Skip to content

Conversation

@RKNF404
Copy link
Collaborator

@RKNF404 RKNF404 commented Jun 26, 2025

This doesn't enable drumbrake (wasm interpreter) but it allows trivially flipping the toggle on.

This also removes the unnecessary patches, which means current JIT overrides will be cleared.

@RKNF404 RKNF404 requested a review from RoyalOughtness as a code owner June 26, 2025 02:51
@RoyalOughtness
Copy link
Contributor

@RKNF404
Copy link
Collaborator Author

RKNF404 commented Jun 29, 2025

these changes won't impact https://github.com/secureblue/Trivalent/blob/live/vanadium_patches/0188-Restriction-of-dynamic-code-execution-via-seccomp-bp.patch, right?

It shouldn't since that patch depends on the --jitless flag, not the JIT pref, which we are currently setting either way

RoyalOughtness
RoyalOughtness previously approved these changes Jun 29, 2025
@RoyalOughtness RoyalOughtness merged commit a8467d4 into secureblue:live Jun 29, 2025
5 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants