Files
gristlabs_grist-core/app/client/ui
Paul Fitzpatrick 134ae99e9a (core) add gvisor-based sandboxing to core
Summary:
This adds support for gvisor sandboxing in core. When Grist is run outside of a container, regular gvisor can be used (if on linux), and will run in rootless mode. When Grist is run inside a container, docker's default policy is insufficient for running gvisor, so a fork of gvisor is used that has less defence-in-depth but can run without privileges.

Sandboxing is automatically turned on in the Grist core container. It is not turned on automatically when built from source, since it is operating-system dependent.

This diff may break a complex method of testing Grist with gvisor on macs that I may have been the only person using. If anyone complains I'll find time on a mac to fix it :)

This diff includes a small "easter egg" to force document loads, primarily intended for developer use.

Test Plan: existing tests pass; checked that core and saas docker builds function

Reviewers: alexmojaki

Reviewed By: alexmojaki

Subscribers: alexmojaki

Differential Revision: https://phab.getgrist.com/D3333
2022-03-24 17:04:49 -04:00
..
2022-02-19 09:46:49 +00:00
2020-10-02 13:24:21 -04:00
2022-02-19 09:46:49 +00:00
2022-03-12 13:51:48 +01:00
2022-02-10 12:46:19 +02:00
2022-02-19 09:46:49 +00:00
2020-10-02 13:24:21 -04:00
2022-02-19 09:46:49 +00:00
2021-06-29 15:29:56 +02:00
2020-10-02 13:24:21 -04:00
2022-02-19 09:46:49 +00:00
2021-05-25 21:14:49 +02:00
2020-10-02 13:24:21 -04:00
2022-02-19 09:46:49 +00:00
2021-11-05 13:07:30 +01:00
2020-10-02 13:24:21 -04:00
2020-10-02 13:24:21 -04:00