New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 765819 link

Starred by 1 user

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

consider relaxing reparse point checks in sandbox target filesystem policy

Project Member Reported by wfh@chromium.org, Sep 15 2017

Issue description

Currently sandbox policy does not allow filesystem rules to be placed onto directories that contain reparse points in the paths.

This is implemented in PreProcessName in src/filesystem_policy.cc

We could consider relaxing this policy as Windows now blocks non writable mount points from sandboxes so the original risks are not as worrisome as before.

This has benefit of sandbox intercepts working fully on machines using e.g. user profile disks on RDS e.g. issue 413889
 
Cc: wfh@chromium.org

Sign in to add a comment