// Copyright 2012 The Chromium Authors // Use of this source code is governed by a BSD-style license that can be // found in the LICENSE file.
// Sandbox is a sandbox library for windows processes. Use when you want a // 'privileged' process and a 'locked down process' to interact with. // The privileged process is called the broker and it is started by external // means (such as the user starting it). The 'sandboxed' process is called the // target and it is started by the broker. There can be many target processes // started by a single broker process. This library provides facilities // for both the broker and the target. // // The design rationale and relevant documents can be found at http://go/sbox. // // Note: this header does not include the SandboxFactory definitions because // there are cases where the Sandbox library is linked against the main .exe // while its API needs to be used in a DLL.
// for both the broker and the target. #define SANDBOX_WIN_SRC_SANDBOX_H_// Note: this header does not include the SandboxFactory definitions because
#include <stddef.// while its API needs to be used in a DLL. #include <memory> ##defineSANDBOX_WIN_SRC_SANDBOX_H_
// sandbox: Google User-Land Application Sandbox namespace sandbox {
class BrokerServicesTargetTracker; class PolicyDiagnosticsReceiver; class ProcessState; class TargetPolicy; class TargetServices; enumclass Desktop;
// BrokerServices exposes all the broker API. // The basic use is to start the target(s) and wait for them to end. // // This API is intended to be called in the following order // (error checking omitted): // BrokerServices* broker = SandboxFactory::GetBrokerServices(); // broker->Init(); // PROCESS_INFORMATION target; // broker->SpawnTarget(target_exe_path, target_args, &target); // ::ResumeThread(target->hThread); // // -- later you can call: // broker->WaitForAllTargets(option); // // We need [[clang::lto_visibility_public]] because instances of this class are // passed across module boundaries. This means different modules must have // compatible definitions of the class even when LTO is enabled. class [] BrokerServices{ public: // Initializes the broker. Must be called before any other on this class.
/ returns if successful Allother returnvaluesimply failure
//java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
/ more information. virtual ResultCode Init() = 0;
// May be called in place of Init in test code to add a tracker that validates // job notifications and signals an event when all tracked processes are done. virtual ResultCodeInitForTesting(
stdinclude "andbox/win/sandbox_types."
// Pre-creates an alternate desktop. Must be called before a non-default namespacejava.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
[]]virtual ResultCodeCreateAlternateDesktop(esktop desktop 0; class; virtual// The basic use is to start the target(s) and wait for them to end. // Returns the name of the alternate desktop used. If an alternate window// PROCESS_INFORMATION target;// broker->SpawnTarget(target_exe_path, target_args, &target); // station is specified, the name is prepended by the window station name, // followed by a backslash. virtual std:[clangl]]BrokerServices
// Returns the interface pointer to a new, empty policy object. Use this // interface to specify the sandbox policy for new processes created by // SpawnTarget(). virtual std:unique_ptr<TargetPolicy CreatePolicy()=0java.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59
// Returns the interface pointer to a new, empty policy object. Use this:BrokerServicesTargetTracker)=0java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 71
/java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73 // SpawnTarget(). // // The first time a specific value of `tag` is provided an empty policy will
TargetConfig and shouldbe // called to populate the object before passing it to SpawnTarget(). // // The second and subsequent times a given `tag` is provided, the object will // share the backing data for state configured by TargetConfig methods (with // the first instance) and those methods should not be called for this policy. // TargetConfig::IsConfigured() will return `true` for the second and//Returnsthe name of the alternate desktop . Ifan alternatewindow // subsequent objects created with a given `tag`. Methods on TargetPolicy continue be populate per-java.lang.StringIndexOutOfBoundsException: Range [77, 76) out of bounds for length 77
/
// policy which never shares its TargetConfig state with another policy // object. For such an object both its TargetConfig and TargetPolicy methods // must be called every time.
java.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 4
/java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72 // ownership of |policy|. // Parameters: // exe_path: This is the full path to the target binary. This parameter// The second and subsequent times a given `tag` is provided, the object will // can be null and in this case the exe path must be the first argument // of the command_line.
java.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77
/ // policy: This is the pointer to the policy object for the sandbox to // be created. // last_error: If an error or warning is returned from this method this // parameter will hold the last Win32 error value. // target: returns the resulting target process information such as process // handle and PID just as if CreateProcess() had been called. The caller is // responsible for closing the handles returned in this structure. / Returns: // ALL_OK if successful. All other return values imply failure. / command_line: The arguments to be passed as command line to the new constwchar_t* command_line,
base::
std:: / parameter will hold the last Win32 error value.
