| OLD | NEW |
| 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #ifndef CONTENT_COMMON_SANDBOX_MAC_H_ | 5 #ifndef CONTENT_COMMON_SANDBOX_MAC_H_ |
| 6 #define CONTENT_COMMON_SANDBOX_MAC_H_ | 6 #define CONTENT_COMMON_SANDBOX_MAC_H_ |
| 7 | 7 |
| 8 #include <map> | |
| 9 #include <string> | 8 #include <string> |
| 10 | 9 |
| 11 #include "base/basictypes.h" | 10 #include "base/basictypes.h" |
| 12 #include "base/containers/hash_tables.h" | 11 #include "base/containers/hash_tables.h" |
| 13 #include "base/gtest_prod_util.h" | 12 #include "base/gtest_prod_util.h" |
| 14 #include "content/common/content_export.h" | 13 #include "content/common/content_export.h" |
| 15 #include "content/public/common/sandbox_type.h" | 14 #include "content/public/common/sandbox_type.h" |
| 16 | 15 |
| 17 namespace base { | 16 namespace base { |
| 18 class FilePath; | 17 class FilePath; |
| 19 } | 18 } |
| 20 | 19 |
| 21 #if __OBJC__ | 20 #if __OBJC__ |
| 22 @class NSArray; | 21 @class NSArray; |
| 23 @class NSString; | 22 @class NSString; |
| 24 #else | 23 #else |
| 25 class NSArray; | 24 class NSArray; |
| 26 class NSString; | 25 class NSString; |
| 27 #endif | 26 #endif |
| 28 | 27 |
| 29 namespace content { | 28 namespace content { |
| 30 | 29 |
| 31 // This class wraps the C-style sandbox APIs in a class to ensure proper | 30 // Class representing a substring of the sandbox profile tagged with its type. |
| 32 // initialization and cleanup. | 31 class SandboxSubstring { |
| 33 class CONTENT_EXPORT SandboxCompiler { | |
| 34 public: | 32 public: |
| 35 explicit SandboxCompiler(const std::string& profile_str); | 33 enum SandboxSubstringType { |
| 34 PLAIN, // Just a plain string, no escaping necessary. |
| 35 LITERAL, // Escape for use in (literal ...) expression. |
| 36 REGEX, // Escape for use in (regex ...) expression. |
| 37 }; |
| 36 | 38 |
| 37 ~SandboxCompiler(); | 39 SandboxSubstring() {} |
| 38 | 40 |
| 39 // Inserts a boolean into the parameters key/value map. A duplicate key is not | 41 explicit SandboxSubstring(const std::string& value) |
| 40 // allowed, and will cause the function to return false. The value is not | 42 : value_(value), |
| 41 // inserted in this case. | 43 type_(PLAIN) {} |
| 42 bool InsertBooleanParam(const std::string& key, bool value); | |
| 43 | 44 |
| 44 // Inserts a string into the parameters key/value map. A duplicate key is not | 45 SandboxSubstring(const std::string& value, SandboxSubstringType type) |
| 45 // allowed, and will cause the function to return false. The value is not | 46 : value_(value), |
| 46 // inserted in this case. | 47 type_(type) {} |
| 47 bool InsertStringParam(const std::string& key, const std::string& value); | |
| 48 | 48 |
| 49 // Compiles and applies the profile; returns true on success. | 49 const std::string& value() { return value_; } |
| 50 bool CompileAndApplyProfile(std::string* error); | 50 SandboxSubstringType type() { return type_; } |
| 51 | 51 |
| 52 private: | 52 private: |
| 53 // Frees all of the system resources allocated for the sandbox. | 53 std::string value_; |
| 54 void FreeSandboxResources(void* profile, void* params, char* error); | 54 SandboxSubstringType type_; |
| 55 | |
| 56 // Storage of the key/value pairs of strings that are used in the sandbox | |
| 57 // profile. | |
| 58 std::map<std::string, std::string> params_map_; | |
| 59 | |
| 60 // The sandbox profile source code. | |
| 61 const std::string profile_str_; | |
| 62 | |
| 63 DISALLOW_COPY_AND_ASSIGN(SandboxCompiler); | |
| 64 }; | 55 }; |
| 65 | 56 |
| 66 class CONTENT_EXPORT Sandbox { | 57 class CONTENT_EXPORT Sandbox { |
| 67 public: | 58 public: |
| 59 // A map of variable name -> string to substitute in its place. |
| 60 typedef base::hash_map<std::string, SandboxSubstring> |
| 61 SandboxVariableSubstitions; |
| 68 | 62 |
| 69 // Warm up System APIs that empirically need to be accessed before the | 63 // Warm up System APIs that empirically need to be accessed before the |
