Changeset 83425 in webkit


Ignore:
Timestamp:
Apr 10, 2011 10:49:27 PM (13 years ago)
Author:
mjs@apple.com
Message:

2011-04-10 Maciej Stachowiak <mjs@apple.com>

Reviewed by Dan Bernstein.

REGRESSION: WebProcess spews sandboxing violations for outbound network traffic
https://bugs.webkit.org/show_bug.cgi?id=58215
<rdar://problem/9251695>


  • WebProcess/com.apple.WebProcess.sb: Restore some previously removed rules.
Location:
trunk/Source/WebKit2
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • trunk/Source/WebKit2/ChangeLog

    r83416 r83425  
     12011-04-10  Maciej Stachowiak  <mjs@apple.com>
     2
     3        Reviewed by Dan Bernstein.
     4
     5        REGRESSION: WebProcess spews sandboxing violations for outbound network traffic
     6        https://bugs.webkit.org/show_bug.cgi?id=58215
     7        <rdar://problem/9251695>
     8       
     9        * WebProcess/com.apple.WebProcess.sb: Restore some previously removed rules.
     10
    1112011-04-10  Kimmo Kinnunen  <kimmo.t.kinnunen@nokia.com>
    212
  • trunk/Source/WebKit2/WebProcess/com.apple.WebProcess.sb

    r83157 r83425  
    133133)
    134134
     135;; FIXME: <rdar://problem/9263428> These rules are required to avoid
     136;; sandbox violation spam, but some narrower rule should be
     137;; sufficient.
     138(allow network-outbound)
     139(deny network-outbound (regex ""))
     140(deny network-outbound (local ip))
     141
    135142(allow network-outbound
    136143   ;; Local mDNSResponder for DNS, arbitrary outbound TCP
     
    138145   (remote tcp)
    139146)
     147
     148(allow system-socket)
     149(allow network-outbound (control-name "com.apple.network.statistics"))
    140150
    141151;; FIXME: Once <rdar://problem/8900275> has been fixed, these rules can be removed.
Note: See TracChangeset for help on using the changeset viewer.