<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>175827</bug_id>
          
          <creation_ts>2017-08-22 10:24:43 -0700</creation_ts>
          <short_desc>Add sanity check for source origin in WebLoaderStrategy::startPingLoad()</short_desc>
          <delta_ts>2017-08-22 13:54:00 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>REOPENED</bug_status>
          <resolution></resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Chris Dumez">cdumez</reporter>
          <assigned_to name="Chris Dumez">cdumez</assigned_to>
          <cc>commit-queue</cc>
    
    <cc>ggaren</cc>
    
    <cc>ryanhaddad</cc>
    
    <cc>webkit-bug-importer</cc>
    
    <cc>youennf</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1341087</commentid>
    <comment_count>0</comment_count>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2017-08-22 10:24:43 -0700</bug_when>
    <thetext>Add sanity check for source origin in WebLoaderStrategy::startPingLoad().</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1341089</commentid>
    <comment_count>1</comment_count>
      <attachid>318762</attachid>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2017-08-22 10:26:10 -0700</bug_when>
    <thetext>Created attachment 318762
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1341091</commentid>
    <comment_count>2</comment_count>
      <attachid>318762</attachid>
    <who name="Geoffrey Garen">ggaren</who>
    <bug_when>2017-08-22 10:29:56 -0700</bug_when>
    <thetext>Comment on attachment 318762
Patch

r=me</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1341092</commentid>
    <comment_count>3</comment_count>
    <who name="youenn fablet">youennf</who>
    <bug_when>2017-08-22 10:31:25 -0700</bug_when>
    <thetext>Origin header might not always be there for same-origin requests.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1341093</commentid>
    <comment_count>4</comment_count>
      <attachid>318763</attachid>
    <who name="Chris Dumez">cdumez</who>
    <bug_when>2017-08-22 10:34:28 -0700</bug_when>
    <thetext>Created attachment 318763
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1341151</commentid>
    <comment_count>5</comment_count>
      <attachid>318763</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2017-08-22 11:16:43 -0700</bug_when>
    <thetext>Comment on attachment 318763
Patch

Clearing flags on attachment: 318763

Committed r221027: &lt;http://trac.webkit.org/changeset/221027&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1341152</commentid>
    <comment_count>6</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2017-08-22 11:16:45 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1341155</commentid>
    <comment_count>7</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2017-08-22 11:17:31 -0700</bug_when>
    <thetext>&lt;rdar://problem/34016866&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1341244</commentid>
    <comment_count>8</comment_count>
    <who name="Ryan Haddad">ryanhaddad</who>
    <bug_when>2017-08-22 13:53:24 -0700</bug_when>
    <thetext>Reverted r221027 for reason:

This change caused LayoutTests to exit early with assertion failures.

