What exactly is function of "Enable file source tracking" in auto sandbox rules?

First of all thank for this excellent masterpice - i use Comodo FW third year now and i didn get any infection since then !

My config: WIN 10 PRO, Commodo Firewall 8.2.0.5027 with default configuration except this two: HIPS off and with enabled auto sandbox RUN VIRTUALLY for ALL unrecognized applications from ANY location.

My question - that i cant find answer anywhere - and i really did search for definition of “source” long time :

  1. What is definition of “source” ? Is that digital signature or something else ?

It says in manual:
Enable file source tracking – If enabled, CIS will decide whether to sandbox a file based on file source, reputation and location. If disabled, sandbox decisions are based only on file reputation and location.

What will happen if i disable “source tracking” : can WIN 10 freeze if some updates will not be recognized as Microsofts origin if i disable “source tracking”? If i disable “source tracking” will that lower my default security or will just put more files to UNTRUSTED/UNRECOGNIZED state that i can manually move to TRUSTED later when i run SCAN ?

And most important question : can disabling “source tracking” render my computer unbotable because some M$ updates will not be applied ?

  1. I have problem with my application, that is for some strange reason installed on mapped network drive and is without any digitaly sig (look at screenshot) . I already declare this file as installer and i put and entire folder to TRUSTED but it keeps saying that could not be recognized

On second screen you see that that this app FAW.EXE is trusted ???

What componenet put this pop-up ? If this is pop-up from sandbox why, if i set FAW.EXE as trusted and as i understand any manual action should override automatic file check ? I also did try to put hash of this file (FAW.EXE) and also did try to add runing process and nothing works … always i end up with this pop-up. Its not hard to click every day once to allow and trust this application , but some day i will click allow to something that i shuld not … and in this times of Petya and CryptoXXX this can be real problem …Is maybe reason for my problem that this file reside/starts on mapped intranet network drive, but then somehow (i suppose) then go to my temp folder or in RAM and execute there? I have HIPS disabled.

Thanks for excellent program , this is my first “problem” in third year of use of Comodo FW !

Source refers to whether a file is from the Internet, local network, internal or external drive.

And most important question : can disabling "source tracking" render my computer unbotable because some M$ updates will not be applied ?
It does not interfere with Microsoft updates.
2. I have problem with my application, that is for some strange reason installed on mapped network drive and is without any digitaly sig (look at screenshot) . I already declare this file as installer and i put and entire folder to TRUSTED but it keeps saying that could not be recognized

On second screen you see that that this app FAW.EXE is trusted ???

What componenet put this pop-up ? If this is pop-up from sandbox why, if i set FAW.EXE as trusted and as i understand any manual action should override automatic file check ? I also did try to put hash of this file (FAW.EXE) and also did try to add runing process and nothing works … always i end up with this pop-up. Its not hard to click every day once to allow and trust this application , but some day i will click allow to something that i shuld not … and in this times of Petya and CryptoXXX this can be real problem …Is maybe reason for my problem that this file reside/starts on mapped intranet network drive,

You’re hitting the nail on the head that it’s because it’s on a network drive.
but then somehow (i suppose) then go to my temp folder or in RAM and execute there? I have HIPS disabled.
If you would run the file from your internal hard drive CIS will keep on trusting it because an internal hd gets continuously monitored and is therefor a safe source.