<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>207276</bug_id>
          
          <creation_ts>2020-02-05 10:12:46 -0800</creation_ts>
          <short_desc>Update sandbox to allow communication with dnssd service</short_desc>
          <delta_ts>2020-02-05 13:42:35 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Brent Fulgham">bfulgham</reporter>
          <assigned_to name="Brent Fulgham">bfulgham</assigned_to>
          <cc>bfulgham</cc>
    
    <cc>commit-queue</cc>
    
    <cc>pvollan</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1615109</commentid>
    <comment_count>0</comment_count>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2020-02-05 10:12:46 -0800</bug_when>
    <thetext>Testing and telemetry indicates that we need access to the DNSSD mach service in our Network Process.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1615111</commentid>
    <comment_count>1</comment_count>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2020-02-05 10:15:49 -0800</bug_when>
    <thetext>&lt;rdar://problem/59158405&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1615113</commentid>
    <comment_count>2</comment_count>
      <attachid>389827</attachid>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2020-02-05 10:16:44 -0800</bug_when>
    <thetext>Created attachment 389827
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1615142</commentid>
    <comment_count>3</comment_count>
      <attachid>389827</attachid>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2020-02-05 11:17:52 -0800</bug_when>
    <thetext>Comment on attachment 389827
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=389827&amp;action=review

&gt; Source/WebKit/Resources/SandboxProfiles/ios/com.apple.WebKit.Networking.sb:95
&gt; +            (allow network-outbound (literal &quot;/private/var/run/mDNSResponder&quot;))
&gt; +            (allow mach-lookup (global-name &quot;com.apple.dnssd.service&quot;))) ;; &lt;rdar://problem/55562091&gt;
&gt; +        (begin
&gt; +            (allow network-outbound (literal &quot;/private/var/run/mDNSResponder&quot;))
&gt; +            (allow mach-lookup (global-name &quot;com.apple.dnssd.service&quot;)))) ;; &lt;rdar://problem/55562091&gt;

Should this be outside &apos;if gizmo?&apos;?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1615181</commentid>
    <comment_count>4</comment_count>
      <attachid>389827</attachid>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2020-02-05 12:14:36 -0800</bug_when>
    <thetext>Comment on attachment 389827
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=389827&amp;action=review

&gt;&gt; Source/WebKit/Resources/SandboxProfiles/ios/com.apple.WebKit.Networking.sb:95
&gt;&gt; +            (allow mach-lookup (global-name &quot;com.apple.dnssd.service&quot;)))) ;; &lt;rdar://problem/55562091&gt;
&gt; 
&gt; Should this be outside &apos;if gizmo?&apos;?

It is in the &apos;else&apos; of the &apos;if gizmo?&apos; clause, so it&apos;s correct.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1615207</commentid>
    <comment_count>5</comment_count>
      <attachid>389827</attachid>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2020-02-05 12:59:01 -0800</bug_when>
    <thetext>Comment on attachment 389827
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=389827&amp;action=review

R=me.

&gt;&gt;&gt; Source/WebKit/Resources/SandboxProfiles/ios/com.apple.WebKit.Networking.sb:95
&gt;&gt;&gt; +            (allow mach-lookup (global-name &quot;com.apple.dnssd.service&quot;)))) ;; &lt;rdar://problem/55562091&gt;
&gt;&gt; 
&gt;&gt; Should this be outside &apos;if gizmo?&apos;?
&gt; 
&gt; It is in the &apos;else&apos; of the &apos;if gizmo?&apos; clause, so it&apos;s correct.

Ah, I see!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1615250</commentid>
    <comment_count>6</comment_count>
      <attachid>389827</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2020-02-05 13:42:33 -0800</bug_when>
    <thetext>Comment on attachment 389827
Patch

Clearing flags on attachment: 389827

Committed r255852: &lt;https://trac.webkit.org/changeset/255852&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1615251</commentid>
    <comment_count>7</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2020-02-05 13:42:35 -0800</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>389827</attachid>
            <date>2020-02-05 10:16:44 -0800</date>
            <delta_ts>2020-02-05 13:42:33 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>bug-207276-20200205101643.patch</filename>
            <type>text/plain</type>
            <size>3510</size>
            <attacher name="Brent Fulgham">bfulgham</attacher>
            