Committed r221043: &lt;http://trac.webkit.org/changeset/221043&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1341246</commentid>
    <comment_count>9</comment_count>
    <who name="Ryan Haddad">ryanhaddad</who>
    <bug_when>2017-08-22 13:54:00 -0700</bug_when>
    <thetext>(In reply to Ryan Haddad from comment #8)
&gt; Reverted r221027 for reason:
&gt; 
&gt; This change caused LayoutTests to exit early with assertion failures.
&gt; 
&gt; Committed r221043: &lt;http://trac.webkit.org/changeset/221043&gt;
Relevant link:
https://build.webkit.org/results/Apple%20Sierra%20Debug%20WK2%20(Tests)/r221029%20(2653)/results.html</thetext>
  </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>318762</attachid>
            <date>2017-08-22 10:26:10 -0700</date>
            <delta_ts>2017-08-22 10:34:27 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-175827-20170822102609.patch</filename>
            <type>text/plain</type>
            <size>2343</size>
            <attacher name="Chris Dumez">cdumez</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMjIxMDE3CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L0No
YW5nZUxvZyBiL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCmluZGV4IDg2MGViMzljNDgzZjI1ZTdm
ZDY0NGE5YzlkYWQzYTYwNGY1MTc5NmEuLmM1M2E5MzM0YjMzZTI1MTdhNzY0ZDk4MjlmNmYzZDll
NDE5OWRlYjkgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCisrKyBiL1NvdXJj
ZS9XZWJLaXQvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTMgQEAKKzIwMTctMDgtMjIgIENocmlzIER1
bWV6ICA8Y2R1bWV6QGFwcGxlLmNvbT4KKworICAgICAgICBBZGQgc2FuaXR5IGNoZWNrIGZvciBz
b3VyY2Ugb3JpZ2luIGluIFdlYkxvYWRlclN0cmF0ZWd5OjpzdGFydFBpbmdMb2FkKCkKKyAgICAg
ICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTE3NTgyNworCisgICAg
ICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgICogV2ViUHJvY2Vzcy9O
ZXR3b3JrL1dlYkxvYWRlclN0cmF0ZWd5LmNwcDoKKyAgICAgICAgKFdlYktpdDo6V2ViTG9hZGVy
U3RyYXRlZ3k6OnN0YXJ0UGluZ0xvYWQpOgorCiAyMDE3LTA4LTIyICBCcmVudCBGdWxnaGFtICA8
YmZ1bGdoYW1AYXBwbGUuY29tPiBhbmQgUHJhbmphbCBKdW1kZSAgPHBqdW1kZUBhcHBsZS5jb20+
CiAKICAgICAgICAgRGlzYWJsZSBhY2Nlc3MgdG8gc2VjdXJlIGNvb2tpZXMgaWYgYW4gSFRUUFMg
c2l0ZSBsb2FkcyBtaXhlZCBjb250ZW50CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L1dlYlBy
b2Nlc3MvTmV0d29yay9XZWJMb2FkZXJTdHJhdGVneS5jcHAgYi9Tb3VyY2UvV2ViS2l0L1dlYlBy
b2Nlc3MvTmV0d29yay9XZWJMb2FkZXJTdHJhdGVneS5jcHAKaW5kZXggMWYwYTIxM2MyYzAwYzI3
YzkwMGVhYWMyOGZjYzg5ZGYwN2QzZGQ4MS4uN2U5MGJhMzk5NWFmNGMzNzI4NDhkOTVkMzU2YTYx
ZjE1MDc3MTRmMCAxMDA2NDQKLS0tIGEvU291cmNlL1dlYktpdC9XZWJQcm9jZXNzL05ldHdvcmsv
V2ViTG9hZGVyU3RyYXRlZ3kuY3BwCisrKyBiL1NvdXJjZS9XZWJLaXQvV2ViUHJvY2Vzcy9OZXR3
b3JrL1dlYkxvYWRlclN0cmF0ZWd5LmNwcApAQCAtNDI1LDEzICs0MjUsMTQgQEAgdm9pZCBXZWJM
