<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>207488</bug_id>
          
          <creation_ts>2020-02-10 11:39:48 -0800</creation_ts>
          <short_desc>[iOS] Deny mach lookup access to the tccd service in the WebContent process</short_desc>
          <delta_ts>2020-02-11 14:22:30 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit Misc.</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Per Arne Vollan">pvollan</reporter>
          <assigned_to name="Per Arne Vollan">pvollan</assigned_to>
          <cc>bfulgham</cc>
    
    <cc>commit-queue</cc>
    
    <cc>darin</cc>
    
    <cc>ggaren</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1617002</commentid>
    <comment_count>0</comment_count>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2020-02-10 11:39:48 -0800</bug_when>
    <thetext>As part of sandbox hardening, deny mach lookup access to the tccd service.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1617005</commentid>
    <comment_count>1</comment_count>
      <attachid>390275</attachid>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2020-02-10 11:44:40 -0800</bug_when>
    <thetext>Created attachment 390275
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1617006</commentid>
    <comment_count>2</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2020-02-10 11:45:06 -0800</bug_when>
    <thetext>&lt;rdar://problem/59319475&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1617569</commentid>
    <comment_count>3</comment_count>
      <attachid>390275</attachid>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2020-02-11 13:00:25 -0800</bug_when>
    <thetext>Comment on attachment 390275
Patch

Thanks for reviewing!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1617626</commentid>
    <comment_count>4</comment_count>
      <attachid>390275</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2020-02-11 14:22:28 -0800</bug_when>
    <thetext>Comment on attachment 390275
Patch

