Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(865)

Issue 1051243002: Non-SFI: move socketpair() from plugin process to browser process. (Closed)

Created:
5 years, 8 months ago by hidehiko
Modified:
5 years, 7 months ago
CC:
chromium-reviews, hamaji, mazda, mdempsky, Tom Sepez
Base URL:
https://chromium.googlesource.com/chromium/src.git@master
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

Non-SFI: move socketpair() from plugin process to browser process. Currently, socket pairs for the IPC channels (mainly for PPAPI IPC channels) are created in nacl_helper (and nacl_helper_nonsfi). However, to make more secure, socketpair() will be prohibited in Non-SFI mode. So, this is its preparation. TEST=Ran bots. BUG=358417 Committed: https://crrev.com/7f43c10288a54b68bf4ac3a6656618d7b14c7bec Cr-Commit-Position: refs/heads/master@{#330330}

Patch Set 1 #

Patch Set 2 : #

Total comments: 14

Patch Set 3 : Rebase & reimplement #

Total comments: 22

Patch Set 4 : #

Total comments: 6

Patch Set 5 : #

Total comments: 4

Patch Set 6 : Rebase #

Patch Set 7 : #

Unified diffs Side-by-side diffs Delta from patch set Stats (+205 lines, -117 lines) Patch
M components/nacl/browser/nacl_process_host.h View 1 2 3 2 chunks +10 lines, -1 line 0 comments Download
M components/nacl/browser/nacl_process_host.cc View 1 2 3 4 5 chunks +154 lines, -55 lines 0 comments Download
M components/nacl/common/nacl_messages.h View 1 2 3 4 5 6 2 chunks +8 lines, -0 lines 0 comments Download
M components/nacl/common/nacl_types.h View 1 2 3 4 5 6 1 chunk +12 lines, -0 lines 0 comments Download
M components/nacl/loader/nonsfi/nonsfi_listener.h View 1 2 1 chunk +0 lines, -1 line 0 comments Download
M components/nacl/loader/nonsfi/nonsfi_listener.cc View 1 2 3 4 2 chunks +21 lines, -60 lines 0 comments Download

