<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>197844</bug_id>
          
          <creation_ts>2019-05-13 10:11:12 -0700</creation_ts>
          <short_desc>Correct the sandbox to allow loading libraries from /Library/Apple</short_desc>
          <delta_ts>2019-05-13 12:53:51 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Brent Fulgham">bfulgham</reporter>
          <assigned_to name="Brent Fulgham">bfulgham</assigned_to>
          <cc>ap</cc>
    
    <cc>bfulgham</cc>
    
    <cc>bshafiei</cc>
    
    <cc>commit-queue</cc>
    
    <cc>pvollan</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1535655</commentid>
    <comment_count>0</comment_count>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2019-05-13 10:11:12 -0700</bug_when>
    <thetext>Some InjectedBundles need to load libraries from &quot;/Library/Apple&quot;, which is not allowed by default. Revise the sandbox to support this additional location for frameworks.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1535656</commentid>
    <comment_count>1</comment_count>
      <attachid>369744</attachid>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2019-05-13 10:13:11 -0700</bug_when>
    <thetext>Created attachment 369744
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1535657</commentid>
    <comment_count>2</comment_count>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2019-05-13 10:17:17 -0700</bug_when>
    <thetext>&lt;rdar://problem/50727815&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1535660</commentid>
    <comment_count>3</comment_count>
      <attachid>369744</attachid>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2019-05-13 10:27:46 -0700</bug_when>
    <thetext>Comment on attachment 369744
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=369744&amp;action=review

R=me.

&gt; Source/WebKit/WebProcess/com.apple.WebProcess.sb.in:43
&gt;  (allow file-read*
&gt;      (require-all (file-mode #o0004)
&gt;      (require-any (subpath &quot;/Library/Filesystems/NetFSPlugins&quot;)
&gt; +    (subpath &quot;/Library/Apple/System&quot;)

Is this only needed for the injected bundle? If that is the case, maybe we could issue an extension? I don&apos;t think this is required now, and could be done in a followup patch.

&gt; Source/WebKit/WebProcess/com.apple.WebProcess.sb.in:63
&gt; +;;; Allow mapping of system frameworks + dylibs
&gt; +(allow file-map-executable
&gt; +    (subpath &quot;/Library/Apple/System/Library/Frameworks&quot;)
&gt; +    (subpath &quot;/Library/Apple/System/Library/PrivateFrameworks&quot;)
&gt; +    (subpath &quot;/System/Library/Frameworks&quot;)
&gt; +    (subpath &quot;/System/Library/PrivateFrameworks&quot;)
&gt; +    (subpath &quot;/usr/lib&quot;)

Ditto.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1535670</commentid>
    <comment_count>4</comment_count>
      <attachid>369744</attachid>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2019-05-13 10:44:47 -0700</bug_when>
    <thetext>Comment on attachment 369744
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=369744&amp;action=review

&gt;&gt; Source/WebKit/WebProcess/com.apple.WebProcess.sb.in:43
&gt;&gt; +    (subpath &quot;/Library/Apple/System&quot;)
&gt; 
&gt; Is this only needed for the injected bundle? If that is the case, maybe we could issue an extension? I don&apos;t think this is required now, and could be done in a followup patch.

After reviewing things further, I think we should just treat this as another canonical location where system frameworks might live. It&apos;s not specific to injected bundles.

&gt;&gt; Source/WebKit/WebProcess/com.apple.WebProcess.sb.in:63
&gt;&gt; +    (subpath &quot;/usr/lib&quot;)
&gt; 
&gt; Ditto.

This section might not be needed (yet), because we don&apos;t prohibit file mapping. But having this here will allow us to flip on that protection in a future patch.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1535732</commentid>
    <comment_count>5</comment_count>
      <attachid>369744</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2019-05-13 12:53:50 -0700</bug_when>
    <thetext>Comment on attachment 369744
Patch

