| Summary: | [iOS] AGX compiler service sandbox violation | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | WebKit | Reporter: | Per Arne Vollan <pvollan> | ||||||
| Component: | WebKit Misc. | Assignee: | Per Arne Vollan <pvollan> | ||||||
| Status: | RESOLVED FIXED | ||||||||
| Severity: | Normal | CC: | benjamin, bfulgham, cdumez, cmarcelo, ews-watchlist, matt, webkit-bug-importer | ||||||
| Priority: | P2 | Keywords: | InRadar | ||||||
| Version: | WebKit Nightly Build | ||||||||
| Hardware: | Unspecified | ||||||||
| OS: | Unspecified | ||||||||
| See Also: | https://bugs.webkit.org/show_bug.cgi?id=203915 | ||||||||
| Attachments: |
|
||||||||
|
Description
Per Arne Vollan
2020-09-01 10:04:33 PDT
Created attachment 407693 [details]
Patch
Comment on attachment 407693 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=407693&action=review r=me > Source/WebKit/Shared/Cocoa/SandboxExtensionCocoa.mm:97 > + extensionFlags |= SANDBOX_EXTENSION_PREFIXMATCH; Can you double-check we do not have any other "xpc-service-prefix" rules that aren't set with this flag? (In reply to Brent Fulgham from comment #3) > Comment on attachment 407693 [details] > Patch > > View in context: > https://bugs.webkit.org/attachment.cgi?id=407693&action=review > > r=me > > > Source/WebKit/Shared/Cocoa/SandboxExtensionCocoa.mm:97 > > + extensionFlags |= SANDBOX_EXTENSION_PREFIXMATCH; > > Can you double-check we do not have any other "xpc-service-prefix" rules > that aren't set with this flag? I just checked and don't see any others. Created attachment 407706 [details]
Patch
(In reply to Brent Fulgham from comment #3) > Comment on attachment 407693 [details] > Patch > > View in context: > https://bugs.webkit.org/attachment.cgi?id=407693&action=review > > r=me > > > Source/WebKit/Shared/Cocoa/SandboxExtensionCocoa.mm:97 > > + extensionFlags |= SANDBOX_EXTENSION_PREFIXMATCH; > > Can you double-check we do not have any other "xpc-service-prefix" rules > that aren't set with this flag? I had to change the patch to issue an array of AGX extensions, since the prefix match did not work as expected. Thanks for reviewing! Comment on attachment 407706 [details]
Patch
r=me. It's a shame we have to handle them individually, but this makes sense.
(In reply to Brent Fulgham from comment #7) > Comment on attachment 407706 [details] > Patch > > r=me. It's a shame we have to handle them individually, but this makes sense. Thanks for reviewing! Committed r266411: <https://trac.webkit.org/changeset/266411> All reviewed patches have been landed. Closing bug and clearing flags on attachment 407706 [details]. *** Bug 216033 has been marked as a duplicate of this bug. *** Hi I have seen that this issue has reappeared in iPasOS 14.2 Thanks |