Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(7)

Issue 2124373002: [PPAPI] Quarantine files that are writeable by a Pepper plugin. (Closed)

Created:
4 years, 5 months ago by asanka
Modified:
4 years ago
CC:
chromium-reviews, darin-cc_chromium.org, jam
Base URL:
https://chromium.googlesource.com/chromium/src.git@consolidate-file-metadata
Target Ref:
refs/pending/heads/master
Project:
chromium
Visibility:
Public.

Description

[PPAPI] Quarantine files that are writeable by a Pepper plugin. Henceforth Chrome will treat files that were writeable by a Pepper plugin the same way it treats files that were downloaded from the origin of the plugin. This new behavior is limited to Windows and Linux. On Mac OS X, quarantining a file interferes with subsequent opening by a plugin. PPAPI's file write support currently relies on being able to do so. This CL makes the following changes: * Move quarantine* files into //content/public/common and //content/common. This logic now needs to be accessed from both //content and //chrome. * When a PPAPI plug-in attempts to open a file for writing, //content quarantines the file prior to allowing the plug-in to write to it. BUG=598812 Committed: https://crrev.com/c1ab0290967226e37abb9537f0f53f1616f5fb70 Cr-Commit-Position: refs/heads/master@{#437359}

Patch Set 1 #

Patch Set 2 : . #

Patch Set 3 : . #

Total comments: 2

Patch Set 4 : Add a comment explaining MOTW #

Patch Set 5 : . #

Patch Set 6 : Rebase + test contents of Zone.Identifier stream. #

Patch Set 7 : Fix win_clang build #

Patch Set 8 : . #

Patch Set 9 : More tests and refactoring. #

Patch Set 10 : . #

Patch Set 11 : Resurrect with better test support #

Patch Set 12 : . #

Total comments: 5

Patch Set 13 : Move quarantine_* files to content/common/quarantine/ #

Total comments: 4

Patch Set 14 : Address comments. #

Unified diffs Side-by-side diffs Delta from patch set Stats (+430 lines, -1586 lines) Patch
M base/test/test_file_util.h View 1 2 3 4 5 6 7 8 1 chunk +0 lines, -9 lines 0 comments Download
M base/test/test_file_util_win.cc View 1 2 3 4 5 6 7 8 1 chunk +0 lines, -43 lines 0 comments Download
M chrome/browser/download/download_browsertest.cc View 1 2 3 4 5 6 7 8 9 10 11 12 13 5 chunks +19 lines, -8 lines 0 comments Download
M chrome/test/ppapi/ppapi_filechooser_browsertest.cc View 1 2 3 4 5 6 7 8 2 chunks +29 lines, -0 lines 0 comments Download
M content/browser/BUILD.gn View 1 2 3 4 5 6 7 8 9 10 11 12 13 1 chunk +0 lines, -6 lines 0 comments Download
M content/browser/download/base_file.cc View 1 2 3 4 5 6 7 8 1 chunk +1 line, -1 line 0 comments Download
D content/browser/download/quarantine.h View 1 2 3 4 5 6 7 8 1 chunk +0 lines, -83 lines 0 comments Download
D content/browser/download/quarantine.cc View 1 2 3 4 5 6 7 8 1 chunk +0 lines, -22 lines 0 comments Download
