Allow utilities to preload libraries before sandbox lockdown Some utilities on Windows wrap dynamic libraries which might be distributed as components. Allowing these to load requires punching holes in the sandbox using file interceptions that are being phased out. This CL introduces a mechanism for service processes to specify a list of dll paths which will be loaded before the sandbox goes into lockdown. They can later be loaded by code using the same path, as Windows keeps them in memory. The mechanism uses a new opaque data transfer mechanism in the sandbox which will extend to different uses later. For now the list of DLLs is the only data transferred so this CL uses base::Pickle to serialize & transfer the DLLs to load. As loading arbitrary DLLs is a powerful capability a passkey is added for the new service process host option, and a file containing valid callers is added with OWNERS from the sandbox to ensure security review. A following CL will enable this behavior for screen_ai, but at this point only tests exercise these APIs The flow is roughly: --- In the browser/broker:- ServiceProcessHost gets a new option: .WithPreloadedLibraries UtilityProcessHost gets a new member: preload_libraries_ UtilityProcessHost gives this to the UtilitySandboxedProcessLauncherDelegate UtilitySandboxedProcessLauncherDelegate turns a list of DLLs into an opaque blob and attaches it to the sandbox's TargetPolicy during PreSpawnTarget. The sandbox smuggles this blob into the target (previous CL). In the child/target:- The UtilityMain knows it might have a blob, so asks TargetServices. UtilityMain coordinates with its sandbox delegate, so knows that the blob is a pickled list of DLLs. UtilityMain loads these dlls before sandbox lockdown. --- Bug: 1435571 Change-Id: Ided63f9d723811b66c183335b5533c84e9783a2a Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/4471953 Reviewed-by: Nasko Oskov <nasko@chromium.org> Reviewed-by: Ken Rockot <rockot@google.com> Reviewed-by: Will Harris <wfh@chromium.org> Commit-Queue: Will Harris <wfh@chromium.org> Cr-Commit-Position: refs/heads/main@{#1137415}
Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.
The project's web site is https://www.chromium.org.
To check out the source code locally, don't use git clone! Instead, follow the instructions on how to get the code.
Documentation in the source is rooted in docs/README.md.
Learn how to Get Around the Chromium Source Code Directory Structure .
For historical reasons, there are some small top level directories. Now the guidance is that new top level directories are for product (e.g. Chrome, Android WebView, Ash). Even if these products have multiple executables, the code should be in subdirectories of the product.
If you found a bug, please file it at https://crbug.com/new.