OLD | NEW |
---|---|
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include "base/stringprintf.h" | 5 #include "base/stringprintf.h" |
6 #include "sandbox/src/handle_policy.h" | 6 #include "sandbox/src/handle_policy.h" |
7 #include "sandbox/src/nt_internals.h" | 7 #include "sandbox/src/nt_internals.h" |
8 #include "sandbox/src/sandbox.h" | 8 #include "sandbox/src/sandbox.h" |
9 #include "sandbox/src/sandbox_factory.h" | 9 #include "sandbox/src/sandbox_factory.h" |
10 #include "sandbox/src/sandbox_policy.h" | 10 #include "sandbox/src/sandbox_policy.h" |
(...skipping 69 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... | |
80 target.process_id()); | 80 target.process_id()); |
81 EXPECT_EQ(SBOX_TEST_DENIED, runner.RunTest(cmd_line.c_str())); | 81 EXPECT_EQ(SBOX_TEST_DENIED, runner.RunTest(cmd_line.c_str())); |
82 | 82 |
83 // Now successfully open the event after adding a duplicate handle rule. | 83 // Now successfully open the event after adding a duplicate handle rule. |
84 EXPECT_TRUE(runner.AddRule(TargetPolicy::SUBSYS_HANDLES, | 84 EXPECT_TRUE(runner.AddRule(TargetPolicy::SUBSYS_HANDLES, |
85 TargetPolicy::HANDLES_DUP_ANY, | 85 TargetPolicy::HANDLES_DUP_ANY, |
86 L"Event")); | 86 L"Event")); |
87 EXPECT_EQ(SBOX_TEST_SUCCEEDED, runner.RunTest(cmd_line.c_str())); | 87 EXPECT_EQ(SBOX_TEST_SUCCEEDED, runner.RunTest(cmd_line.c_str())); |
88 } | 88 } |
89 | 89 |
90 // Tests that duplicating an object works only when the policy allows it. | |
91 TEST(HandlePolicyTest, DuplicateBrokerHandle) { | |
92 TestRunner target; | |
rvargas (doing something else)
2012/05/18 21:02:52
No need for a target
jschuh
2012/05/18 21:40:53
Done.
| |
93 TestRunner runner; | |
94 | |
95 // First test that we fail to open the event. | |
96 std::wstring cmd_line = base::StringPrintf(L"Handle_DuplicateEvent %d", | |
97 ::GetCurrentProcessId()); | |
98 EXPECT_EQ(SBOX_TEST_DENIED, runner.RunTest(cmd_line.c_str())); | |
99 | |
100 // Add the peer rule and make sure we fail again. | |
101 EXPECT_TRUE(runner.AddRule(TargetPolicy::SUBSYS_HANDLES, | |
102 TargetPolicy::HANDLES_DUP_ANY, | |
103 L"Event")); | |
104 EXPECT_EQ(SBOX_TEST_DENIED, runner.RunTest(cmd_line.c_str())); | |
105 | |
106 | |
107 // Now successfully open the event after adding a broker handle rule. | |
108 EXPECT_TRUE(runner.AddRule(TargetPolicy::SUBSYS_HANDLES, | |
109 TargetPolicy::HANDLES_DUP_BROKER, | |
110 L"Event")); | |
111 EXPECT_EQ(SBOX_TEST_SUCCEEDED, runner.RunTest(cmd_line.c_str())); | |
112 } | |
113 | |
90 } // namespace sandbox | 114 } // namespace sandbox |
91 | 115 |
OLD | NEW |