OLD | NEW |
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include "base/stringprintf.h" | 5 #include "base/stringprintf.h" |
6 #include "sandbox/src/handle_policy.h" | 6 #include "sandbox/src/handle_policy.h" |
7 #include "sandbox/src/nt_internals.h" | 7 #include "sandbox/src/nt_internals.h" |
8 #include "sandbox/src/sandbox.h" | 8 #include "sandbox/src/sandbox.h" |
9 #include "sandbox/src/sandbox_factory.h" | 9 #include "sandbox/src/sandbox_factory.h" |
10 #include "sandbox/src/sandbox_policy.h" | 10 #include "sandbox/src/sandbox_policy.h" |
(...skipping 47 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
58 target.process_id()); | 58 target.process_id()); |
59 EXPECT_EQ(SBOX_TEST_DENIED, runner.RunTest(cmd_line.c_str())); | 59 EXPECT_EQ(SBOX_TEST_DENIED, runner.RunTest(cmd_line.c_str())); |
60 | 60 |
61 // Now successfully open the event after adding a duplicate handle rule. | 61 // Now successfully open the event after adding a duplicate handle rule. |
62 EXPECT_TRUE(runner.AddRule(TargetPolicy::SUBSYS_HANDLES, | 62 EXPECT_TRUE(runner.AddRule(TargetPolicy::SUBSYS_HANDLES, |
63 TargetPolicy::HANDLES_DUP_ANY, | 63 TargetPolicy::HANDLES_DUP_ANY, |
64 L"Event")); | 64 L"Event")); |
65 EXPECT_EQ(SBOX_TEST_SUCCEEDED, runner.RunTest(cmd_line.c_str())); | 65 EXPECT_EQ(SBOX_TEST_SUCCEEDED, runner.RunTest(cmd_line.c_str())); |
66 } | 66 } |
67 | 67 |
| 68 // Tests that duplicating an object works only when the policy allows it. |
| 69 TEST(HandlePolicyTest, DuplicatePeerHandle) { |
| 70 TestRunner target; |
| 71 TestRunner runner; |
| 72 |
| 73 // Kick off an asynchronous target process for testing. |
| 74 target.SetAsynchronous(true); |
| 75 target.SetUnsandboxed(true); |
| 76 EXPECT_EQ(SBOX_TEST_SUCCEEDED, target.RunTest(L"Handle_WaitProcess 30000")); |
| 77 |
| 78 // First test that we fail to open the event. |
| 79 std::wstring cmd_line = base::StringPrintf(L"Handle_DuplicateEvent %d", |
| 80 target.process_id()); |
| 81 EXPECT_EQ(SBOX_TEST_DENIED, runner.RunTest(cmd_line.c_str())); |
| 82 |
| 83 // Now successfully open the event after adding a duplicate handle rule. |
| 84 EXPECT_TRUE(runner.AddRule(TargetPolicy::SUBSYS_HANDLES, |
| 85 TargetPolicy::HANDLES_DUP_ANY, |
| 86 L"Event")); |
| 87 EXPECT_EQ(SBOX_TEST_SUCCEEDED, runner.RunTest(cmd_line.c_str())); |
| 88 } |
| 89 |
68 } // namespace sandbox | 90 } // namespace sandbox |
69 | 91 |
OLD | NEW |