<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>206020</bug_id>
          
          <creation_ts>2020-01-09 11:44:12 -0800</creation_ts>
          <short_desc>Remove AGXCompilerService access from the WebContent sandbox</short_desc>
          <delta_ts>2020-01-09 15:18:14 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Brent Fulgham">bfulgham</reporter>
          <assigned_to name="Brent Fulgham">bfulgham</assigned_to>
          <cc>achristensen</cc>
    
    <cc>bfulgham</cc>
    
    <cc>commit-queue</cc>
    
    <cc>pvollan</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1604747</commentid>
    <comment_count>0</comment_count>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2020-01-09 11:44:12 -0800</bug_when>
    <thetext>Now that we generate a dynamic extension for &apos;com.apple.AGXCompilerService&apos;, we should remove the blanket allow rule from the sandbox.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1604752</commentid>
    <comment_count>1</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2020-01-09 11:47:25 -0800</bug_when>
    <thetext>&lt;rdar://problem/58451395&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1604762</commentid>
    <comment_count>2</comment_count>
      <attachid>387251</attachid>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2020-01-09 12:09:45 -0800</bug_when>
    <thetext>Created attachment 387251
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1604805</commentid>
    <comment_count>3</comment_count>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2020-01-09 13:21:48 -0800</bug_when>
    <thetext>Should we also add a test case for this in fast/sandbox/ios/sandbox-mach-lookup.html?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1604841</commentid>
    <comment_count>4</comment_count>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2020-01-09 14:06:05 -0800</bug_when>
    <thetext>(In reply to Per Arne Vollan from comment #3)
&gt; Should we also add a test case for this in
&gt; fast/sandbox/ios/sandbox-mach-lookup.html?

Since this is hardware specific, will we have too many test failures?

Is there a way to skip on specific hardware? I think we only support version and platform (not 2017 iPad versus 2018 iPad, for example).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1604847</commentid>
    <comment_count>5</comment_count>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2020-01-09 14:11:28 -0800</bug_when>
    <thetext>(In reply to Brent Fulgham from comment #4)
&gt; (In reply to Per Arne Vollan from comment #3)
&gt; &gt; Should we also add a test case for this in
&gt; &gt; fast/sandbox/ios/sandbox-mach-lookup.html?
&gt; 
&gt; Since this is hardware specific, will we have too many test failures?
&gt; 
&gt; Is there a way to skip on specific hardware? I think we only support version
&gt; and platform (not 2017 iPad versus 2018 iPad, for example).

You&apos;re right, I don&apos;t think there is a way to skip specific hardware.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1604848</commentid>
    <comment_count>6</comment_count>
      <attachid>387251</attachid>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2020-01-09 14:12:01 -0800</bug_when>
    <thetext>Comment on attachment 387251
Patch

Great! R=me.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1604893</commentid>
    <comment_count>7</comment_count>
      <attachid>387251</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2020-01-09 15:18:12 -0800</bug_when>
    <thetext>Comment on attachment 387251
Patch

