Skip to content

Commit

Permalink
Merge pull request google#7169 from sjwheel:patch-1
Browse files Browse the repository at this point in the history
PiperOrigin-RevId: 431788150
  • Loading branch information
gvisor-bot committed Mar 1, 2022
2 parents d79504d + 025bcdb commit 53385a9
Showing 1 changed file with 2 additions and 1 deletion.
3 changes: 2 additions & 1 deletion g3doc/architecture_guide/resources.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,8 @@ descriptor to the Sentry via [SCM_RIGHTS][scmrights][^1].
These files may be read from and written to through standard system calls, and
also mapped into the associated application's address space. This allows the
same host memory to be shared across multiple sandboxes, although this mechanism
does not preclude the use of side-channels (see [Security Model](./security.md).
does not preclude the use of side-channels (see
[Security Model](./security.md)).

Note that some file systems exist only within the context of the sandbox. For
example, in many cases a `tmpfs` mount will be available at `/tmp` or
Expand Down

0 comments on commit 53385a9

Please sign in to comment.