Changeset 283375 in webkit
- Timestamp:
- Oct 1, 2021, 10:07:54 AM (3 years ago)
- Location:
- trunk/Source/WebKit
- Files:
-
- 3 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/Source/WebKit/ChangeLog
r283374 r283375 1 2021-10-01 Per Arne Vollan <pvollan@apple.com> 2 3 Make sandbox rules for debug syscalls stricter 4 https://bugs.webkit.org/show_bug.cgi?id=230985 5 <rdar://49531420> 6 7 Reviewed by Brent Fulgham. 8 9 Make sandbox rules for debug syscalls stricter in the WebContent process on macOS and iOS. 10 11 * Resources/SandboxProfiles/ios/com.apple.WebKit.WebContent.sb.in: 12 * WebProcess/com.apple.WebProcess.sb.in: 13 1 14 2021-10-01 Per Arne Vollan <pvollan@apple.com> 2 15 -
trunk/Source/WebKit/Resources/SandboxProfiles/ios/com.apple.WebKit.WebContent.sb.in
r283204 r283375 1295 1295 (syscall-number SYS_ulock_wait) 1296 1296 (syscall-number SYS_ulock_wake) 1297 (syscall-number SYS_kdebug_typefilter)1298 1297 (syscall-number SYS_shared_region_check_np) 1299 1298 (syscall-number SYS_getpid) … … 1317 1316 (syscall-number SYS_pread_nocancel) 1318 1317 (syscall-number SYS___semwait_signal_nocancel) 1319 (syscall-number SYS_kdebug_trace_string) ;; Needed for performance sampling, see <rdar://problem/48829655>.1320 1318 (syscall-number SYS_fgetattrlist) ;; <rdar://problem/50266257> 1321 1319 (syscall-number SYS_fsetxattr) ;; <rdar://problem/49795964> … … 1332 1330 (allow syscall-unix (syscall-number SYS_objc_bp_assist_cfg_np))) 1333 1331 ) 1332 1333 (with-filter (system-attribute apple-internal) 1334 (when (defined? 'syscall-unix) 1335 (allow syscall-unix 1336 (syscall-number SYS_kdebug_trace_string) ;; Needed for performance sampling, see <rdar://problem/48829655>. 1337 (syscall-number SYS_kdebug_typefilter)))) 1334 1338 1335 1339 (when (defined? 'file-ioctl) -
trunk/Source/WebKit/WebProcess/com.apple.WebProcess.sb.in
r283289 r283375 1972 1972 (syscall-number SYS_ulock_wake) 1973 1973 (syscall-number SYS_work_interval_ctl) 1974 (syscall-number SYS_kdebug_typefilter)1975 1974 (syscall-number SYS_gettid) ;; Needed for base system, see <rdar://problem/48651255> 1976 1975 (syscall-number SYS_memorystatus_control) ;; Needed for memory measurement infrastructure, see <rdar://problem/48647263> 1977 (syscall-number SYS_kdebug_trace_string) ;; Needed for performance sampling, see <rdar://problem/48829655>.1978 1976 (syscall-number SYS_psynch_rw_rdlock) ;; <rdar://problem/49060359> 1979 1977 (syscall-number SYS_terminate_with_payload) ;; <rdar://problem/50026580> … … 2012 2010 #endif 2013 2011 ) 2012 2013 (with-filter (system-attribute apple-internal) 2014 (when (defined? 'syscall-unix) 2015 (allow syscall-unix 2016 (syscall-number SYS_kdebug_trace_string) ;; Needed for performance sampling, see <rdar://problem/48829655>. 2017 (syscall-number SYS_kdebug_typefilter)))) 2014 2018 2015 2019 #if USE(APPLE_INTERNAL_SDK)
Note:
See TracChangeset
for help on using the changeset viewer.