summaryrefslogtreecommitdiff
path: root/chromium/sandbox/features.gni
diff options
context:
space:
mode:
authorAllan Sandfeld Jensen <allan.jensen@qt.io>2020-10-12 14:27:29 +0200
committerAllan Sandfeld Jensen <allan.jensen@qt.io>2020-10-13 09:35:20 +0000
commitc30a6232df03e1efbd9f3b226777b07e087a1122 (patch)
treee992f45784689f373bcc38d1b79a239ebe17ee23 /chromium/sandbox/features.gni
parent7b5b123ac58f58ffde0f4f6e488bcd09aa4decd3 (diff)
downloadqtwebengine-chromium-85-based.tar.gz
BASELINE: Update Chromium to 85.0.4183.14085-based
Change-Id: Iaa42f4680837c57725b1344f108c0196741f6057 Reviewed-by: Allan Sandfeld Jensen <allan.jensen@qt.io>
Diffstat (limited to 'chromium/sandbox/features.gni')
-rw-r--r--chromium/sandbox/features.gni5
1 files changed, 5 insertions, 0 deletions
diff --git a/chromium/sandbox/features.gni b/chromium/sandbox/features.gni
index 09280d35f6a..46c8a03f45e 100644
--- a/chromium/sandbox/features.gni
+++ b/chromium/sandbox/features.gni
@@ -14,3 +14,8 @@ use_seccomp_bpf = (is_linux || is_android) &&
current_cpu == "mipsel" || current_cpu == "mips64el")
use_seccomp_bpf = use_seccomp_bpf || is_nacl_nonsfi
+
+# SSBD (Speculative Store Bypass Disable) is a mitigation of Spectre Variant 4.
+# As Spectre Variant 4 can be mitigated by site isolation, opt-out SSBD on site
+# isolation fully applied platform.
+disable_seccomp_ssbd = use_seccomp_bpf && !is_android