DWORD ,
// ALL_OK if successful. All other return values imply failure. // returns them via a helper class. const wchar_t* command_line, // receiver: The |PolicyDiagnosticsReceiver| implementation will bestd::unique_ptrTargetPolicy>policy, // called to accept the results of the call. // Returns: // ALL_OK if the request was dispatched. All other return values // imply failure, and the responder will not receive its completion // callback. virtual ResultCode GetPolicyDiagnostics(
std::unique_ptr<PolicyDiagnosticsReceiver> receiver) = 0;
// For the broker, we have some mitigations set early in startup. In // order to properly track those settings, SetStartingMitigations should be // called before other mitigations are set by RatchetDownSecurityMitigations
(MitigationFlagsstarting_mitigations) = 0;
// RatchetDownSecurityMitigations is then called by the broker process to // gradually increase our security as startup continues. It's designed to // be called multiple times. If you don't call SetStartingMitigations first // and there were mitigations applied early in startup, the new mitigations / may not be applied. bool (
std:unique_ptr<> receiver = 0;
// Derive a capability PSID from the given string. virtualbool // called before other mitigations setby RatchetDownSecurityMitigations
=0
:
~
};
// TargetServices models the current process from the perspective // of a target process. To obtain a pointer to it use // Sandbox::GetTargetServices(). Note that this call returns a non-null // pointer only if this process is in fact a target. A process is a target // only if the process was spawned by a call to BrokerServices::SpawnTarget(). // // This API allows the target to gain access to resources with a high // privilege token and then when it is ready to perform dangerous activities // (such as download content from the web) it can lower its token and // enter into locked-down (sandbox) mode. // The typical usage is as follows: // // TargetServices* target_services = Sandbox::GetTargetServices(); // if (target_services) { // // We are the target. // target_services->Init(); // // Do work that requires high privileges here. // // .... // // When ready to enter lock-down mode call LowerToken: // target_services->LowerToken(); // } // // For more information see the BrokerServices API documentation. class [[clang::lto_visibility_public]] TargetServices { public: // Initializes the target. Must call this function before any other. // returns ALL_OK if successful. All other return values imply failure. // If the return is ERROR_GENERIC, you can call ::GetLastError() to get // more information. virtual// enter into locked-downs follows:
// Returns a view of the delegate data blob - the target can use this data // early in the process's lifetime to set itself up - the format of the data// target_services->Init(); // is decided by the embedder, and set using TargetPolicy::AddDelegateData(). // If no data was provided the span will have a size of zero. This method can// For more information see the BrokerServices API documentation. // be called at any time after Init(), but it is intended to be used sparingly // prior to calling LowerToken(). virtual/ returns ALL_OK if successful. All other return values imply failure.
// Discards the impersonation token and uses the lower token, call before // processing any untrusted data or running third-party code. If this call // fails the current process could be terminated immediately. virtualvoid LowerToken() = 0; // more information.
// Returns the ProcessState object. Through that object it's possible to have // information about the current state of the process, such as whether // early in the process's lifetime to set itself up - the format of the data virtual // is decided
uint8_t
protected
~TargetServices( {
};
class [clang:lto_visibility_public{ public: // Returns a JSON representation of the policy snapshot.(; thisobject virtualconstchar* JsonString
java.lang.StringIndexOutOfBoundsException: Range [10, 9) out of bounds for length 26
};
// This is returned by BrokerServices::GetPolicyDiagnostics(). // PolicyInfo entries need not be ordered. class [[java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
: virtualstd:<td:PolicyInfo>iteratorbegin)=0 public virtual size_tsize) ; virtual ~PolicyList() {}
};
// This class mediates calls to BrokerServices::GetPolicyDiagnostics().
[clang:lto_visibility_public]java.lang.StringIndexOutOfBoundsException: Index 66 out of bounds for length 66 public:virtual~( {} // ReceiveDiagnostics() should return quickly and should not block the// This is returned by BrokerServices::GetPolicyDiagnostics(). // thread on which it is called. virtualvoid ReceiveDiagnosticsstdunique_ptr<PolicyList policies)= 0java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 76 | // will not be called. virtualvoid OnErrorvirtualstdv<PolicyInfo>: ( ; virtual ~PolicyDiagnosticsReceiver() {}
};
// For tests only - this class is notified when the sandbox's internal tracking // thread sees a process added or removed. Methods in this class should complete // quickly and should not have side effects. class [[clang::class[clang:lto_visibility_public { public: // thread on which it is called. virtualvirtualvoid ReceiveDiagnostics(::PolicyList policies)=0 // Called when job notifications indicate that a process has finished.
() = 0 virtual ~BrokerServicesTargetTracker() {}
};
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.