D content/browser/download/quarantine_constants_linux.h View 1 2 3 4 5 6 7 8 1 chunk +0 lines, -23 lines 0 comments Download
D content/browser/download/quarantine_linux.cc View 1 2 3 4 5 6 7 8 1 chunk +0 lines, -66 lines 0 comments Download
M content/browser/download/quarantine_linux_unittest.cc View 1 2 3 4 5 6 7 8 1 chunk +0 lines, -180 lines 0 comments Download
D content/browser/download/quarantine_mac.mm View 1 2 3 4 5 6 7 8 1 chunk +0 lines, -304 lines 0 comments Download
D content/browser/download/quarantine_mac_unittest.mm View 1 2 3 4 5 6 7 8 1 chunk +0 lines, -108 lines 0 comments Download
D content/browser/download/quarantine_win.cc View 1 2 3 4 5 6 7 8 1 chunk +0 lines, -336 lines 0 comments Download
D content/browser/download/quarantine_win_unittest.cc View 1 2 3 4 5 6 7 8 1 chunk +0 lines, -265 lines 0 comments Download
M content/browser/renderer_host/pepper/pepper_file_io_host.h View 1 2 3 4 5 6 7 8 2 chunks +11 lines, -2 lines 0 comments Download
M content/browser/renderer_host/pepper/pepper_file_io_host.cc View 1 2 3 4 5 6 7 8 6 chunks +47 lines, -10 lines 0 comments Download
M content/common/BUILD.gn View 1 2 3 4 5 6 7 8 9 10 11 12 13 1 chunk +5 lines, -0 lines 0 comments Download
A + content/common/quarantine/quarantine.cc View 1 2 3 4 5 6 7 8 9 10 11 12 2 chunks +9 lines, -3 lines 0 comments Download
A + content/common/quarantine/quarantine_constants_linux.h View 1 2 3 4 5 6 7 8 9 10 11 12 2 chunks +3 lines, -3 lines 0 comments Download
A + content/common/quarantine/quarantine_linux.cc View 1 2 3 4 5 6 7 8 9 10 11 12 4 chunks +35 lines, -2 lines 0 comments Download
A + content/common/quarantine/quarantine_linux_unittest.cc View 1 2 3 4 5 6 7 8 9 10 11 12 9 chunks +47 lines, -44 lines 0 comments Download
A + content/common/quarantine/quarantine_mac.mm View 1 2 3 4 5 6 7 8 9 10 11 12 7 chunks +55 lines, -12 lines 0 comments Download
A + content/common/quarantine/quarantine_mac_unittest.mm View 1 2 3 4 5 6 7 8 9 10 11 12 4 chunks +53 lines, -36 lines 0 comments Download
A content/common/quarantine/quarantine_unittest.cc View 1 2 3 4 5 6 7 8 9 10 11 12 1 chunk +58 lines, -0 lines 0 comments Download
A + content/common/quarantine/quarantine_win.cc View 1 2 3 4 5 6 7 8 9 10 11 12 13 5 chunks +24 lines, -9 lines 0 comments Download
A + content/common/quarantine/quarantine_win_unittest.cc View 1 2 3 4 5 6 7 8 9 10 11 12 2 chunks +3 lines, -5 lines 0 comments Download
M content/public/common/BUILD.gn View 1 2 3 4 5 6 7 8 9 10 11 12 1 chunk +1 line, -0 lines 0 comments Download
A + content/public/common/quarantine.h View 1 2 3 4 5 6 7 8 9 10 11 12 13 2 chunks +26 lines, -3 lines 0 comments Download
M content/test/BUILD.gn View 1 2 3 4 5 6 7 8 9 10 11 12 13 2 chunks +4 lines, -3 lines 0 comments Download

