| OLD | NEW |
| 1 // Copyright (c) 2011 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2011 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #include "chrome/common/sandbox_policy.h" | 5 #include "chrome/common/sandbox_policy.h" |
| 6 | 6 |
| 7 #include <string> | 7 #include <string> |
| 8 | 8 |
| 9 #include "base/command_line.h" | 9 #include "base/command_line.h" |
| 10 #include "base/debug/debugger.h" | 10 #include "base/debug/debugger.h" |
| (...skipping 513 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 524 policy->SetDelayedIntegrityLevel(sandbox::INTEGRITY_LEVEL_LOW); | 524 policy->SetDelayedIntegrityLevel(sandbox::INTEGRITY_LEVEL_LOW); |
| 525 } else { | 525 } else { |
| 526 policy->SetTokenLevel(sandbox::USER_UNPROTECTED, | 526 policy->SetTokenLevel(sandbox::USER_UNPROTECTED, |
| 527 sandbox::USER_LIMITED); | 527 sandbox::USER_LIMITED); |
| 528 } | 528 } |
| 529 | 529 |
| 530 AddDllEvictionPolicy(policy); | 530 AddDllEvictionPolicy(policy); |
| 531 return true; | 531 return true; |
| 532 } | 532 } |
| 533 | 533 |
| 534 void AddPolicyForRenderer(sandbox::TargetPolicy* policy, | 534 void AddPolicyForRenderer(sandbox::TargetPolicy* policy) { |
| 535 bool* on_sandbox_desktop) { | |
| 536 policy->SetJobLevel(sandbox::JOB_LOCKDOWN, 0); | 535 policy->SetJobLevel(sandbox::JOB_LOCKDOWN, 0); |
| 537 | 536 |
| 538 sandbox::TokenLevel initial_token = sandbox::USER_UNPROTECTED; | 537 sandbox::TokenLevel initial_token = sandbox::USER_UNPROTECTED; |
| 539 if (base::win::GetVersion() > base::win::VERSION_XP) { | 538 if (base::win::GetVersion() > base::win::VERSION_XP) { |
| 540 // On 2003/Vista the initial token has to be restricted if the main | 539 // On 2003/Vista the initial token has to be restricted if the main |
| 541 // token is restricted. | 540 // token is restricted. |
| 542 initial_token = sandbox::USER_RESTRICTED_SAME_ACCESS; | 541 initial_token = sandbox::USER_RESTRICTED_SAME_ACCESS; |
| 543 } | 542 } |
| 544 | 543 |
| 545 policy->SetTokenLevel(initial_token, sandbox::USER_LOCKDOWN); | 544 policy->SetTokenLevel(initial_token, sandbox::USER_LOCKDOWN); |
| 546 policy->SetDelayedIntegrityLevel(sandbox::INTEGRITY_LEVEL_LOW); | 545 policy->SetDelayedIntegrityLevel(sandbox::INTEGRITY_LEVEL_LOW); |
| 547 | 546 |
| 548 bool use_winsta = !CommandLine::ForCurrentProcess()->HasSwitch( | 547 bool use_winsta = !CommandLine::ForCurrentProcess()->HasSwitch( |
| 549 switches::kDisableAltWinstation); | 548 switches::kDisableAltWinstation); |
| 550 | 549 |
| 551 if (sandbox::SBOX_ALL_OK == policy->SetAlternateDesktop(use_winsta)) { | 550 if (sandbox::SBOX_ALL_OK != policy->SetAlternateDesktop(use_winsta)) { |
| 552 *on_sandbox_desktop = true; | |
| 553 } else { | |
| 554 *on_sandbox_desktop = false; | |
| 555 DLOG(WARNING) << "Failed to apply desktop security to the renderer"; | 551 DLOG(WARNING) << "Failed to apply desktop security to the renderer"; |
| 556 } | 552 } |
| 557 | 553 |
| 558 AddDllEvictionPolicy(policy); | 554 AddDllEvictionPolicy(policy); |
| 559 } | 555 } |
| 560 | 556 |
| 557 // The Pepper process as locked-down as a renderer execpt that it can |
| 558 // create the server side of chrome pipes. |
| 559 bool AddPolicyForPepperPlugin(sandbox::TargetPolicy* policy) { |
| 560 sandbox::ResultCode result; |
| 561 result = policy->AddRule(sandbox::TargetPolicy::SUBSYS_NAMED_PIPES, |
| 562 sandbox::TargetPolicy::NAMEDPIPES_ALLOW_ANY, |
| 563 L"\\\\.\\pipe\\chrome.*"); |
| 564 if (result != sandbox::SBOX_ALL_OK) { |
| 565 NOTREACHED(); |
| 566 return false; |
| 567 } |
