Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(886)

Unified Diff: content/browser/web_contents/web_contents_impl.cc

Issue 92873004: Prevent the browser process from creating duplicate RenderViewHosts. (Closed) Base URL: svn://svn.chromium.org/chrome/trunk/src
Patch Set: Cleanup. Created 7 years ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « content/browser/web_contents/web_contents_impl.h ('k') | content/test/test_web_contents.h » ('j') | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: content/browser/web_contents/web_contents_impl.cc
diff --git a/content/browser/web_contents/web_contents_impl.cc b/content/browser/web_contents/web_contents_impl.cc
index e05cab0f097872512e1ae9eee65624193aa7bcf7..be495ef46912c484a012a7a5b4202df1b89f195d 100644
--- a/content/browser/web_contents/web_contents_impl.cc
+++ b/content/browser/web_contents/web_contents_impl.cc
@@ -12,6 +12,7 @@
#include "base/logging.h"
#include "base/metrics/histogram.h"
#include "base/metrics/stats_counters.h"
+#include "base/process/process.h"
#include "base/strings/string16.h"
#include "base/strings/string_number_conversions.h"
#include "base/strings/string_util.h"
@@ -73,6 +74,7 @@
#include "content/public/common/content_constants.h"
#include "content/public/common/content_switches.h"
#include "content/public/common/page_zoom.h"
+#include "content/public/common/result_codes.h"
#include "content/public/common/url_constants.h"
#include "net/base/mime_util.h"
#include "net/base/net_util.h"
@@ -1252,6 +1254,7 @@ void WebContentsImpl::LostMouseLock() {
}
void WebContentsImpl::CreateNewWindow(
+ int render_process_id,
int route_id,
int main_frame_route_id,
const ViewHostMsg_CreateWindow_Params& params,
@@ -1262,11 +1265,30 @@ void WebContentsImpl::CreateNewWindow(
// SiteInstance in its own BrowsingInstance.
bool is_guest = GetRenderProcessHost()->IsGuest();
+ // If the opener is to be suppressed, the new window can be in any process.
+ // Since routing ids are process specific, we must not have one passed in
+ // as argument here.
+ DCHECK(!params.opener_suppressed || route_id == MSG_ROUTING_NONE);
+
scoped_refptr<SiteInstance> site_instance =
params.opener_suppressed && !is_guest ?
SiteInstance::CreateForURL(GetBrowserContext(), params.target_url) :
GetSiteInstance();
+ // A message to create a new window can only come from the active process for
+ // this WebContentsImpl instance. If any other process sends the request,
+ // it is invalid and the process must be terminated.
+ if (GetRenderProcessHost()->GetID() != render_process_id) {
+ base::ProcessHandle process_handle =
+ RenderProcessHost::FromID(render_process_id)->GetHandle();
+ if (process_handle != base::kNullProcessHandle) {
+ RecordAction(
+ UserMetricsAction("Terminate_ProcessMismatch_CreateNewWindow"));
+ base::KillProcess(process_handle, content::RESULT_CODE_KILLED, false);
+ }
+ return;
+ }
+
// We must assign the SessionStorageNamespace before calling Init().
//
// http://crbug.com/142685
« no previous file with comments | « content/browser/web_contents/web_contents_impl.h ('k') | content/test/test_web_contents.h » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698