Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(183)

Issue 2955573003: Set frame policy correctly in newly created renderer proxies (Closed)

Created:
3 years, 6 months ago by iclelland
Modified:
3 years, 5 months ago
CC:
chromium-reviews, creis+watch_chromium.org, darin-cc_chromium.org, jam, nasko+codewatch_chromium.org, site-isolation-reviews_chromium.org
Target Ref:
refs/heads/master
Project:
chromium
Visibility:
Public.

Description

Set frame policy correctly in newly created renderer proxies Previously, the initial frame policies (sandbox flags and container policy) were being set only in the browser, after the RenderFrameHost and any associated proxies were created, and were not being subsequently replicated to those proxies afterwards. This caused the feature policies constructed in remote frames to be incorrect. Separately, container policies were not being replicated correctly to provisional render frames, so a frame which performed a cross-site navigation to an existing site instance would have the wrong policy after the navigation was committed. This patch fixes both of those issues, and reinstates the disabled tests on the site-isolation trybots. BUG=716085, 718160 CQ_INCLUDE_TRYBOTS=master.tryserver.chromium.linux:linux_site_isolation Review-Url: https://codereview.chromium.org/2955573003 Cr-Commit-Position: refs/heads/master@{#482968} Committed: https://chromium.googlesource.com/chromium/src/+/098da75cd0415c2e21a7ee78e47a75abdfabf461

Patch Set 1 #

Total comments: 4

Patch Set 2 : Reinstate failing FP tests #

Patch Set 3 : Reorder logic, add comment #

Patch Set 4 : Stop using invalid pointer so much #

Patch Set 5 : Fix container policy replication bug in provisional frames #

Unified diffs Side-by-side diffs Delta from patch set Stats (+33 lines, -32 lines) Patch
M content/browser/frame_host/frame_tree.cc View 1 2 3 2 chunks +17 lines, -14 lines 0 comments Download
M content/renderer/render_frame_impl.cc View 1 2 3 4 1 chunk +2 lines, -1 line 0 comments Download
M third_party/WebKit/LayoutTests/FlagExpectations/site-per-process View 1 1 chunk +0 lines, -10 lines 0 comments Download
M third_party/WebKit/Source/core/frame/FrameTestHelpers.cpp View 1 2 3 4 1 chunk +1 line, -1 line 0 comments Download
M third_party/WebKit/Source/web/WebLocalFrameImpl.h View 1 2 3 4 1 chunk +2 lines, -1 line 0 comments Download
M third_party/WebKit/Source/web/WebLocalFrameImpl.cpp View 1 2 3 4 3 chunks +9 lines, -4 lines 0 comments Download
M third_party/WebKit/public/web/WebLocalFrame.h View 1 2 3 4 1 chunk +2 lines, -1 line 0 comments Download

Dependent Patchsets:

Messages

Total messages: 37 (27 generated)
iclelland
+r alexmos -- this needs tests, but there currently isn't a way to query the ...
3 years, 6 months ago (2017-06-23 17:18:47 UTC) #6
alexmos
+site-isolation-reviews Thanks for fixing this! The fix looks good; a couple of suggestions below. For ...
3 years, 6 months ago (2017-06-23 18:23:55 UTC) #9
iclelland
https://codereview.chromium.org/2955573003/diff/1/content/browser/frame_host/frame_tree.cc File content/browser/frame_host/frame_tree.cc (right): https://codereview.chromium.org/2955573003/diff/1/content/browser/frame_host/frame_tree.cc#newcode202 content/browser/frame_host/frame_tree.cc:202: last_committed_entry->ClearStaleFrameEntriesForNewFrame(new_node.get()); On 2017/06/23 18:23:55, alexmos wrote: > Hmm, ClearStaleFrameEntriesForNewFrame ...
3 years, 6 months ago (2017-06-24 03:57:44 UTC) #14
iclelland
alexmos -- can you PTAL again? Thanks! (The issue you raised in https://bugs.chromium.org/p/chromium/issues/detail?id=716085#c35 was also ...
3 years, 5 months ago (2017-06-27 20:31:41 UTC) #24
alexmos
LGTM
3 years, 5 months ago (2017-06-27 20:59:07 UTC) #25
iclelland
+r pfeldman -- can you PTAL as OWNER in WebKit/* ? Thanks!
3 years, 5 months ago (2017-06-27 22:58:07 UTC) #29
iclelland
n/m, pfeldman is OOO for another week or so -- jochen, do you mind taking ...
3 years, 5 months ago (2017-06-28 03:45:44 UTC) #31
jochen (gone - plz use gerrit)
lgtm
3 years, 5 months ago (2017-06-28 07:39:19 UTC) #32
commit-bot: I haz the power
CQ is trying da patch. Follow status at: https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2955573003/80001
3 years, 5 months ago (2017-06-28 13:42:08 UTC) #34
commit-bot: I haz the power
3 years, 5 months ago (2017-06-28 13:47:11 UTC) #37
Message was sent while issue was closed.
Committed patchset #5 (id:80001) as
https://chromium.googlesource.com/chromium/src/+/098da75cd0415c2e21a7ee78e47a...

Powered by Google App Engine
This is Rietveld 408576698