p>
<p dir="auto">P.P.S. It seems that I still have an employee badge but I have left Opera now, following the shut down of the Desktop team in Olso.</p>
]]></description><link>https://forums.opera.com/post/74424</link><guid isPermaLink="true">https://forums.opera.com/post/74424</guid><dc:creator><![CDATA[ruario]]></dc:creator><pubDate>Thu, 07 May 2015 18:27:12 GMT</pubDate></item></channel></rss>