OLD | NEW |
1 // Copyright (c) 2011 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2011 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include "sandbox/src/process_thread_policy.h" | 5 #include "sandbox/win/src/process_thread_policy.h" |
6 | 6 |
7 #include <string> | 7 #include <string> |
8 | 8 |
9 #include "base/memory/scoped_ptr.h" | 9 #include "base/memory/scoped_ptr.h" |
10 #include "sandbox/src/ipc_tags.h" | 10 #include "sandbox/win/src/ipc_tags.h" |
11 #include "sandbox/src/nt_internals.h" | 11 #include "sandbox/win/src/nt_internals.h" |
12 #include "sandbox/src/policy_engine_opcodes.h" | 12 #include "sandbox/win/src/policy_engine_opcodes.h" |
13 #include "sandbox/src/policy_params.h" | 13 #include "sandbox/win/src/policy_params.h" |
14 #include "sandbox/src/sandbox_types.h" | 14 #include "sandbox/win/src/sandbox_types.h" |
15 #include "sandbox/src/win_utils.h" | 15 #include "sandbox/win/src/win_utils.h" |
16 | 16 |
17 namespace { | 17 namespace { |
18 | 18 |
19 // These are the only safe rights that can be given to a sandboxed | 19 // These are the only safe rights that can be given to a sandboxed |
20 // process for the process created by the broker. All others are potential | 20 // process for the process created by the broker. All others are potential |
21 // vectors of privilege elevation. | 21 // vectors of privilege elevation. |
22 const DWORD kProcessRights = SYNCHRONIZE | | 22 const DWORD kProcessRights = SYNCHRONIZE | |
23 PROCESS_QUERY_INFORMATION | | 23 PROCESS_QUERY_INFORMATION | |
24 PROCESS_QUERY_LIMITED_INFORMATION | | 24 PROCESS_QUERY_LIMITED_INFORMATION | |
25 PROCESS_TERMINATE | | 25 PROCESS_TERMINATE | |
(...skipping 207 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
233 if (!CreateProcessExWHelper(client_info.process, should_give_full_access, | 233 if (!CreateProcessExWHelper(client_info.process, should_give_full_access, |
234 app_name.c_str(), cmd_line.get(), NULL, NULL, | 234 app_name.c_str(), cmd_line.get(), NULL, NULL, |
235 FALSE, 0, NULL, NULL, &startup_info, | 235 FALSE, 0, NULL, NULL, &startup_info, |
236 process_info)) { | 236 process_info)) { |
237 return ERROR_ACCESS_DENIED; | 237 return ERROR_ACCESS_DENIED; |
238 } | 238 } |
239 return ERROR_SUCCESS; | 239 return ERROR_SUCCESS; |
240 } | 240 } |
241 | 241 |
242 } // namespace sandbox | 242 } // namespace sandbox |
OLD | NEW |