| 70 // sandbox is turned on. |sandbox_type| is the type of sandbox to warm up. | 64 // sandbox is turned on. |sandbox_type| is the type of sandbox to warm up. |
| 71 // Valid |sandbox_type| values are defined by the enum SandboxType, or can be | 65 // Valid |sandbox_type| values are defined by the enum SandboxType, or can be |
| 72 // defined by the embedder via | 66 // defined by the embedder via |
| 73 // ContentClient::GetSandboxProfileForProcessType(). | 67 // ContentClient::GetSandboxProfileForProcessType(). |
| 74 static void SandboxWarmup(int sandbox_type); | 68 static void SandboxWarmup(int sandbox_type); |
| 75 | 69 |
| 76 // Turns on the OS X sandbox for this process. | 70 // Turns on the OS X sandbox for this process. |
| 77 // |sandbox_type| - type of Sandbox to use. See SandboxWarmup() for legal | 71 // |sandbox_type| - type of Sandbox to use. See SandboxWarmup() for legal |
| 78 // values. | 72 // values. |
| 79 // |allowed_dir| - directory to allow access to, currently the only sandbox | 73 // |allowed_dir| - directory to allow access to, currently the only sandbox |
| 80 // profile that supports this is SANDBOX_TYPE_UTILITY . | 74 // profile that supports this is SANDBOX_TYPE_UTILITY . |
| 81 // | 75 // |
| 82 // Returns true on success, false if an error occurred enabling the sandbox. | 76 // Returns true on success, false if an error occurred enabling the sandbox. |
| 83 static bool EnableSandbox(int sandbox_type, | 77 static bool EnableSandbox(int sandbox_type, |
| 84 const base::FilePath& allowed_dir); | 78 const base::FilePath& allowed_dir); |
| 85 | 79 |
| 86 // Returns true if the sandbox has been enabled for the current process. | 80 // Returns true if the sandbox has been enabled for the current process. |
| 87 static bool SandboxIsCurrentlyActive(); | 81 static bool SandboxIsCurrentlyActive(); |
| 88 | 82 |
| 83 // Exposed for testing purposes, used by an accessory function of our tests |
| 84 // so we can't use FRIEND_TEST. |
| 85 |
| 86 // Build the Sandbox command necessary to allow access to a named directory |
| 87 // indicated by |allowed_dir|. |
| 88 // Returns a string containing the sandbox profile commands necessary to allow |
| 89 // access to that directory or nil if an error occured. |
| 90 |
| 91 // The header comment for PostProcessSandboxProfile() explains how variable |
| 92 // substition works in sandbox templates. |
| 93 // The returned string contains embedded variables. The function fills in |
| 94 // |substitutions| to contain the values for these variables. |
| 95 static NSString* BuildAllowDirectoryAccessSandboxString( |
| 96 const base::FilePath& allowed_dir, |
| 97 SandboxVariableSubstitions* substitutions); |
| 98 |
| 99 // Assemble the final sandbox profile from a template by removing comments |
| 100 // and substituting variables. |
| 101 // |
| 102 // |sandbox_template| is a string which contains 2 entitites to operate on: |
| 103 // |
| 104 // - Comments - The sandbox comment syntax is used to make the OS sandbox |
| 105 // optionally ignore commands it doesn't support. e.g. |
| 106 // ;10.6_ONLY (foo) |
| 107 // Where (foo) is some command that is only supported on OS X 10.6. |
| 108 // The ;10.6_ONLY comment can then be removed from the template to enable |
| 109 // (foo) as appropriate. |
| 110 // |
| 111 // - Variables - denoted by @variable_name@ . These are defined in the |
| 112 // sandbox template in cases where another string needs to be substituted at |
| 113 // runtime. e.g. @HOMEDIR_AS_LITERAL@ is substituted at runtime for the user's |
| 114 // home directory escaped appropriately for a (literal ...) expression. |
| 115 // |
| 116 // |comments_to_remove| is a list of NSStrings containing the comments to |
| 117 // remove. |
| 118 // |substitutions| is a hash of "variable name" -> "string to substitute". |
| 119 // Where the replacement string is tagged with information on how it is to be |