Messages

Total messages: 27 (10 generated)
hidehiko
Hi Mark, Could you take a look? Thanks, - hidehiko
5 years, 8 months ago (2015-04-12 14:04:22 UTC) #2
hidehiko
On 2015/04/12 14:04:22, hidehiko wrote: > Hi Mark, > > Could you take a look? ...
5 years, 8 months ago (2015-04-15 13:47:39 UTC) #3
Mark Seaborn
https://codereview.chromium.org/1051243002/diff/20001/components/nacl/browser/nacl_process_host.cc File components/nacl/browser/nacl_process_host.cc (right): https://codereview.chromium.org/1051243002/diff/20001/components/nacl/browser/nacl_process_host.cc#newcode826 components/nacl/browser/nacl_process_host.cc:826: if (params.enable_ipc_proxy && uses_nonsfi_mode_) { Nit: At the moment, ...
5 years, 8 months ago (2015-04-15 20:52:05 UTC) #4
Mark Seaborn
https://codereview.chromium.org/1051243002/diff/20001/components/nacl/browser/nacl_process_host.cc File components/nacl/browser/nacl_process_host.cc (right): https://codereview.chromium.org/1051243002/diff/20001/components/nacl/browser/nacl_process_host.cc#newcode829 components/nacl/browser/nacl_process_host.cc:829: !IPC::SocketPair(&params.renderer_server_ppapi_fd.fd, On 2015/04/15 20:52:05, Mark Seaborn wrote: > If ...
5 years, 7 months ago (2015-05-12 06:46:10 UTC) #5
hidehiko
PTAL. https://codereview.chromium.org/1051243002/diff/20001/components/nacl/browser/nacl_process_host.cc File components/nacl/browser/nacl_process_host.cc (right): https://codereview.chromium.org/1051243002/diff/20001/components/nacl/browser/nacl_process_host.cc#newcode826 components/nacl/browser/nacl_process_host.cc:826: if (params.enable_ipc_proxy && uses_nonsfi_mode_) { On 2015/04/15 20:52:05, ...
5 years, 7 months ago (2015-05-12 18:47:51 UTC) #10
Mark Seaborn
LGTM, thanks https://codereview.chromium.org/1051243002/diff/120001/components/nacl/browser/nacl_process_host.cc File components/nacl/browser/nacl_process_host.cc (left): https://codereview.chromium.org/1051243002/diff/120001/components/nacl/browser/nacl_process_host.cc#oldcode677 components/nacl/browser/nacl_process_host.cc:677: // IPC messages relating to NaCl's validation ...
5 years, 7 months ago (2015-05-12 23:24:06 UTC) #11
hidehiko
R+=jln@. Julien, could you take a look at *_message.h" file as an OWNER? Thanks, - ...
5 years, 7 months ago (2015-05-13 06:39:21 UTC) #15
Mark Seaborn
https://codereview.chromium.org/1051243002/diff/180001/components/nacl/browser/nacl_process_host.cc File components/nacl/browser/nacl_process_host.cc (right): https://codereview.chromium.org/1051243002/diff/180001/components/nacl/browser/nacl_process_host.cc#newcode879 components/nacl/browser/nacl_process_host.cc:879: DCHECK(params.enable_ipc_proxy); Nit: This isn't needed now, since you check ...
5 years, 7 months ago (2015-05-13 06:51:11 UTC) #16
hidehiko
https://codereview.chromium.org/1051243002/diff/180001/components/nacl/browser/nacl_process_host.cc File components/nacl/browser/nacl_process_host.cc (right): https://codereview.chromium.org/1051243002/diff/180001/components/nacl/browser/nacl_process_host.cc#newcode879 components/nacl/browser/nacl_process_host.cc:879: DCHECK(params.enable_ipc_proxy); On 2015/05/13 06:51:11, Mark Seaborn wrote: > Nit: ...
5 years, 7 months ago (2015-05-13 14:44:48 UTC) #17
Mark Seaborn
@hidehiko: One more commenting nit... https://codereview.chromium.org/1051243002/diff/200001/components/nacl/common/nacl_messages.h File components/nacl/common/nacl_messages.h (right): https://codereview.chromium.org/1051243002/diff/200001/components/nacl/common/nacl_messages.h#newcode128 components/nacl/common/nacl_messages.h:128: IPC_MESSAGE_CONTROL4(NaClProcessHostMsg_PpapiChannelsCreated, Similarly, can you ...
5 years, 7 months ago (2015-05-13 17:15:39 UTC) #18
Mark Seaborn
@jln: I reviewed the IPC message changes for security. The message contents are fine. The ...
5 years, 7 months ago (2015-05-13 17:17:47 UTC) #19
hidehiko
jln@, friendly ping? On 2015/05/13 17:17:47, Mark Seaborn wrote: > @jln: I reviewed the IPC ...
5 years, 7 months ago (2015-05-15 12:53:42 UTC) #20
jln (very slow on Chromium)
On 2015/05/15 12:53:42, hidehiko wrote: > jln@, friendly ping? Thanks hidehiko for the well thought ...
5 years, 7 months ago (2015-05-16 00:10:30 UTC) #21
hidehiko
Thank you for review. Submitting. For father improvement, +1 with jln@. Let's discuss in another ...
5 years, 7 months ago (2015-05-18 06:28:14 UTC) #22
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/1051243002/240001
5 years, 7 months ago (2015-05-18 06:28:23 UTC) #25
commit-bot: I haz the power
Committed patchset #7 (id:240001)
5 years, 7 months ago (2015-05-18 06:31:14 UTC) #26
commit-bot: I haz the power
5 years, 7 months ago (2015-05-18 11:33:47 UTC) #27
Message was sent while issue was closed.
Patchset 7 (id:??) landed as
https://crrev.com/7f43c10288a54b68bf4ac3a6656618d7b14c7bec
Cr-Commit-Position: refs/heads/master@{#330330}

Powered by Google App Engine
This is Rietveld 408576698