Commit a670e7a2 authored by James Forshaw's avatar James Forshaw Committed by Commit Bot

[Windows] Add DACL lockdown and Random Restricted SID for GPU process.

This CL adds support to enable default DACL lockdown on GPU processes as
well as enabling the random restricted SID feature to limit cross process access.

Bug: 1057218
Change-Id: I669e0d32a5eb2cd3724a876a5cef5f306d7db8a5
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/2091901Reviewed-by: default avatarWill Harris <wfh@chromium.org>
Commit-Queue: James Forshaw <forshaw@chromium.org>
Cr-Commit-Position: refs/heads/master@{#747838}
parent 0e8c98fa
...@@ -941,6 +941,13 @@ sandbox::ResultCode SandboxWin::StartSandboxedProcess( ...@@ -941,6 +941,13 @@ sandbox::ResultCode SandboxWin::StartSandboxedProcess(
return result; return result;
} }
if (process_type == service_manager::switches::kGpuProcess &&
base::FeatureList::IsEnabled(
{"GpuLockdownDefaultDacl", base::FEATURE_ENABLED_BY_DEFAULT})) {
policy->SetLockdownDefaultDacl();
policy->AddRestrictingRandomSid();
}
#if !defined(NACL_WIN64) #if !defined(NACL_WIN64)
if (process_type == service_manager::switches::kRendererProcess || if (process_type == service_manager::switches::kRendererProcess ||
process_type == service_manager::switches::kPpapiPluginProcess || process_type == service_manager::switches::kPpapiPluginProcess ||
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment