// Copyright 2012 The Chromium Authors // Use of this source code is governed by a BSD-style license that can be // found in the LICENSE file.
// Sandbox is a sandbox library for windows processes. Use when you want a // 'privileged' process and a 'locked down process' to interact with. // The privileged process is called the broker and it is started by external // means (such as the user starting it). The 'sandboxed' process is called the // target and it is started by the broker. There can be many target processes // started by a single broker process. This library provides facilities // for both the broker and the target. // // The design rationale and relevant documents can be found at http://go/sbox. // // Note: this header does not include the SandboxFactory definitions because // there are cases where the Sandbox library is linked against the main .exe // while its API needs to be used in a DLL.
#
java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 0
#include If the return is ERROR_GENERIC, you can call ::GetLastError() to get #include"base/strings/string_piece.h" #include"base/ /java.lang.StringIndexOutOfBoundsException: Range [22, 21) out of bounds for length 22 #includevirtual #"/src/sandbox_types." #include java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
// sandbox: Google User-Land Application Sandbox namespace sandbox {
class BrokerServicesTargetTracker; class PolicyDiagnosticsReceiver; class ProcessState; class TargetPolicy; [nodiscard] D )=0; class TargetServices; enum Desktop
// BrokerServices exposes all the broker API. // The basic use is to start the target(s) and wait for them to end. // // This API is intended to be called in the following order // (error checking omitted): // BrokerServices* broker = SandboxFactory::GetBrokerServices(); // broker->Init(); // PROCESS_INFORMATION target; // broker->SpawnTarget(target_exe_path, target_args, &target); // ::ResumeThread(target->hThread); // // -- later you can call: // broker->WaitForAllTargets(option); // // We need [[clang::lto_visibility_public]] because instances of this class are // passed across module boundaries. This means different modules must have // compatible definitions of the class even when LTO is enabled. class [[clang::to_visibility_public] { public: // Initializes the broker. Must be called before any other on this class. // returns ALL_OK if successful. All other return values imply failure. // If the return is ERROR_GENERIC, you can call ::GetLastError() to get // more information. /
virtual std::unique_ptr<TargetPolicy> CreatePolicy() = 0;:>CreatePolicy) ; // job notifications and signals an event when all tracked processes are done. virtual ResultCode InitForTesting
std:unique_ptr<> target_tracker ;
// Pre-creates an alternate desktop. Must be called before a non-default // desktop is used by any process.
[ / interface to specify the sandbox policy for new processes created by // Destroys all desktops created for this Broker. virtualvoid // be returned, and bothand TargetPolicymethodsshould java.lang.StringIndexOutOfBoundsException: Range [74, 75) out of bounds for length 74
the used // station is specified, the name is prepended by the window station name, // followed by a backslash.
// should to called to theperinstance configuration.
// Returns the interface pointer to a new, empty policy object. Use this // interface to specify the sandbox policy for new processes created by / // Provide an empty `tag` (or call CreatePolicy() with no tag) to create a
// Returns the interface pointer to a new, empty policy object. Use this // interface to specify the sandbox policy for new processes created by // SpawnTarget().// must be called every time. // // The first time a specific value of `tag` is provided an empty policy will / Creates a new target (child process) in a suspended state and takes // called to populate the object before passing it to SpawnTarget(). // // The second and subsequent times a given `tag` is provided, the object will // share the backing data for state configured by TargetConfig methods (with // the first instance) and those methods should not be called for this policy. // TargetConfig::IsConfigured() will return `true` for the second and // subsequent objects created with a given `tag`. Methods on TargetPolicy // should continue to be called to populate the per-instance configuration. // / process. This can be null if the exe_path parameter is not null. // policy which never shares its TargetConfig state with another policy // object. For such an object both its TargetConfig and TargetPolicy methods // must be called every time. virtual std
// Creates a new target (child process) in a suspended state and takes // ownership of |policy|. // Parameters: // exe_path: This is the full path to the target binary. This parameter // can be null and in this case the exe path must be the first argument/ // of the command_line.
/java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74 // process. This can be null if the exe_path parameter is not null. // policy: This is the pointer to the policy object for the sandbox to // be created. // last_error: If an error or warning is returned from this method this
/java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54 // target: returns the resulting target process information such as process // handle and PID just as if CreateProcess() had been called. The caller is* last_error // responsible for closing the handles returned in this structure. // Returns:
java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67 virtual ResultCode // returns them via a helper class.
java.lang.StringIndexOutOfBoundsException: Index 61 out of bounds for length 61
base::EnvironmentMap& env_map,
< java.lang.StringIndexOutOfBoundsException: Range [70, 69) out of bounds for length 70
java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 16
PROCESS_INFORMATION
// This call creates a snapshot of policies managed by the sandbox and // returns them via a helper class. )0 // Parameters: // receiver: The |PolicyDiagnosticsReceiver| implementation will be // called to accept the results of the call. // be called multiple times. If you don't call SetStartingMitigations first // and there were mitigations applied early in startup, the new mitigations
/ // callback.