b2FkZXJTdHJhdGVneTo6c3RhcnRQaW5nTG9hZChGcmFtZSYgZnJhbWUsIFJlc291cmNlUmVxdWVz
dCYgcmVxdWVzdCwgY28KICAgICBsb2FkUGFyYW1ldGVycy5pZGVudGlmaWVyID0gZ2VuZXJhdGVQ
aW5nTG9hZElkZW50aWZpZXIoKTsKICAgICBsb2FkUGFyYW1ldGVycy5yZXF1ZXN0ID0gcmVxdWVz
dDsKICAgICBsb2FkUGFyYW1ldGVycy5zb3VyY2VPcmlnaW4gPSAmZG9jdW1lbnQtPnNlY3VyaXR5
T3JpZ2luKCk7CisgICAgQVNTRVJUKGxvYWRQYXJhbWV0ZXJzLnJlcXVlc3QuaHR0cEhlYWRlckZp
ZWxkKEhUVFBIZWFkZXJOYW1lOjpPcmlnaW4pID09IGxvYWRQYXJhbWV0ZXJzLnNvdXJjZU9yaWdp
bi0+dG9TdHJpbmcoKSk7CiAgICAgbG9hZFBhcmFtZXRlcnMuc2Vzc2lvbklEID0gd2ViUGFnZSA/
IHdlYlBhZ2UtPnNlc3Npb25JRCgpIDogUEFMOjpTZXNzaW9uSUQ6OmRlZmF1bHRTZXNzaW9uSUQo
KTsKICAgICBsb2FkUGFyYW1ldGVycy5hbGxvd1N0b3JlZENyZWRlbnRpYWxzID0gb3B0aW9ucy5j
cmVkZW50aWFscyA9PSBGZXRjaE9wdGlvbnM6OkNyZWRlbnRpYWxzOjpPbWl0ID8gRG9Ob3RBbGxv
d1N0b3JlZENyZWRlbnRpYWxzIDogQWxsb3dTdG9yZWRDcmVkZW50aWFsczsKICAgICBsb2FkUGFy
YW1ldGVycy5tb2RlID0gb3B0aW9ucy5tb2RlOwogICAgIGxvYWRQYXJhbWV0ZXJzLnNob3VsZEZv
bGxvd1JlZGlyZWN0cyA9IG9wdGlvbnMucmVkaXJlY3QgPT0gRmV0Y2hPcHRpb25zOjpSZWRpcmVj
dDo6Rm9sbG93OwogICAgIGxvYWRQYXJhbWV0ZXJzLnNob3VsZENsZWFyUmVmZXJyZXJPbkhUVFBT
VG9IVFRQUmVkaXJlY3QgPSBuZXR3b3JraW5nQ29udGV4dC0+c2hvdWxkQ2xlYXJSZWZlcnJlck9u
SFRUUFNUb0hUVFBSZWRpcmVjdCgpOwogICAgIGlmICghZG9jdW1lbnQtPnNob3VsZEJ5cGFzc01h
aW5Xb3JsZENvbnRlbnRTZWN1cml0eVBvbGljeSgpKSB7Ci0gICAgICAgIGlmIChhdXRvICogY29u
dGVudFNlY3VyaXR5UG9saWN5ID0gZG9jdW1lbnQtPmNvbnRlbnRTZWN1cml0eVBvbGljeSgpKQor
ICAgICAgICBpZiAoYXV0byogY29udGVudFNlY3VyaXR5UG9saWN5ID0gZG9jdW1lbnQtPmNvbnRl
bnRTZWN1cml0eVBvbGljeSgpKQogICAgICAgICAgICAgbG9hZFBhcmFtZXRlcnMuY3NwUmVzcG9u
c2VIZWFkZXJzID0gY29udGVudFNlY3VyaXR5UG9saWN5LT5yZXNwb25zZUhlYWRlcnMoKTsKICAg
ICB9CiAK
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>318763</attachid>
            <date>2017-08-22 10:34:28 -0700</date>
            <delta_ts>2017-08-22 11:16:43 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-175827-20170822103427.patch</filename>
            <type>text/plain</type>
            <size>2418</size>
            <attacher name="Chris Dumez">cdumez</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMjIxMDE3CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L0No
YW5nZUxvZyBiL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCmluZGV4IDg2MGViMzljNDgzZjI1ZTdm
ZDY0NGE5YzlkYWQzYTYwNGY1MTc5NmEuLjc1OGFlMDA0MjIwZTg3ZGZlYTRjZGRjNjc3YWUzNWZk
M2E2ZGNmYTAgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCisrKyBiL1NvdXJj
ZS9XZWJLaXQvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTMgQEAKKzIwMTctMDgtMjIgIENocmlzIER1
bWV6ICA8Y2R1bWV6QGFwcGxlLmNvbT4KKworICAgICAgICBBZGQgc2FuaXR5IGNoZWNrIGZvciBz
b3VyY2Ugb3JpZ2luIGluIFdlYkxvYWRlclN0cmF0ZWd5OjpzdGFydFBpbmdMb2FkKCkKKyAgICAg
ICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTE3NTgyNworCisgICAg
