| 1 | // Package packagegrant removes, from the tree an application runs from, the |
| 2 | // access entries that grant a specific Windows app package. |
| 3 | // |
| 4 | // Chromium's sandboxed renderer exits with STATUS_BREAKPOINT while loading a DLL |
| 5 | // whose DACL carries an allow entry for a specific AppContainer package SID, and |
| 6 | // the window never paints. On Electron 43 and 44 alike one such entry on |
| 7 | // ffmpeg.dll is enough, and a live package's SID fails the same as one whose |
| 8 | // profile is gone; the same entry on the executable, on a directory alone, or as |
| 9 | // a deny entry changes nothing. The built-in package groups (ALL APPLICATION |
| 10 | // PACKAGES, ALL RESTRICTED APPLICATION PACKAGES) and capability SIDs do not. |
| 11 | // |
| 12 | // Such entries arrive from whatever last ran an AppContainer against files in |
| 13 | // that tree with inheritance on: a sandbox granting its package read and |
| 14 | // execute on the directory of a tool it launches is the ordinary way. |
| 15 | // |
| 16 | // The judgement reads the SID's structure — authority 15, base RID 2, more |
| 17 | // sub-authorities than a built-in group has — never an account name, which a |
| 18 | // package SID does not resolve to anyway. Only allow entries are removed, so a |
| 19 | // pass narrows access and never widens it. An entry inherited from above the |
| 20 | // tree cannot be removed at its source without touching a directory this tree |
| 21 | // does not own; the object that inherits it is protected instead, keeping every |
| 22 | // other entry it had as its own. |
| 23 | package packagegrant |
| 24 |