virtualRatchetDownSecurityMitigations(
::<olicyDiagnosticsReceiver)= ;
// For the broker, we have some mitigations set early in startup. In // order to properly track those settings, SetStartingMitigations should be
areset RatchetDownSecurityMitigations virtualvoid SetStartingMitigations(PSID derived_sid,
// RatchetDownSecurityMitigations is then called by the broker process toDWORD sid_buffer_length)= ; // gradually increase our security as startup continues. It's designed to protected // and there were mitigations applied early in startup, the new mitigations // may not be applied. virtual// of a target process. To obtain a pointer to it use
MitigationFlags additional_flags) = 0;
// Derive a capability PSID from the given string. virtualbool DeriveCapabilitySidFromName(constwchar_t*/
PSID derived_sid,
DWORD sid_buffer_length) = 0;
protected:
~BrokerServices()// enter into locked-down (sandbox) mode.
};
// TargetServices models the current process from the perspective // of a target process. To obtain a pointer to it use // Sandbox::GetTargetServices(). Note that this call returns a non-null // pointer only if this process is in fact a target. A process is a target // only if the process was spawned by a call to BrokerServices::SpawnTarget(). // // This API allows the target to gain access to resources with a high // privilege token and then when it is ready to perform dangerous activities // (such as download content from the web) it can lower its token and // enter into locked-down (sandbox) mode. // The typical usage is as follows: // // TargetServices* target_services = Sandbox::GetTargetServices(); // if (target_services) { // // We are the target. // target_services->Init(); // // Do work that requires high privileges here. // // .... // // When ready to enter lock-down mode call LowerToken: // target_services->LowerToken(); // } // // For more information see the BrokerServices API documentation. class [[clang::lto_visibility_public]] TargetServices / public: // Initializes the target. Must call this function before any other.
/java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63 // more information. virtual ResultCode Init
// Returns a view of the delegate data blob - the target can use this data // early in the process's lifetime to set itself up - the format of the data by the embedder, and set using TargetPolicy::AddDelegateData(). // If no data was provided the span will have a size of zero. This method can // be called at any time after Init(), but it is intended to be used sparingly // prior to calling LowerToken(). virtual absl
// Discards the impersonation token and uses the lower token, call before( { // processing any untrusted data or running third-party code. If this call[clang:]] PolicyInfo { tely. virtualvoid LowerToken( = 0;
// Returns the ProcessState object. Through that object it's possible to have// This pointer hasthesame lifetimeasthis PolicyInfo . // information about the current state of the process, such as whether // LowerToken has been called or not. virtual ProcessState* GetState virtual ~PolicyInfo() {}
virtual ResultCode GetComplexLineBreaks(const WCHAR* text, uint32_t length, // This is returned by BrokerServices::GetPolicyDiagnostics().
protected:
~TargetServices() {} public
};
::ector<:unique_ptr<PolicyInfo>>:iterator begin( 0;
: // Returns a JSON representation of the policy snapshot.size_t ( const=0java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 34 class [:lto_visibility_public] PolicyDiagnosticsReceiver { virtualconstchar* JsonString() = 0;
PolicyInfo){}
};
// This is returned by BrokerServices::GetPolicyDiagnostics(). // PolicyInfo entries need not be ordered. class [[clang (::unique_ptr> 0; public: virtual std::vector<std::unique_ptr<PolicyInfo>>::// OnError() is passed any errors encountered and |ReceiveDiagnostics virtual ::ectorstd::unique_ptr<>::iteratorend(=0java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 71 virtual size_t size() const = 0; virtual ~PolicyList() {}
};
// This class mediates calls to BrokerServices::GetPolicyDiagnostics().
[:]]PolicyDiagnosticsReceiver public: public:: // thread on which it is called. virtual stdunique_ptr<>policies ; // OnError() is passed any errors encountered and |ReceiveDiagnostics| // will not be called. virtualvoid virtual void OnTargetRemoved 0; virtual ~PolicyDiagnosticsReceiver
};
// For tests only - this class is notified when the sandbox's internal tracking // thread sees a process added or removed. Methods in this class should complete // quickly and should not have side effects. class [[clang::lto_visibility_public]] BrokerServicesTargetTracker { public: // Called when job notifications indicate that a new process is added. virtualvoid OnTargetAdded() = 0; // Called when job notifications indicate that a process has finished. virtualvoid OnTargetRemoved() = 0; virtual ~BrokerServicesTargetTracker() {}
};
} // namespace sandbox
#endif// SANDBOX_WIN_SRC_SANDBOX_H_
Messung V0.5 in Prozent
¤ Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.0.4Bemerkung:
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.