Never add win32k or signed policy rules on unsupported OS.
This CL also ensures that mitigation policy is applied before adding any rules that depend on the policy. It also restores the sandbox convention that mitigation policies and rules can always be requested by a sandbox user and the sandbox will try and enforce the maximum set of rules supported by the running OS. i.e. the user should not be aware of OS capabilities, merely sandbox capabilities. BUG=996834 Change-Id: I5a8432d94dc1bcfbe327589f2b21c4c76fb9fedb Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/1810937Reviewed-by:James Forshaw <forshaw@chromium.org> Commit-Queue: Will Harris <wfh@chromium.org> Cr-Commit-Position: refs/heads/master@{#697622}
Showing
Please register or sign in to comment