Changeset 290250 in webkit
- Timestamp:
- Feb 21, 2022 10:10:40 AM (2 years ago)
- Location:
- trunk/Source/WebKit
- Files:
-
- 3 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/Source/WebKit/ChangeLog
r290246 r290250 1 2022-02-21 Per Arne Vollan <pvollan@apple.com> 2 3 [macOS] Remove resource access in sandbox for older OS versions 4 https://bugs.webkit.org/show_bug.cgi?id=236975 5 6 Reviewed by Brent Fulgham. 7 8 Remove access to some resources in sandbox for older OS versions. Access to these resources were initially 9 added in https://trac.webkit.org/changeset/290180/webkit and https://trac.webkit.org/changeset/290066/webkit, 10 and was only intended to land on a branch. 11 12 * NetworkProcess/mac/com.apple.WebKit.NetworkProcess.sb.in: 13 * WebProcess/com.apple.WebProcess.sb.in: 14 1 15 2022-02-21 Simon Lewis <simon.lewis@apple.com> 2 16 -
trunk/Source/WebKit/NetworkProcess/mac/com.apple.WebKit.NetworkProcess.sb.in
r289926 r290250 113 113 #if ENABLE(SET_WEBCONTENT_PROCESS_INFORMATION_IN_NETWORK_PROCESS) 114 114 (allow mach-lookup (global-name "com.apple.coreservices.launchservicesd")) 115 #endif116 117 #if !PLATFORM(MAC) || __MAC_OS_X_VERSION_MIN_REQUIRED < 130000118 (allow mach-lookup119 (global-name120 "com.apple.analyticsd.messagetracer"121 "com.apple.appsleep"122 "com.apple.bsd.dirhelper"123 "com.apple.espd"124 "com.apple.secinitd"125 "com.apple.system.DirectoryService.libinfo_v1"126 "com.apple.system.logger"127 "com.apple.system.opendirectoryd.membership"128 "com.apple.xpc.activity.unmanaged"))129 115 #endif 130 116 -
trunk/Source/WebKit/WebProcess/com.apple.WebProcess.sb.in
r290183 r290250 1873 1873 #endif 1874 1874 1875 #if !PLATFORM(MAC) || __MAC_OS_X_VERSION_MIN_REQUIRED < 1300001876 (define (syscall-unix-older-macOS)1877 (syscall-number1878 SYS___pthread_markcancel1879 SYS_abort_with_payload1880 SYS_chmod_extended1881 SYS_connect_nocancel1882 SYS_connectx1883 SYS_fgetattrlist ;; <rdar://problem/50931110>1884 SYS_fileport_makeport1885 SYS_fstat64_extended ;; <rdar://problem/61310019>1886 SYS_getpeername1887 SYS_getsockopt1888 SYS_guarded_write_np1889 SYS_lstat64_extended1890 SYS_lstat_extended1891 SYS_memorystatus_control ;; Needed for memory measurement infrastructure, see <rdar://problem/48647263>1892 SYS_mkdirat1893 SYS_open_dprotected_np ;; <rdar://problem/74473824>1894 SYS_pipe1895 SYS_process_policy1896 SYS_psynch_rw_rdlock ;; <rdar://problem/49060359>1897 SYS_pwrite1898 SYS_quotactl ;; <rdar://problem/49945031>1899 SYS_recvfrom1900 SYS_recvfrom_nocancel1901 SYS_rmdir1902 SYS_select1903 SYS_select_nocancel1904 SYS_sem_post1905 SYS_sem_wait1906 SYS_sendmsg_nocancel1907 SYS_sendto_nocancel1908 #if __MAC_OS_X_VERSION_MIN_REQUIRED < 1200001909 SYS_setattrlist ;; rdar://problem/741627771910 #endif1911 SYS_setpriority1912 SYS_setrlimit1913 SYS_setsockopt1914 SYS_shutdown1915 SYS_sigreturn1916 SYS_socketpair1917 SYS_stat64_extended ;; <rdar://problem/50473330>1918 SYS_terminate_with_payload ;; <rdar://problem/50026580>1919 SYS_thread_selfusage1920 #if __MAC_OS_X_VERSION_MIN_REQUIRED >= 1100001921 SYS_ulock_wait2 ;; <rdar://problem/58743778>1922 #endif1923 ))1924 #endif1925 1926 1875 (define (syscall-unix-common) 1927 1876 (syscall-number … … 1971 1920 SYS_kdebug_trace64 1972 1921 SYS_kdebug_trace_string ;; Needed for performance sampling, see <rdar://problem/48829655>. 1973 SYS_kevent ;; <rdar://89072361>1974 1922 SYS_kevent_id 1975 1923 SYS_kevent_qos … … 2047 1995 SYS_guarded_pwrite_np 2048 1996 SYS_kdebug_typefilter 1997 SYS_kevent ;; <rdar://89072361> 2049 1998 SYS_mlock 2050 1999 SYS_munlock … … 2078 2027 (allow syscall-unix 2079 2028 (syscall-unix-common)) 2080 2081 #if !PLATFORM(MAC) || __MAC_OS_X_VERSION_MIN_REQUIRED < 1300002082 (allow syscall-unix2083 (syscall-unix-older-macOS))2084 #endif2085 2029 2086 2030 (if (equal? (param "CPU") "arm64")
Note: See TracChangeset
for help on using the changeset viewer.