Chromium Code Reviews| OLD | NEW |
|---|---|
| 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #include "sandbox/win/src/handle_dispatcher.h" | 5 #include "sandbox/win/src/handle_dispatcher.h" |
| 6 | 6 |
| 7 #include "base/win/scoped_handle.h" | 7 #include "base/win/scoped_handle.h" |
| 8 #include "sandbox/win/src/handle_interception.h" | 8 #include "sandbox/win/src/handle_interception.h" |
| 9 #include "sandbox/win/src/handle_policy.h" | 9 #include "sandbox/win/src/handle_policy.h" |
| 10 #include "sandbox/win/src/ipc_tags.h" | 10 #include "sandbox/win/src/ipc_tags.h" |
| (...skipping 26 matching lines...) Expand all Loading... | |
| 37 } | 37 } |
| 38 | 38 |
| 39 return false; | 39 return false; |
| 40 } | 40 } |
| 41 | 41 |
| 42 bool HandleDispatcher::DuplicateHandleProxy(IPCInfo* ipc, | 42 bool HandleDispatcher::DuplicateHandleProxy(IPCInfo* ipc, |
| 43 HANDLE source_handle, | 43 HANDLE source_handle, |
| 44 DWORD target_process_id, | 44 DWORD target_process_id, |
| 45 DWORD desired_access, | 45 DWORD desired_access, |
| 46 DWORD options) { | 46 DWORD options) { |
| 47 NTSTATUS error; | |
| 48 static NtQueryObject QueryObject = NULL; | 47 static NtQueryObject QueryObject = NULL; |
| 49 if (!QueryObject) | 48 if (!QueryObject) |
| 50 ResolveNTFunctionPtr("NtQueryObject", &QueryObject); | 49 ResolveNTFunctionPtr("NtQueryObject", &QueryObject); |
| 51 | 50 |
| 52 // Get a copy of the handle for use in the broker process. | 51 // Get a copy of the handle for use in the broker process. |
| 53 HANDLE handle_temp; | 52 HANDLE handle_temp; |
| 54 if (!::DuplicateHandle(ipc->client_info->process, source_handle, | 53 if (!::DuplicateHandle(ipc->client_info->process, source_handle, |
| 55 ::GetCurrentProcess(), &handle_temp, | 54 ::GetCurrentProcess(), &handle_temp, |
| 56 0, FALSE, DUPLICATE_SAME_ACCESS | options)) { | 55 0, FALSE, DUPLICATE_SAME_ACCESS | options)) { |
| 57 ipc->return_info.win32_result = ::GetLastError(); | 56 ipc->return_info.win32_result = ::GetLastError(); |
| 58 return false; | 57 return false; |
| 59 } | 58 } |
| 60 options &= ~DUPLICATE_CLOSE_SOURCE; | 59 options &= ~DUPLICATE_CLOSE_SOURCE; |
| 61 base::win::ScopedHandle handle(handle_temp); | 60 base::win::ScopedHandle handle(handle_temp); |
| 62 | 61 |
| 63 // Get the object type (32 characters is safe; current max is 14). | 62 // Get the object type (32 characters is safe; current max is 14). |
| 64 BYTE buffer[sizeof(OBJECT_TYPE_INFORMATION) + 32 * sizeof(wchar_t)]; | 63 BYTE buffer[sizeof(OBJECT_TYPE_INFORMATION) + 32 * sizeof(wchar_t)]; |
| 65 OBJECT_TYPE_INFORMATION* type_info = | 64 OBJECT_TYPE_INFORMATION* type_info = |
| 66 reinterpret_cast<OBJECT_TYPE_INFORMATION*>(buffer); | 65 reinterpret_cast<OBJECT_TYPE_INFORMATION*>(buffer); |
| 67 ULONG size = sizeof(buffer) - sizeof(wchar_t); | 66 ULONG size = sizeof(buffer) - sizeof(wchar_t); |
| 68 error = QueryObject(handle, ObjectTypeInformation, type_info, size, &size); | 67 NTSTATUS error = |
| 68 QueryObject(handle, ObjectTypeInformation, type_info, size, &size); | |
| 69 if (!NT_SUCCESS(error)) { | 69 if (!NT_SUCCESS(error)) { |
| 70 ipc->return_info.win32_result = error; | 70 ipc->return_info.nt_status = error; |
|
Peter Kasting
2014/07/09 18:55:18
Note that because win32_result and nt_status are i
cpu_(ooo_6.6-7.5)
2014/07/10 00:49:34
yeah that reads like it was a bug, but it can beco
Peter Kasting
2014/07/10 01:19:31
I don't know if I understand this comment.
As far
| |
| 71 return false; | 71 return false; |
| 72 } | 72 } |
| 73 type_info->Name.Buffer[type_info->Name.Length / sizeof(wchar_t)] = L'\0'; | 73 type_info->Name.Buffer[type_info->Name.Length / sizeof(wchar_t)] = L'\0'; |
| 74 | 74 |
| 75 CountedParameterSet<HandleTarget> params; | 75 CountedParameterSet<HandleTarget> params; |
| 76 params[HandleTarget::NAME] = ParamPickerMake(type_info->Name.Buffer); | 76 params[HandleTarget::NAME] = ParamPickerMake(type_info->Name.Buffer); |
| 77 params[HandleTarget::TARGET] = ParamPickerMake(target_process_id); | 77 params[HandleTarget::TARGET] = ParamPickerMake(target_process_id); |
| 78 | 78 |
| 79 EvalResult eval = policy_base_->EvalPolicy(IPC_DUPLICATEHANDLEPROXY_TAG, | 79 EvalResult eval = policy_base_->EvalPolicy(IPC_DUPLICATEHANDLEPROXY_TAG, |
| 80 params.GetBase()); | 80 params.GetBase()); |
| 81 ipc->return_info.win32_result = | 81 ipc->return_info.win32_result = |
| 82 HandlePolicy::DuplicateHandleProxyAction(eval, handle, | 82 HandlePolicy::DuplicateHandleProxyAction(eval, handle, |
| 83 target_process_id, | 83 target_process_id, |
| 84 &ipc->return_info.handle, | 84 &ipc->return_info.handle, |
| 85 desired_access, options); | 85 desired_access, options); |
| 86 return true; | 86 return true; |
| 87 } | 87 } |
| 88 | 88 |
| 89 } // namespace sandbox | 89 } // namespace sandbox |
| 90 | 90 |
| OLD | NEW |