fix(sandbox): harden the per-session record and the ACL runner failure paths (review round v6)

Durable record: bound to the owning session id and validated at the fold (orphan-SID shape, temp path inside the host temp root) — a fork's copied parent record no longer provisions the child, and a tampered record fails loud. Private temp dir: random unguessable name persisted in the record, created exclusively (pre-existing entries and reparse points fail EEXIST). Persistence: a fresh provision kicks an immediate flush (no write-behind debounce), narrowing the crash window to the flush latency — documented as the one self-healing gap. Runner-failure rules: exit-gated on 127 so a confined command that prints the signature on a non-127 exit is never misclassified. Spawn: AssignProcessToJobObject failure terminates the suspended child (no hanging orphans). SandboxExecutionPolicy.sessionId is the branded SessionId. Boundary docs: qualifying clause on the absolutist sentences, NULL-DACL Known Limitation, 'full' scoped to the supported NTFS surface, CLM gate comment.
This commit is contained in:
Huanqi Cao
2026-08-08 23:23:38 +08:00
parent 441927c526
commit 6478da61e3
27 changed files with 472 additions and 278 deletions

View File

@@ -331,7 +331,11 @@ export function spawnSandboxedInherited(
}
if (api.assignProcessToJobObject(job, processHandle) === 0) {
// The child was created suspended and is NOT in the kill-on-close job:
// closing handles would leave it suspended forever. Terminate it first,
// then drop the handles and throw.
const win32Code = api.getLastError()
api.terminateProcess(processHandle, 1)
api.closeHandle(threadHandle)
api.closeHandle(processHandle)
api.closeHandle(job)