Messages

Total messages: 79 (58 generated)
asanka
bbudge: PTAL?
4 years, 5 months ago (2016-07-08 19:26:35 UTC) #3
bbudge
One comment, otherwise LGTM https://codereview.chromium.org/2124373002/diff/40001/chrome/test/ppapi/ppapi_filechooser_browsertest.cc File chrome/test/ppapi/ppapi_filechooser_browsertest.cc (right): https://codereview.chromium.org/2124373002/diff/40001/chrome/test/ppapi/ppapi_filechooser_browsertest.cc#newcode356 chrome/test/ppapi/ppapi_filechooser_browsertest.cc:356: #if defined(OS_WIN) Could you add ...
4 years, 5 months ago (2016-07-11 20:08:23 UTC) #4
asanka
Thanks! https://codereview.chromium.org/2124373002/diff/40001/chrome/test/ppapi/ppapi_filechooser_browsertest.cc File chrome/test/ppapi/ppapi_filechooser_browsertest.cc (right): https://codereview.chromium.org/2124373002/diff/40001/chrome/test/ppapi/ppapi_filechooser_browsertest.cc#newcode356 chrome/test/ppapi/ppapi_filechooser_browsertest.cc:356: #if defined(OS_WIN) On 2016/07/11 at 20:08:22, bbudge wrote: ...
4 years, 3 months ago (2016-09-12 16:07:04 UTC) #5
asanka
Resurrect with better test support
4 years ago (2016-12-02 14:56:27 UTC) #37
asanka
bbudge: Thanks for your review! Resurrecting this old CL. brettw: base/test/test_file_util* content/common/quarantine_win.cc content/common/quarantine_win_unittest.cc I'm moving ...
4 years ago (2016-12-02 19:23:01 UTC) #47
Avi (use Gerrit)
lgtm https://codereview.chromium.org/2124373002/diff/280001/chrome/browser/download/download_browsertest.cc File chrome/browser/download/download_browsertest.cc (right): https://codereview.chromium.org/2124373002/diff/280001/chrome/browser/download/download_browsertest.cc#newcode1184 chrome/browser/download/download_browsertest.cc:1184: // |browser_tests| aren't run from a process that ...
4 years ago (2016-12-02 19:58:27 UTC) #48
jochen (gone - plz use gerrit)
Can you move the quarantine files into a subdirectory in common (either common/download as the ...
4 years ago (2016-12-05 15:31:04 UTC) #49
asanka
Thanks! jochen: I moved quarantine_* files to //content/common/quarantine brettw: Ping https://codereview.chromium.org/2124373002/diff/280001/chrome/browser/download/download_browsertest.cc File chrome/browser/download/download_browsertest.cc (right): https://codereview.chromium.org/2124373002/diff/280001/chrome/browser/download/download_browsertest.cc#newcode1184 ...
4 years ago (2016-12-06 20:34:36 UTC) #52
brettw
I still need to look at pepper_file_io_host but I need more time to page in ...
4 years ago (2016-12-06 22:48:42 UTC) #55
brettw
lgtm
4 years ago (2016-12-07 00:11:11 UTC) #56
jochen (gone - plz use gerrit)
rubberstamp lgtm now that Brett approved
4 years ago (2016-12-07 15:34:20 UTC) #57
asanka
Thanks everyone! https://codereview.chromium.org/2124373002/diff/280001/chrome/browser/download/download_browsertest.cc File chrome/browser/download/download_browsertest.cc (right): https://codereview.chromium.org/2124373002/diff/280001/chrome/browser/download/download_browsertest.cc#newcode1204 chrome/browser/download/download_browsertest.cc:1204: // restrictions on MOTW can be applied. ...
4 years ago (2016-12-08 15:13:29 UTC) #60
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2124373002/320001
4 years ago (2016-12-08 15:49:12 UTC) #63
commit-bot: I haz the power
Try jobs failed on following builders: android_n5x_swarming_rel on master.tryserver.chromium.android (JOB_FAILED, https://build.chromium.org/p/tryserver.chromium.android/builders/android_n5x_swarming_rel/builds/82323)
4 years ago (2016-12-08 16:37:05 UTC) #65
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2124373002/320001
4 years ago (2016-12-08 16:54:38 UTC) #67
commit-bot: I haz the power
Try jobs failed on following builders: android_n5x_swarming_rel on master.tryserver.chromium.android (JOB_FAILED, https://build.chromium.org/p/tryserver.chromium.android/builders/android_n5x_swarming_rel/builds/82379)
4 years ago (2016-12-08 18:21:57 UTC) #69
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2124373002/320001
4 years ago (2016-12-08 18:45:09 UTC) #71
commit-bot: I haz the power
Try jobs failed on following builders: android_n5x_swarming_rel on master.tryserver.chromium.android (JOB_FAILED, https://build.chromium.org/p/tryserver.chromium.android/builders/android_n5x_swarming_rel/builds/82609)
4 years ago (2016-12-08 20:53:40 UTC) #73
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2124373002/320001
4 years ago (2016-12-08 21:12:09 UTC) #75
commit-bot: I haz the power
Committed patchset #14 (id:320001)
4 years ago (2016-12-08 21:54:07 UTC) #77
commit-bot: I haz the power
4 years ago (2016-12-08 21:56:59 UTC) #79
Message was sent while issue was closed.
Patchset 14 (id:??) landed as
https://crrev.com/c1ab0290967226e37abb9537f0f53f1616f5fb70
Cr-Commit-Position: refs/heads/master@{#437359}

Powered by Google App Engine
This is Rietveld 408576698