Clearing flags on attachment: 387251

Committed r254306: &lt;https://trac.webkit.org/changeset/254306&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1604894</commentid>
    <comment_count>8</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2020-01-09 15:18:14 -0800</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>387251</attachid>
            <date>2020-01-09 12:09:45 -0800</date>
            <delta_ts>2020-01-09 15:18:12 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>bug-206020-20200109120945.patch</filename>
            <type>text/plain</type>
            <size>1692</size>
            <attacher name="Brent Fulgham">bfulgham</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMjU0MjgxCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L0No
YW5nZUxvZyBiL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCmluZGV4IGMyYmFhYTVkZDdmNjI1MTIz
NDc0Y2UwNmVjNTFiOWVkMzVlMDRjYzUuLjJiODJiYTQzMDg5MGY0N2IwNDQ3MmViZWMzOTNiOGUz
NzQzNThlMDQgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCisrKyBiL1NvdXJj
ZS9XZWJLaXQvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTggQEAKKzIwMjAtMDEtMDkgIEJyZW50IEZ1
bGdoYW0gIDxiZnVsZ2hhbUBhcHBsZS5jb20+CisKKyAgICAgICAgUmVtb3ZlIEFHWENvbXBpbGVy
U2VydmljZSBhY2Nlc3MgZnJvbSB0aGUgV2ViQ29udGVudCBzYW5kYm94CisgICAgICAgIGh0dHBz
Oi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0yMDYwMjAKKyAgICAgICAgPHJkYXI6
Ly9wcm9ibGVtLzU4NDUxMzk1PgorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEp
LgorCisgICAgICAgIE5vdyB0aGF0IHdlIGdlbmVyYXRlIGEgZHluYW1pYyBleHRlbnNpb24gZm9y
ICdjb20uYXBwbGUuQUdYQ29tcGlsZXJTZXJ2aWNlJywgd2Ugc2hvdWxkIHJlbW92ZSB0aGUKKyAg
ICAgICAgYmxhbmtldCBhbGxvdyBydWxlIGZyb20gdGhlIHNhbmRib3guCisKKyAgICAgICAgQ292
ZXJlZCBieSBleGlzdGluZyB0ZXN0cy4KKworICAgICAgICAqIFJlc291cmNlcy9TYW5kYm94UHJv
ZmlsZXMvaW9zL2NvbS5hcHBsZS5XZWJLaXQuV2ViQ29udGVudC5zYjoKKwogMjAyMC0wMS0wOSAg
eW91ZW5uIGZhYmxldCAgPHlvdWVubkBhcHBsZS5jb20+CiAKICAgICAgICAgUkVHUkVTU0lPTjog
WyBNYWMgd2syIF0gZmFzdC9tZWRpYXN0cmVhbS9jYXB0dXJlSW5HUFVQcm9jZXNzLmh0bWwgaXMg
YSBmbGFreSBmYWlsdXJlCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L1Jlc291cmNlcy9TYW5k
Ym94UHJvZmlsZXMvaW9zL2NvbS5hcHBsZS5XZWJLaXQuV2ViQ29udGVudC5zYiBiL1NvdXJjZS9X
ZWJLaXQvUmVzb3VyY2VzL1NhbmRib3hQcm9maWxlcy9pb3MvY29tLmFwcGxlLldlYktpdC5XZWJD
b250ZW50LnNiCmluZGV4IGZiMTc1YTBmMjk0MmE4MjBkMmIzODc4NWI5NTcwNDQ4MTU4N2MzYTku
LjgxNTQ2MmYyNTQ2Nzk4ZGRlMWI5NzRkZjc0ZmEyMjMxYmE3YjQ5NjAgMTAwNjQ0Ci0tLSBhL1Nv
dXJjZS9XZWJLaXQvUmVzb3VyY2VzL1NhbmRib3hQcm9maWxlcy9pb3MvY29tLmFwcGxlLldlYktp
dC5XZWJDb250ZW50LnNiCisrKyBiL1NvdXJjZS9XZWJLaXQvUmVzb3VyY2VzL1NhbmRib3hQcm9m
aWxlcy9pb3MvY29tLmFwcGxlLldlYktpdC5XZWJDb250ZW50LnNiCkBAIC0yOTgsOSArMjk4LDYg
QEAKICAgICAoYWxsb3cgc3lzY3RsLXJlYWQKICAgICAgICAgICAgKHN5c2N0bC1uYW1lICMia2Vy
bi5ib290c2Vzc2lvbnV1aWQiKSkKIAotICAgIChhbGxvdyBtYWNoLWxvb2t1cCAod2l0aCByZXBv
cnQpICh3aXRoIHRlbGVtZXRyeSkKLSAgICAgICAgKHhwYy1zZXJ2aWNlLW5hbWUtcHJlZml4ICJj
b20uYXBwbGUuQUdYQ29tcGlsZXJTZXJ2aWNlIikpCi0KICAgICAoYWxsb3cgbWFjaC1sb29rdXAK
ICAgICAgICA7OyA8cmRhcjovL3Byb2JsZW0vNDcyNjgxNjY+CiAgICAgICAgKHhwYy1zZXJ2aWNl
LW5hbWUgImNvbS5hcHBsZS5NVExDb21waWxlclNlcnZpY2UiKSkK
</data>

          </attachment>
      

    </bug>

</bugzilla>