              <data encoding="base64">U3VidmVyc2lvbiBSZXZpc2lvbjogMjU1NjgyCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L0No
YW5nZUxvZyBiL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCmluZGV4IDBlNzcwNzMxMGM4ODg0ZDk2
OTRlZjIwN2U3MjA0YzhiZjIwNzlkMDAuLjcxOGU2Zjk5MjQzNzMyNWM3MTc2N2ZjNWQzNGYyODA5
YjNkOWY1NGMgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCisrKyBiL1NvdXJj
ZS9XZWJLaXQvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTYgQEAKKzIwMjAtMDItMDUgIEJyZW50IEZ1
bGdoYW0gIDxiZnVsZ2hhbUBhcHBsZS5jb20+CisKKyAgICAgICAgVXBkYXRlIHNhbmRib3ggdG8g
YWxsb3cgY29tbXVuaWNhdGlvbiB3aXRoIGRuc3NkIHNlcnZpY2UKKyAgICAgICAgaHR0cHM6Ly9i
dWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTIwNzI3NgorICAgICAgICA8cmRhcjovL3By
b2JsZW0vNTkxNTg0MDU+CisKKyAgICAgICAgUmV2aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisK
KyAgICAgICAgVGVzdGluZyBhbmQgdGVsZW1ldHJ5IGluZGljYXRlcyB0aGF0IHdlIG5lZWQgYWNj
ZXNzIHRvIHRoZSBETlNTRCBtYWNoIHNlcnZpY2UgaW4gb3VyIE5ldHdvcmsgUHJvY2VzcworCisg
ICAgICAgICogTmV0d29ya1Byb2Nlc3MvbWFjL2NvbS5hcHBsZS5XZWJLaXQuTmV0d29ya1Byb2Nl
c3Muc2IuaW46CisgICAgICAgICogUmVzb3VyY2VzL1NhbmRib3hQcm9maWxlcy9pb3MvY29tLmFw
cGxlLldlYktpdC5OZXR3b3JraW5nLnNiOgorCiAyMDIwLTAyLTA0ICB5b3Vlbm4gZmFibGV0ICA8
eW91ZW5uQGFwcGxlLmNvbT4KIAogICAgICAgICBOZXR3b3JrUHJvY2VzcyBzaG91bGQgYmUgbm90
aWZpZWQgYnkgVUlQcm9jZXNzIHdoZW4gaXRzIHNlcnZpY2Ugd29ya2VyIHByb2Nlc3MgY29ubmVj
dGlvbiBzaG91bGQgYmUgb24KZGlmZiAtLWdpdCBhL1NvdXJjZS9XZWJLaXQvTmV0d29ya1Byb2Nl
c3MvbWFjL2NvbS5hcHBsZS5XZWJLaXQuTmV0d29ya1Byb2Nlc3Muc2IuaW4gYi9Tb3VyY2UvV2Vi
S2l0L05ldHdvcmtQcm9jZXNzL21hYy9jb20uYXBwbGUuV2ViS2l0Lk5ldHdvcmtQcm9jZXNzLnNi
LmluCmluZGV4IDk2YjA3ODA4YWVmNDI3NWZlYjMyYWZhMjk1NjY1NTIwNzViNDkwOTYuLjY1ODJj
MWE5N2RjNDRjOTdlODlmZGJhN2RmZTNlNDI2OTM5N2YxMjEgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9X
ZWJLaXQvTmV0d29ya1Byb2Nlc3MvbWFjL2NvbS5hcHBsZS5XZWJLaXQuTmV0d29ya1Byb2Nlc3Mu
c2IuaW4KKysrIGIvU291cmNlL1dlYktpdC9OZXR3b3JrUHJvY2Vzcy9tYWMvY29tLmFwcGxlLldl
YktpdC5OZXR3b3JrUHJvY2Vzcy5zYi5pbgpAQCAtMSw0ICsxLDQgQEAKLTsgQ29weXJpZ2h0IChD
KSAyMDEzLTIwMTkgQXBwbGUgSW5jLiBBbGwgcmlnaHRzIHJlc2VydmVkLgorOyBDb3B5cmlnaHQg
KEMpIDIwMTMtMjAyMCBBcHBsZSBJbmMuIEFsbCByaWdodHMgcmVzZXJ2ZWQuCiA7CiA7IFJlZGlz
dHJpYnV0aW9uIGFuZCB1c2UgaW4gc291cmNlIGFuZCBiaW5hcnkgZm9ybXMsIHdpdGggb3Igd2l0
aG91dAogOyBtb2RpZmljYXRpb24sIGFyZSBwZXJtaXR0ZWQgcHJvdmlkZWQgdGhhdCB0aGUgZm9s
bG93aW5nIGNvbmRpdGlvbnMKQEAgLTEzOSw2ICsxMzksNyBAQAogICAgIChhbGxvdyBtYWNoLWxv
b2t1cAogICAgICAgICAgKGdsb2JhbC1uYW1lICJjb20uYXBwbGUuU3lzdGVtQ29uZmlndXJhdGlv
