Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(169)

Issue 1960983002: Kill renderer if it changes the main frame's origin on subframe commits. (Closed)

Created:
4 years, 7 months ago by Charlie Reis
Modified:
4 years, 7 months ago
Reviewers:
ncarter (slow)
CC:
chromium-reviews, darin-cc_chromium.org, nasko+codewatch_chromium.org, jam, creis+watch_chromium.org, site-isolation-reviews_chromium.org
Base URL:
https://chromium.googlesource.com/chromium/src.git@master
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

Kill renderer if it changes the main frame's origin on subframe commits. This is hopefully safe after the fix for 597322. It's a useful second line of defense against URL spoofs. BUG=486916, 597322 TEST=No NC_AUTO_SUBFRAME kills CQ_INCLUDE_TRYBOTS=tryserver.chromium.linux:linux_site_isolation Committed: https://crrev.com/fb6eeb6dde866fbe9b48b62311eb6cc48771fc70 Cr-Commit-Position: refs/heads/master@{#392666}

Patch Set 1 #

Unified diffs Side-by-side diffs Delta from patch set Stats (+2 lines, -5 lines) Patch
M content/browser/frame_host/navigation_controller_impl.cc View 1 chunk +2 lines, -5 lines 0 comments Download

Messages

Total messages: 9 (4 generated)
Charlie Reis
This restores the renderer kill we had before, to try to prevent URL spoofs after ...
4 years, 7 months ago (2016-05-09 17:32:10 UTC) #3
ncarter (slow)
lgtm If you wait a couple days, I ought to have the magic_signature/DumpWithoutCrashing stuff landed, ...
4 years, 7 months ago (2016-05-09 19:06:33 UTC) #4
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/patch-status/1960983002/1 View timeline at https://chromium-cq-status.appspot.com/patch-timeline/1960983002/1
4 years, 7 months ago (2016-05-10 17:37:46 UTC) #6
commit-bot: I haz the power
Committed patchset #1 (id:1)
4 years, 7 months ago (2016-05-10 19:02:04 UTC) #7
commit-bot: I haz the power
4 years, 7 months ago (2016-05-10 19:04:35 UTC) #9
Message was sent while issue was closed.
Patchset 1 (id:??) landed as
https://crrev.com/fb6eeb6dde866fbe9b48b62311eb6cc48771fc70
Cr-Commit-Position: refs/heads/master@{#392666}

Powered by Google App Engine
This is Rietveld 408576698