Issue 2638: Sanbox: Add a policy to prevent load of unknown dlls on the  
renderer.
http://code.google.com/p/chromium/issues/detail?id=2638

Comment #2 by [EMAIL PROTECTED]:
More ideas:

We have a very short list of dlls that we want to load on the renderer.  
 From the
browser, we can get the already loaded module for each one and get the list  
of static
dependencies of each dll, recursively. We end up with the set of "required"  
dlls,
independent of any hotfix installed on the machine. We can push this list  
to the
sandbox as the white list for the dll policy. Given that everything is  
in-memory,
this could be done quickly (and yes, we could also cache the list for next  
time).

escape hatch #1: see if the renderer is able to start properly, and if it  
doesn't,
just remove this policy and launch another one (we could even use a canary).

escape hatch #2: just see how it goes with a --clean-sandbox command line.

Still to investigate: There could be a bad interaction with side by side  
assemblies.
Hopefully they have the same generic name?


Issue attribute updates:
        Cc: [EMAIL PROTECTED]

-- 
You received this message because you are listed in the owner
or CC fields of this issue, or because you starred this issue.
You may adjust your issue notification preferences at:
http://code.google.com/hosting/settings

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"Chromium-bugs" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at 
http://groups.google.com/group/chromium-bugs?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to