Bug 207276 - Update sandbox to allow communication with dnssd service
Summary: Update sandbox to allow communication with dnssd service
Status: RESOLVED FIXED
Alias: None
Product: WebKit
Classification: Unclassified
Component: WebKit2 (show other bugs)
Version: WebKit Nightly Build
Hardware: Unspecified Unspecified
: P2 Normal
Assignee: Brent Fulgham
URL:
Keywords: InRadar
Depends on:
Blocks:
 
Reported: 2020-02-05 10:12 PST by Brent Fulgham
Modified: 2020-02-05 13:42 PST (History)
4 users (show)

See Also:


Attachments
Patch (3.43 KB, patch)
2020-02-05 10:16 PST, Brent Fulgham
no flags Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Brent Fulgham 2020-02-05 10:12:46 PST
Testing and telemetry indicates that we need access to the DNSSD mach service in our Network Process.
Comment 1 Brent Fulgham 2020-02-05 10:15:49 PST
<rdar://problem/59158405>
Comment 2 Brent Fulgham 2020-02-05 10:16:44 PST
Created attachment 389827 [details]
Patch
Comment 3 Per Arne Vollan 2020-02-05 11:17:52 PST
Comment on attachment 389827 [details]
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=389827&action=review

> Source/WebKit/Resources/SandboxProfiles/ios/com.apple.WebKit.Networking.sb:95
> +            (allow network-outbound (literal "/private/var/run/mDNSResponder"))
> +            (allow mach-lookup (global-name "com.apple.dnssd.service"))) ;; <rdar://problem/55562091>
> +        (begin
> +            (allow network-outbound (literal "/private/var/run/mDNSResponder"))
> +            (allow mach-lookup (global-name "com.apple.dnssd.service")))) ;; <rdar://problem/55562091>

Should this be outside 'if gizmo?'?
Comment 4 Brent Fulgham 2020-02-05 12:14:36 PST
Comment on attachment 389827 [details]
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=389827&action=review

>> Source/WebKit/Resources/SandboxProfiles/ios/com.apple.WebKit.Networking.sb:95
>> +            (allow mach-lookup (global-name "com.apple.dnssd.service")))) ;; <rdar://problem/55562091>
> 
> Should this be outside 'if gizmo?'?

It is in the 'else' of the 'if gizmo?' clause, so it's correct.
Comment 5 Per Arne Vollan 2020-02-05 12:59:01 PST
Comment on attachment 389827 [details]
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=389827&action=review

R=me.

>>> Source/WebKit/Resources/SandboxProfiles/ios/com.apple.WebKit.Networking.sb:95
>>> +            (allow mach-lookup (global-name "com.apple.dnssd.service")))) ;; <rdar://problem/55562091>
>> 
>> Should this be outside 'if gizmo?'?
> 
> It is in the 'else' of the 'if gizmo?' clause, so it's correct.

Ah, I see!
Comment 6 WebKit Commit Bot 2020-02-05 13:42:33 PST
Comment on attachment 389827 [details]
Patch

Clearing flags on attachment: 389827

Committed r255852: <https://trac.webkit.org/changeset/255852>
Comment 7 WebKit Commit Bot 2020-02-05 13:42:35 PST
All reviewed patches have been landed.  Closing bug.