Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(879)

Unified Diff: content/browser/renderer_host/pepper/pepper_tcp_socket_message_filter.cc

Issue 1276763002: Avoid UAF in PepperUDP/TCPSocketMessageFilter (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: Created 5 years, 4 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: content/browser/renderer_host/pepper/pepper_tcp_socket_message_filter.cc
diff --git a/content/browser/renderer_host/pepper/pepper_tcp_socket_message_filter.cc b/content/browser/renderer_host/pepper/pepper_tcp_socket_message_filter.cc
index 9031c99d932742e438c24b2801d19e701f99ae16..7f98861339ce33e28f83e6f5799552883d4c13a6 100644
--- a/content/browser/renderer_host/pepper/pepper_tcp_socket_message_filter.cc
+++ b/content/browser/renderer_host/pepper/pepper_tcp_socket_message_filter.cc
@@ -77,7 +77,9 @@ PepperTCPSocketMessageFilter::PepperTCPSocketMessageFilter(
ssl_context_helper_(host->ssl_context_helper()),
pending_accept_(false),
pending_read_on_unthrottle_(false),
- pending_read_net_result_(0) {
+ pending_read_net_result_(0),
+ is_potentially_secure_plugin_context_(
+ host->IsPotentiallySecurePluginContext(instance)) {
DCHECK(host);
++g_num_instances;
host_->AddInstanceObserver(instance_, this);
@@ -110,7 +112,9 @@ PepperTCPSocketMessageFilter::PepperTCPSocketMessageFilter(
ssl_context_helper_(host->ssl_context_helper()),
pending_accept_(false),
pending_read_on_unthrottle_(false),
- pending_read_net_result_(0) {
+ pending_read_net_result_(0),
+ is_potentially_secure_plugin_context_(
+ host->IsPotentiallySecurePluginContext(instance)) {
DCHECK(host);
DCHECK_NE(version, ppapi::TCP_SOCKET_VERSION_1_0);
@@ -1054,7 +1058,7 @@ void PepperTCPSocketMessageFilter::SendConnectReply(
const PP_NetAddress_Private& local_addr,
const PP_NetAddress_Private& remote_addr) {
UMA_HISTOGRAM_BOOLEAN("Pepper.PluginContextSecurity.TCPConnect",
- host_->IsPotentiallySecurePluginContext(instance_));
+ is_potentially_secure_plugin_context_);
ppapi::host::ReplyMessageContext reply_context(context);
reply_context.params.set_result(pp_result);

Powered by Google App Engine
This is Rietveld 408576698