Clearing flags on attachment: 369744

Committed r245246: &lt;https://trac.webkit.org/changeset/245246&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1535733</commentid>
    <comment_count>6</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2019-05-13 12:53:51 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>369744</attachid>
            <date>2019-05-13 10:13:11 -0700</date>
            <delta_ts>2019-05-13 12:53:50 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-197844-20190513101311.patch</filename>
            <type>text/plain</type>
            <size>1957</size>
            <attacher name="Brent Fulgham">bfulgham</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMjQ1MTk2CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L0No
YW5nZUxvZyBiL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCmluZGV4IGE0MGEyZDRkMDkxZWU4NGQw
OTAyNTdlNWUzNjM1NzMzZWEzMzgxZjkuLjRiYzEwN2Q4ZDRmYzJlYTM1NTA3YWFlMzQxY2I0Yzk0
NTk5NzQwMWIgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCisrKyBiL1NvdXJj
ZS9XZWJLaXQvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTUgQEAKKzIwMTktMDUtMTMgIEJyZW50IEZ1
bGdoYW0gIDxiZnVsZ2hhbUBhcHBsZS5jb20+CisKKyAgICAgICAgQ29ycmVjdCB0aGUgc2FuZGJv
eCB0byBhbGxvdyBsb2FkaW5nIGxpYnJhcmllcyBmcm9tIC9MaWJyYXJ5L0FwcGxlIAorICAgICAg
ICBodHRwczovL2J1Z3Mud2Via2l0Lm9yZy9zaG93X2J1Zy5jZ2k/aWQ9MTk3ODQ0CisKKyAgICAg
ICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisKKyAgICAgICAgR3JhbnQgYWNjZXNzIHRv
ICcvTGlicmFyeS9BcHBsZScgYXMgYW4gYXBwcm9wcmlhdGUgcGxhY2UgdG8gbG9hZAorICAgICAg
ICBzeXN0ZW0gZnJhbWV3b3Jrcy4KKworICAgICAgICAqIFdlYlByb2Nlc3MvY29tLmFwcGxlLldl
YlByb2Nlc3Muc2IuaW46CisKIDIwMTktMDUtMTAgIEJyZW50IEZ1bGdoYW0gIDxiZnVsZ2hhbUBh
cHBsZS5jb20+CiAKICAgICAgICAgU3RyZWFtbGluZSB0ZXN0LWFuZC1jbGVhciBvcGVyYXRpb24g
Zm9yIENvbnRleHRNZW51CmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L1dlYlByb2Nlc3MvY29t
LmFwcGxlLldlYlByb2Nlc3Muc2IuaW4gYi9Tb3VyY2UvV2ViS2l0L1dlYlByb2Nlc3MvY29tLmFw
cGxlLldlYlByb2Nlc3Muc2IuaW4KaW5kZXggMDliOGVlZTM0NGQ1ZjY1OTQyMTk5NTEwYWRiZDli
NzFlNDQ5MWE5YS4uZWFiMjU0ZWRjMDE4ZjMzMTcwY2Y5MjMwNzc2MmUzY2U5YjRlNDhiNiAxMDA2
NDQKLS0tIGEvU291cmNlL1dlYktpdC9XZWJQcm9jZXNzL2NvbS5hcHBsZS5XZWJQcm9jZXNzLnNi
LmluCisrKyBiL1NvdXJjZS9XZWJLaXQvV2ViUHJvY2Vzcy9jb20uYXBwbGUuV2ViUHJvY2Vzcy5z
Yi5pbgpAQCAtNDAsNiArNDAsNyBAQAogKGFsbG93IGZpbGUtcmVhZCoKICAgICAocmVxdWlyZS1h
bGwgKGZpbGUtbW9kZSAjbzAwMDQpCiAgICAgKHJlcXVpcmUtYW55IChzdWJwYXRoICIvTGlicmFy
eS9GaWxlc3lzdGVtcy9OZXRGU1BsdWdpbnMiKQorICAgIChzdWJwYXRoICIvTGlicmFyeS9BcHBs
ZS9TeXN0ZW0iKQogICAgIChzdWJwYXRoICIvTGlicmFyeS9QcmVmZXJlbmNlcy9Mb2dnaW5nIikg
ICAgICA7IExvZ2dpbmcgUmV0aGluawogICAgIChzdWJwYXRoICIvU3lzdGVtIikKICAgICAoc3Vi
cGF0aCAiL3ByaXZhdGUvdmFyL2RiL2R5bGQiKQpAQCAtNTMsNiArNTQsMTUgQEAKICAgICAoc3Vi
cGF0aCAiL0FwcGxlSW50ZXJuYWwvTGlicmFyeS9QcmVmZXJlbmNlcy9Mb2dnaW5nIikKICAgICAo
c3lzdGVtLWF0dHJpYnV0ZSBhcHBsZS1pbnRlcm5hbCkpKQogCis7OzsgQWxsb3cgbWFwcGluZyBv
ZiBzeXN0ZW0gZnJhbWV3b3JrcyArIGR5bGlicworKGFsbG93IGZpbGUtbWFwLWV4ZWN1dGFibGUK
KyAgICAoc3VicGF0aCAiL0xpYnJhcnkvQXBwbGUvU3lzdGVtL0xpYnJhcnkvRnJhbWV3b3JrcyIp
CisgICAgKHN1YnBhdGggIi9MaWJyYXJ5L0FwcGxlL1N5c3RlbS9MaWJyYXJ5L1ByaXZhdGVGcmFt
ZXdvcmtzIikKKyAgICAoc3VicGF0aCAiL1N5c3RlbS9MaWJyYXJ5L0ZyYW1ld29ya3MiKQorICAg
IChzdWJwYXRoICIvU3lzdGVtL0xpYnJhcnkvUHJpdmF0ZUZyYW1ld29ya3MiKQorICAgIChzdWJw
YXRoICIvdXNyL2xpYiIpCisgICAgKGxpdGVyYWwgIi91c3IvbG9jYWwvbGliL3Nhbml0aXplcnMi
KSkKKwogKGFsbG93IGZpbGUtcmVhZC1tZXRhZGF0YQogICAgIChsaXRlcmFsICIvZXRjIikKICAg
ICAobGl0ZXJhbCAiL3RtcCIpCg==
</data>

          </attachment>
      

    </bug>

</bugzilla>