sandbox: filesystem policy denies access for relative paths
Reported by
aburgme...@bloomberg.net,
Oct 17 2016
|
||
Issue description
Chrome Version : 53.0.2785.89
OS Version: 6.3
URLs (if applicable) : N/A
Other browsers tested: N/A
What steps will reproduce the problem?
1. Start an application in the sandbox, and allow access to a particular file in the filesystem policy.
2. Let the sandboxed process access the file by providing a relative path, e.g. if the file is at C:\bla\test.txt and the current working directory is C:\bla:
CreateFile("test.txt", GENERIC_READ, 0, NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL)
3. The sandbox denies the request even though the file is white-listed in the policy.
What is the expected result?
The sandbox allows the request since the relative name refers to a white-listed file.
What happens instead of that?
The sandbox denies the request.
Please provide any additional information below. Attach a screenshot if
possible.
I don't think Chromium functionality itself is affected by this in any way, but it can be relevant for third-party users of the chromium sandbox, e.g. in my case I am interested in sandboxing a python process using the chromium sandbox.
UserAgentString: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.89 Safari/537.36
,
Oct 18 2017
Issue has not been modified or commented on in the last 365 days, please re-open or file a new bug if this is still an issue. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||
►
Sign in to add a comment |
||
Comment 1 by jmukthavaram@chromium.org
, Oct 18 2016Labels: TE-NeedsTriageHelp