Changeset 252211 in webkit
- Timestamp:
- Nov 7, 2019 3:20:01 PM (4 years ago)
- Location:
- trunk/Source/WebKit
- Files:
-
- 2 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/Source/WebKit/ChangeLog
r252185 r252211 1 2019-11-07 Per Arne Vollan <pvollan@apple.com> 2 3 [iOS] Add logging and telemetry to more mach lookup rules 4 https://bugs.webkit.org/show_bug.cgi?id=203978 5 6 Reviewed by Brent Fulgham. 7 8 Add logging and telemetry to help determine if mach lookup of these services can be denied in the WebContent process. 9 10 * Resources/SandboxProfiles/ios/com.apple.WebKit.WebContent.sb: 11 1 12 2019-11-07 Alex Christensen <achristensen@webkit.org> 2 13 -
trunk/Source/WebKit/Resources/SandboxProfiles/ios/com.apple.WebKit.WebContent.sb
r252081 r252211 123 123 (define-once (play-audio) 124 124 (allow mach-lookup 125 (global-name "com.apple.audio.AURemoteIOServer") 125 (global-name "com.apple.audio.AURemoteIOServer")) 126 (allow mach-lookup (with report) (with telemetry) 126 127 (xpc-service-name "com.apple.audio.toolbox.reporting.service"))) 127 128 … … 202 203 (allow mach-lookup 203 204 (global-name "com.apple.mediaremoted.xpc")) 205 (allow mach-lookup (with report) (with telemetry) 206 (xpc-service-name "com.apple.MediaPlayer.RemotePlayerService")) 204 207 ) 205 208 … … 628 631 (ipc-posix-name-prefix "apple.cfprefs.")) 629 632 630 (allow mach-lookup 633 (allow mach-lookup (with report) (with telemetry) 634 (global-name "com.apple.lsd.open") 631 635 (global-name "com.apple.lsd.mapdb")) 632 636 … … 644 648 (allow ipc-posix-sem-open)) 645 649 650 (allow mach-lookup (with report) (with telemetry) 651 (global-name "com.apple.runningboard")) 652 646 653 (allow system-sched 647 654 (require-entitlement "com.apple.private.kernel.override-cpumon")) … … 653 660 (allow sysctl-read sysctl-write 654 661 (sysctl-name "vm.footprint_suspend"))) 662 663 (allow mach-lookup (with report) (with telemetry) 664 (global-name "com.apple.system.logger")) 655 665 656 666 (allow file-read-metadata network-outbound … … 661 671 (allow ipc-posix-shm-read* 662 672 (ipc-posix-name "apple.shm.notification_center")) 673 674 (allow mach-lookup (with report) (with telemetry) 675 (global-name "com.apple.diagnosticd")) 663 676 664 677 (logd-diagnostic-client) … … 718 731 (speech-synthesis-and-voiceover) 719 732 720 (allow mach-lookup 733 (allow mach-lookup (with report) (with telemetry) 721 734 (global-name "com.apple.audio.AudioComponentRegistrar")) 722 735 … … 762 775 (allow file-read* 763 776 (well-known-system-group-container-subpath "/systemgroup.com.apple.lsd.iconscache")) 764 (allow mach-lookup 777 (allow mach-lookup (with report) (with telemetry) 765 778 (xpc-service-name "com.apple.iconservices") 766 779 (global-name "com.apple.iconservices"))
Note: See TracChangeset
for help on using the changeset viewer.