ICAgIFJldmlld2VkIGJ5IEdlb2ZmcmV5IEdhcmVuLgorCisgICAgICAgICogV2ViUHJvY2Vzcy9O
ZXR3b3JrL1dlYkxvYWRlclN0cmF0ZWd5LmNwcDoKKyAgICAgICAgKFdlYktpdDo6V2ViTG9hZGVy
U3RyYXRlZ3k6OnN0YXJ0UGluZ0xvYWQpOgorCiAyMDE3LTA4LTIyICBCcmVudCBGdWxnaGFtICA8
YmZ1bGdoYW1AYXBwbGUuY29tPiBhbmQgUHJhbmphbCBKdW1kZSAgPHBqdW1kZUBhcHBsZS5jb20+
CiAKICAgICAgICAgRGlzYWJsZSBhY2Nlc3MgdG8gc2VjdXJlIGNvb2tpZXMgaWYgYW4gSFRUUFMg
c2l0ZSBsb2FkcyBtaXhlZCBjb250ZW50CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L1dlYlBy
b2Nlc3MvTmV0d29yay9XZWJMb2FkZXJTdHJhdGVneS5jcHAgYi9Tb3VyY2UvV2ViS2l0L1dlYlBy
b2Nlc3MvTmV0d29yay9XZWJMb2FkZXJTdHJhdGVneS5jcHAKaW5kZXggMWYwYTIxM2MyYzAwYzI3
YzkwMGVhYWMyOGZjYzg5ZGYwN2QzZGQ4MS4uNWIwY2MxODdlNTE4YmJmYmE3NjQyMWU4MjM2MTY4
NjI3NjlkMDYzMiAxMDA2NDQKLS0tIGEvU291cmNlL1dlYktpdC9XZWJQcm9jZXNzL05ldHdvcmsv
V2ViTG9hZGVyU3RyYXRlZ3kuY3BwCisrKyBiL1NvdXJjZS9XZWJLaXQvV2ViUHJvY2Vzcy9OZXR3
b3JrL1dlYkxvYWRlclN0cmF0ZWd5LmNwcApAQCAtNDI1LDEzICs0MjUsMTQgQEAgdm9pZCBXZWJM
b2FkZXJTdHJhdGVneTo6c3RhcnRQaW5nTG9hZChGcmFtZSYgZnJhbWUsIFJlc291cmNlUmVxdWVz
dCYgcmVxdWVzdCwgY28KICAgICBsb2FkUGFyYW1ldGVycy5pZGVudGlmaWVyID0gZ2VuZXJhdGVQ
aW5nTG9hZElkZW50aWZpZXIoKTsKICAgICBsb2FkUGFyYW1ldGVycy5yZXF1ZXN0ID0gcmVxdWVz
dDsKICAgICBsb2FkUGFyYW1ldGVycy5zb3VyY2VPcmlnaW4gPSAmZG9jdW1lbnQtPnNlY3VyaXR5
T3JpZ2luKCk7CisgICAgQVNTRVJUKGxvYWRQYXJhbWV0ZXJzLnJlcXVlc3QuaHR0cEhlYWRlckZp
ZWxkKEhUVFBIZWFkZXJOYW1lOjpPcmlnaW4pLmlzTnVsbCgpIHx8IGxvYWRQYXJhbWV0ZXJzLnJl
cXVlc3QuaHR0cEhlYWRlckZpZWxkKEhUVFBIZWFkZXJOYW1lOjpPcmlnaW4pID09IGxvYWRQYXJh
bWV0ZXJzLnNvdXJjZU9yaWdpbi0+dG9TdHJpbmcoKSk7CiAgICAgbG9hZFBhcmFtZXRlcnMuc2Vz
c2lvbklEID0gd2ViUGFnZSA/IHdlYlBhZ2UtPnNlc3Npb25JRCgpIDogUEFMOjpTZXNzaW9uSUQ6
OmRlZmF1bHRTZXNzaW9uSUQoKTsKICAgICBsb2FkUGFyYW1ldGVycy5hbGxvd1N0b3JlZENyZWRl
bnRpYWxzID0gb3B0aW9ucy5jcmVkZW50aWFscyA9PSBGZXRjaE9wdGlvbnM6OkNyZWRlbnRpYWxz
OjpPbWl0ID8gRG9Ob3RBbGxvd1N0b3JlZENyZWRlbnRpYWxzIDogQWxsb3dTdG9yZWRDcmVkZW50
aWFsczsKICAgICBsb2FkUGFyYW1ldGVycy5tb2RlID0gb3B0aW9ucy5tb2RlOwogICAgIGxvYWRQ
YXJhbWV0ZXJzLnNob3VsZEZvbGxvd1JlZGlyZWN0cyA9IG9wdGlvbnMucmVkaXJlY3QgPT0gRmV0
Y2hPcHRpb25zOjpSZWRpcmVjdDo6Rm9sbG93OwogICAgIGxvYWRQYXJhbWV0ZXJzLnNob3VsZENs
ZWFyUmVmZXJyZXJPbkhUVFBTVG9IVFRQUmVkaXJlY3QgPSBuZXR3b3JraW5nQ29udGV4dC0+c2hv
dWxkQ2xlYXJSZWZlcnJlck9uSFRUUFNUb0hUVFBSZWRpcmVjdCgpOwogICAgIGlmICghZG9jdW1l
bnQtPnNob3VsZEJ5cGFzc01haW5Xb3JsZENvbnRlbnRTZWN1cml0eVBvbGljeSgpKSB7Ci0gICAg
ICAgIGlmIChhdXRvICogY29udGVudFNlY3VyaXR5UG9saWN5ID0gZG9jdW1lbnQtPmNvbnRlbnRT
ZWN1cml0eVBvbGljeSgpKQorICAgICAgICBpZiAoYXV0byogY29udGVudFNlY3VyaXR5UG9saWN5
ID0gZG9jdW1lbnQtPmNvbnRlbnRTZWN1cml0eVBvbGljeSgpKQogICAgICAgICAgICAgbG9hZFBh
cmFtZXRlcnMuY3NwUmVzcG9uc2VIZWFkZXJzID0gY29udGVudFNlY3VyaXR5UG9saWN5LT5yZXNw
b25zZUhlYWRlcnMoKTsKICAgICB9CiAK
</data>

          </attachment>
      

    </bug>

</bugzilla>