| 120 // escaped e.g. used as part of a regex string or a literal. |
| 121 // |
| 122 // On output |final_sandbox_profile_str| contains the final sandbox profile. |
| 123 // Returns true on success, false otherwise. |
| 124 static bool PostProcessSandboxProfile( |
| 125 NSString* in_sandbox_data, |
| 126 NSArray* comments_to_remove, |
| 127 SandboxVariableSubstitions& substitutions, |
| 128 std::string *final_sandbox_profile_str); |
| 129 |
| 130 private: |
| 131 // Returns an (allow file-read-metadata) rule for |allowed_path| and all its |
| 132 // parent directories. |
| 133 static NSString* AllowMetadataForPath(const base::FilePath& allowed_path); |
| 134 |
| 89 // Escape |src_utf8| for use in a plain string variable in a sandbox | 135 // Escape |src_utf8| for use in a plain string variable in a sandbox |
| 90 // configuraton file. On return |dst| is set to the quoted output. | 136 // configuraton file. On return |dst| is set to the quoted output. |
| 91 // Returns: true on success, false otherwise. | 137 // Returns: true on success, false otherwise. |
| 92 static bool QuotePlainString(const std::string& src_utf8, std::string* dst); | 138 static bool QuotePlainString(const std::string& src_utf8, std::string* dst); |
| 93 | 139 |
| 94 // Escape |str_utf8| for use in a regex literal in a sandbox | 140 // Escape |str_utf8| for use in a regex literal in a sandbox |
| 95 // configuraton file. On return |dst| is set to the utf-8 encoded quoted | 141 // configuraton file. On return |dst| is set to the utf-8 encoded quoted |
| 96 // output. | 142 // output. |
| 97 // | 143 // |
| 98 // The implementation of this function is based on empirical testing of the | 144 // The implementation of this function is based on empirical testing of the |
| 99 // OS X sandbox on 10.5.8 & 10.6.2 which is undocumented and subject to | 145 // OS X sandbox on 10.5.8 & 10.6.2 which is undocumented and subject to |
| 100 // change. | 146 // change. |
| 101 // | 147 // |
| 102 // Note: If str_utf8 contains any characters < 32 || >125 then the function | 148 // Note: If str_utf8 contains any characters < 32 || >125 then the function |
| 103 // fails and false is returned. | 149 // fails and false is returned. |
| 104 // | 150 // |
| 105 // Returns: true on success, false otherwise. | 151 // Returns: true on success, false otherwise. |
| 106 static bool QuoteStringForRegex(const std::string& str_utf8, | 152 static bool QuoteStringForRegex(const std::string& str_utf8, |
| 107 std::string* dst); | 153 std::string* dst); |
| 108 | 154 |
| 109 private: | |
| 110 // Convert provided path into a "canonical" path matching what the Sandbox | 155 // Convert provided path into a "canonical" path matching what the Sandbox |
| 111 // expects i.e. one without symlinks. | 156 // expects i.e. one without symlinks. |
| 112 // This path is not necessarily unique e.g. in the face of hardlinks. | 157 // This path is not necessarily unique e.g. in the face of hardlinks. |
| 113 static base::FilePath GetCanonicalSandboxPath(const base::FilePath& path); | 158 static base::FilePath GetCanonicalSandboxPath(const base::FilePath& path); |
| 114 | 159 |
| 115 FRIEND_TEST_ALL_PREFIXES(MacDirAccessSandboxTest, StringEscape); | 160 FRIEND_TEST_ALL_PREFIXES(MacDirAccessSandboxTest, StringEscape); |
| 116 FRIEND_TEST_ALL_PREFIXES(MacDirAccessSandboxTest, RegexEscape); | 161 FRIEND_TEST_ALL_PREFIXES(MacDirAccessSandboxTest, RegexEscape); |
| 117 FRIEND_TEST_ALL_PREFIXES(MacDirAccessSandboxTest, SandboxAccess); | 162 FRIEND_TEST_ALL_PREFIXES(MacDirAccessSandboxTest, SandboxAccess); |
| 118 | 163 |
| 119 DISALLOW_IMPLICIT_CONSTRUCTORS(Sandbox); | 164 DISALLOW_IMPLICIT_CONSTRUCTORS(Sandbox); |
| 120 }; | 165 }; |
| 121 | 166 |
| 122 } // namespace content | 167 } // namespace content |
| 123 | 168 |
| 124 #endif // CONTENT_COMMON_SANDBOX_MAC_H_ | 169 #endif // CONTENT_COMMON_SANDBOX_MAC_H_ |
| OLD | NEW |