bi5QUFBDb250cm9sbGVyIikKICAgICAgICAgIChnbG9iYWwtbmFtZSAiY29tLmFwcGxlLlN5c3Rl
bUNvbmZpZ3VyYXRpb24uU0NOZXR3b3JrUmVhY2hhYmlsaXR5IikKKyAgICAgICAgIChnbG9iYWwt
bmFtZSAiY29tLmFwcGxlLmRuc3NkLnNlcnZpY2UiKQogICAgICAgICAgKGdsb2JhbC1uYW1lICJj
b20uYXBwbGUubmVoZWxwZXIiKQogICAgICAgICAgKGdsb2JhbC1uYW1lICJjb20uYXBwbGUubmVz
ZXNzaW9ubWFuYWdlciIpCiAgICAgICAgICAoZ2xvYmFsLW5hbWUgImNvbS5hcHBsZS5uZXR3b3Jr
ZCIpCmRpZmYgLS1naXQgYS9Tb3VyY2UvV2ViS2l0L1Jlc291cmNlcy9TYW5kYm94UHJvZmlsZXMv
aW9zL2NvbS5hcHBsZS5XZWJLaXQuTmV0d29ya2luZy5zYiBiL1NvdXJjZS9XZWJLaXQvUmVzb3Vy
Y2VzL1NhbmRib3hQcm9maWxlcy9pb3MvY29tLmFwcGxlLldlYktpdC5OZXR3b3JraW5nLnNiCmlu
ZGV4IDhjMDEzNDA5ZDg5NmUwMWM4NDg0YjY0ZDMzMzI0MGY5OTg2N2NmZjIuLmRkNGJjZjJlNWQ4
NGFkY2RiMzg1MWJiZWNiYmQ2NzQ0Mzc3NjY5MzUgMTAwNjQ0Ci0tLSBhL1NvdXJjZS9XZWJLaXQv
UmVzb3VyY2VzL1NhbmRib3hQcm9maWxlcy9pb3MvY29tLmFwcGxlLldlYktpdC5OZXR3b3JraW5n
LnNiCisrKyBiL1NvdXJjZS9XZWJLaXQvUmVzb3VyY2VzL1NhbmRib3hQcm9maWxlcy9pb3MvY29t
LmFwcGxlLldlYktpdC5OZXR3b3JraW5nLnNiCkBAIC0xLDQgKzEsNCBAQAotOyBDb3B5cmlnaHQg
KEMpIDIwMTQtMjAxOSBBcHBsZSBJbmMuIEFsbCByaWdodHMgcmVzZXJ2ZWQuCis7IENvcHlyaWdo
dCAoQykgMjAxNC0yMDIwIEFwcGxlIEluYy4gQWxsIHJpZ2h0cyByZXNlcnZlZC4KIDsKIDsgUmVk
aXN0cmlidXRpb24gYW5kIHVzZSBpbiBzb3VyY2UgYW5kIGJpbmFyeSBmb3Jtcywgd2l0aCBvciB3
aXRob3V0CiA7IG1vZGlmaWNhdGlvbiwgYXJlIHBlcm1pdHRlZCBwcm92aWRlZCB0aGF0IHRoZSBm
b2xsb3dpbmcgY29uZGl0aW9ucwpAQCAtODgsOCArODgsMTEgQEAKICAgICAgICAgICAgIChyZXF1
aXJlLWFueQogICAgICAgICAgICAgICAgIChyZXF1aXJlLWVudGl0bGVtZW50ICJjb20uYXBwbGUu
c2VjdXJpdHkubmV0d29yay5jbGllbnQiKQogICAgICAgICAgICAgICAgIChyZXF1aXJlLWVudGl0
bGVtZW50ICJjb20uYXBwbGUuc2VjdXJpdHkubmV0d29yay5zZXJ2ZXIiKSkKLSAgICAgICAgICAg
IChhbGxvdyBuZXR3b3JrLW91dGJvdW5kIChsaXRlcmFsICIvcHJpdmF0ZS92YXIvcnVuL21ETlNS
ZXNwb25kZXIiKSkpCi0gICAgICAgIChhbGxvdyBuZXR3b3JrLW91dGJvdW5kIChsaXRlcmFsICIv
cHJpdmF0ZS92YXIvcnVuL21ETlNSZXNwb25kZXIiKSkpCisgICAgICAgICAgICAoYWxsb3cgbmV0
d29yay1vdXRib3VuZCAobGl0ZXJhbCAiL3ByaXZhdGUvdmFyL3J1bi9tRE5TUmVzcG9uZGVyIikp
CisgICAgICAgICAgICAoYWxsb3cgbWFjaC1sb29rdXAgKGdsb2JhbC1uYW1lICJjb20uYXBwbGUu
ZG5zc2Quc2VydmljZSIpKSkgOzsgPHJkYXI6Ly9wcm9ibGVtLzU1NTYyMDkxPgorICAgICAgICAo
YmVnaW4KKyAgICAgICAgICAgIChhbGxvdyBuZXR3b3JrLW91dGJvdW5kIChsaXRlcmFsICIvcHJp
dmF0ZS92YXIvcnVuL21ETlNSZXNwb25kZXIiKSkKKyAgICAgICAgICAgIChhbGxvdyBtYWNoLWxv
b2t1cCAoZ2xvYmFsLW5hbWUgImNvbS5hcHBsZS5kbnNzZC5zZXJ2aWNlIikpKSkgOzsgPHJkYXI6
Ly9wcm9ibGVtLzU1NTYyMDkxPgogCiAgICAgOzsgPHJkYXI6Ly9wcm9ibGVtLzEwOTYyODAzPgog
ICAgIDs7IDxyZGFyOi8vcHJvYmxlbS8xMzIzODczMD4K
</data>

          </attachment>
      

    </bug>

</bugzilla>