| 568 AddPolicyForRenderer(policy); |
| 569 return true; |
| 570 } |
| 571 |
| 561 } // namespace | 572 } // namespace |
| 562 | 573 |
| 563 namespace sandbox { | 574 namespace sandbox { |
| 564 | 575 |
| 565 void InitBrokerServices(sandbox::BrokerServices* broker_services) { | 576 void InitBrokerServices(sandbox::BrokerServices* broker_services) { |
| 566 // TODO(abarth): DCHECK(CalledOnValidThread()); | 577 // TODO(abarth): DCHECK(CalledOnValidThread()); |
| 567 // See <http://b/1287166>. | 578 // See <http://b/1287166>. |
| 568 CHECK(broker_services); | 579 CHECK(broker_services); |
| 569 CHECK(!g_broker_services); | 580 CHECK(!g_broker_services); |
| 570 broker_services->Init(); | 581 broker_services->Init(); |
| (...skipping 92 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 663 | 674 |
| 664 if (!in_sandbox) { | 675 if (!in_sandbox) { |
| 665 base::LaunchApp(*cmd_line, false, false, &process); | 676 base::LaunchApp(*cmd_line, false, false, &process); |
| 666 return process; | 677 return process; |
| 667 } | 678 } |
| 668 | 679 |
| 669 sandbox::ResultCode result; | 680 sandbox::ResultCode result; |
| 670 PROCESS_INFORMATION target = {0}; | 681 PROCESS_INFORMATION target = {0}; |
| 671 sandbox::TargetPolicy* policy = g_broker_services->CreatePolicy(); | 682 sandbox::TargetPolicy* policy = g_broker_services->CreatePolicy(); |
| 672 | 683 |
| 673 bool on_sandbox_desktop = false; | |
| 674 if (type == ChildProcessInfo::PLUGIN_PROCESS) { | 684 if (type == ChildProcessInfo::PLUGIN_PROCESS) { |
| 675 if (!AddPolicyForPlugin(cmd_line, policy)) | 685 if (!AddPolicyForPlugin(cmd_line, policy)) |
| 676 return 0; | 686 return 0; |
| 677 } else if (type == ChildProcessInfo::GPU_PROCESS) { | 687 } else if (type == ChildProcessInfo::GPU_PROCESS) { |
| 678 if (!AddPolicyForGPU(cmd_line, policy)) | 688 if (!AddPolicyForGPU(cmd_line, policy)) |
| 679 return 0; | 689 return 0; |
| 690 } else if (type == ChildProcessInfo::PPAPI_PLUGIN_PROCESS) { |
| 691 if (!AddPolicyForPepperPlugin(policy)) |
| 692 return 0; |
| 680 } else { | 693 } else { |
| 681 AddPolicyForRenderer(policy, &on_sandbox_desktop); | 694 AddPolicyForRenderer(policy); |
| 682 | 695 |
| 683 if (type_str != switches::kRendererProcess) { | 696 if (type_str != switches::kRendererProcess) { |
| 684 // Hack for Google Desktop crash. Trick GD into not injecting its DLL into | 697 // Hack for Google Desktop crash. Trick GD into not injecting its DLL into |
| 685 // this subprocess. See | 698 // this subprocess. See |
| 686 // http://code.google.com/p/chromium/issues/detail?id=25580 | 699 // http://code.google.com/p/chromium/issues/detail?id=25580 |
| 687 cmd_line->AppendSwitchASCII("ignored", " --type=renderer "); | 700 cmd_line->AppendSwitchASCII("ignored", " --type=renderer "); |
| 688 } | 701 } |
| 689 } | 702 } |
| 690 | 703 |
| 691 if (!exposed_dir.empty()) { | 704 if (!exposed_dir.empty()) { |
| (...skipping 35 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 727 | 740 |
| 728 // Help the process a little. It can't start the debugger by itself if | 741 // Help the process a little. It can't start the debugger by itself if |
| 729 // the process is in a sandbox. | 742 // the process is in a sandbox. |
| 730 if (child_needs_help) | 743 if (child_needs_help) |
| 731 base::debug::SpawnDebuggerOnProcess(target.dwProcessId); | 744 base::debug::SpawnDebuggerOnProcess(target.dwProcessId); |
| 732 | 745 |
| 733 return process; | 746 return process; |
| 734 } | 747 } |
| 735 | 748 |
| 736 } // namespace sandbox | 749 } // namespace sandbox |
| OLD | NEW |