diff --git a/src/shared/windows-launch-failure-code.test.ts b/src/shared/windows-launch-failure-code.test.ts index ebbead548cb..95506d42de6 100644 --- a/src/shared/windows-launch-failure-code.test.ts +++ b/src/shared/windows-launch-failure-code.test.ts @@ -64,7 +64,7 @@ describe('decodeWindowsLaunchFailureCode', () => { } ) - // 66 of the table's rows are asserted nowhere individually. The enum is contiguous 0..72 by + // 65 of the table's 71 rows are asserted nowhere individually. The enum is contiguous 0..72 by // construction, so this catches a row dropped or renumbered by an edit without restating 71 // descriptions that would just be the table copied twice. it('decodes every sandbox code in the contiguous range except the excluded ones', () => { diff --git a/src/shared/windows-launch-failure-code.ts b/src/shared/windows-launch-failure-code.ts index 89dc7c8253d..8c0ae16b334 100644 --- a/src/shared/windows-launch-failure-code.ts +++ b/src/shared/windows-launch-failure-code.ts @@ -158,8 +158,9 @@ const LAUNCH_RESULT_CODES: Record = { * * Deliberately absent, on one rule — never name a code that would mislead: SBOX_ALL_OK (0) and * LAUNCH_RESULT_SUCCESS (1002) both contradict launch-failed, LAUNCH_RESULT_START (1001) is a - * range sentinel, and SBOX_ERROR_UNSANDBOXED_PROCESS (62) is ordinary control flow that - * sandbox_win.cc returns to route a child down the unsandboxed path. + * range sentinel, and SBOX_ERROR_UNSANDBOXED_PROCESS (62) is sandbox_win.h's documented "this + * process should be run unsandboxed" status rather than a fault — and is in any case unreachable + * from the pinned Chromium's launch path, which decides that before it generates a policy. */ export function decodeWindowsLaunchFailureCode( exitCode: number