Clearing flags on attachment: 390275

Committed r256371: &lt;https://trac.webkit.org/changeset/256371&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1617627</commentid>
    <comment_count>5</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2020-02-11 14:22:30 -0800</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>390275</attachid>
            <date>2020-02-10 11:44:40 -0800</date>
            <delta_ts>2020-02-11 14:22:28 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>bug-207488-20200210114439.patch</filename>
            <type>text/plain</type>
            <size>3880</size>
            <attacher name="Per Arne Vollan">pvollan</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCj09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFNvdXJjZS9XZWJL
aXQvQ2hhbmdlTG9nCShyZXZpc2lvbiAyNTYxOTcpCisrKyBTb3VyY2UvV2ViS2l0L0NoYW5nZUxv
Zwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDE2IEBACisyMDIwLTAyLTEwICBQZXIgQXJuZSBW
b2xsYW4gIDxwdm9sbGFuQGFwcGxlLmNvbT4KKworICAgICAgICBbaU9TXSBEZW55IG1hY2ggbG9v
a3VwIGFjY2VzcyB0byB0aGUgdGNjZCBzZXJ2aWNlIGluIHRoZSBXZWJDb250ZW50IHByb2Nlc3MK
KyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTIwNzQ4OAor
CisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIEFzIHBhcnQg
b2Ygc2FuZGJveCBoYXJkZW5pbmcsIGRlbnkgbWFjaCBsb29rdXAgYWNjZXNzIHRvIHRoZSB0Y2Nk
IHNlcnZpY2UuCisKKyAgICAgICAgVGVzdDogZmFzdC9zYW5kYm94L2lvcy9zYW5kYm94LW1hY2gt
bG9va3VwLmh0bWwKKworICAgICAgICAqIFJlc291cmNlcy9TYW5kYm94UHJvZmlsZXMvaW9zL2Nv
bS5hcHBsZS5XZWJLaXQuV2ViQ29udGVudC5zYjoKKwogMjAyMC0wMi0xMCAgRGFuaWVsIEJhdGVz
ICA8ZGFiYXRlc0BhcHBsZS5jb20+CiAKICAgICAgICAgRGlzYWxsb3cgc2V0dGluZyBiYXNlIFVS
TCB0byBhIGRhdGEgb3IgSmF2YVNjcmlwdCBVUkwKSW5kZXg6IFNvdXJjZS9XZWJLaXQvUmVzb3Vy
Y2VzL1NhbmRib3hQcm9maWxlcy9pb3MvY29tLmFwcGxlLldlYktpdC5XZWJDb250ZW50LnNiCj09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT0KLS0tIFNvdXJjZS9XZWJLaXQvUmVzb3VyY2VzL1NhbmRib3hQcm9maWxlcy9pb3Mv
Y29tLmFwcGxlLldlYktpdC5XZWJDb250ZW50LnNiCShyZXZpc2lvbiAyNTYxOTUpCisrKyBTb3Vy
Y2UvV2ViS2l0L1Jlc291cmNlcy9TYW5kYm94UHJvZmlsZXMvaW9zL2NvbS5hcHBsZS5XZWJLaXQu
V2ViQ29udGVudC5zYgkod29ya2luZyBjb3B5KQpAQCAtNjA0LDggKzYwNCw3IEBACiAgICAgKGds
b2JhbC1uYW1lICJjb20uYXBwbGUuY2ZwcmVmc2QuZGFlbW9uIikpCiAKIChhbGxvdyBtYWNoLWxv
b2t1cCAod2l0aCByZXBvcnQpICh3aXRoIHRlbGVtZXRyeSkKLSAgICAoZ2xvYmFsLW5hbWUgImNv
bS5hcHBsZS5kaXN0cmlidXRlZF9ub3RpZmljYXRpb25zQDF2MyIpCi0gICAgKGdsb2JhbC1uYW1l
ICJjb20uYXBwbGUudGNjZCIpKQorICAgIChnbG9iYWwtbmFtZSAiY29tLmFwcGxlLmRpc3RyaWJ1
dGVkX25vdGlmaWNhdGlvbnNAMXYzIikpCiAKIChhbGxvdyBpcGMtcG9zaXgtc2htLXJlYWQqCiAg
ICAgICAgKGlwYy1wb3NpeC1uYW1lLXByZWZpeCAiYXBwbGUuY2ZwcmVmcy4iKSkKSW5kZXg6IExh
eW91dFRlc3RzL0NoYW5nZUxvZwo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBMYXlvdXRUZXN0cy9DaGFuZ2VMb2cJ
KHJldmlzaW9uIDI1NjE5NSkKKysrIExheW91dFRlc3RzL0NoYW5nZUxvZwkod29ya2luZyBjb3B5
KQpAQCAtMSwzICsxLDEzIEBACisyMDIwLTAyLTEwICBQZXIgQXJuZSBWb2xsYW4gIDxwdm9sbGFu
QGFwcGxlLmNvbT4KKworICAgICAgICBbaU9TXSBEZW55IG1hY2ggbG9va3VwIGFjY2VzcyB0byB0
aGUgdGNjZCBzZXJ2aWNlIGluIHRoZSBXZWJDb250ZW50IHByb2Nlc3MKKyAgICAgICAgaHR0cHM6
Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lkPTIwNzQ4OAorCisgICAgICAgIFJldmll
d2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgICogZmFzdC9zYW5kYm94L2lvcy9zYW5k
Ym94LW1hY2gtbG9va3VwLWV4cGVjdGVkLnR4dDoKKyAgICAgICAgKiBmYXN0L3NhbmRib3gvaW9z
L3NhbmRib3gtbWFjaC1sb29rdXAuaHRtbDoKKwogMjAyMC0wMi0xMCAgVHJ1aXR0IFNhdmVsbCAg
PHRzYXZlbGxAYXBwbGUuY29tPgogCiAgICAgICAgIFJFR1JFU1NJT046IFsgV2luIF0gY3NzMS9i
b3hfcHJvcGVydGllcy9wYWRkaW5nX2xlZnQuaHRtbCBpcyBmYWlsaW5nCkluZGV4OiBMYXlvdXRU
ZXN0cy9mYXN0L3NhbmRib3gvaW9zL3NhbmRib3gtbWFjaC1sb29rdXAtZXhwZWN0ZWQudHh0Cj09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT0KLS0tIExheW91dFRlc3RzL2Zhc3Qvc2FuZGJveC9pb3Mvc2FuZGJveC1tYWNoLWxv
b2t1cC1leHBlY3RlZC50eHQJKHJldmlzaW9uIDI1NjE5NSkKKysrIExheW91dFRlc3RzL2Zhc3Qv
c2FuZGJveC9pb3Mvc2FuZGJveC1tYWNoLWxvb2t1cC1leHBlY3RlZC50eHQJKHdvcmtpbmcgY29w
eSkKQEAgLTE3LDQgKzE3LDQgQEAgUEFTUyBpbnRlcm5hbHMuaGFzU2FuZGJveE1hY2hMb29rdXBB
Y2NlcwogUEFTUyBpbnRlcm5hbHMuaGFzU2FuZGJveE1hY2hMb29rdXBBY2Nlc3NUb0dsb2JhbE5h
bWUoImNvbS5hcHBsZS5XZWJLaXQuV2ViQ29udGVudCIsICJjb20uYXBwbGUucG93ZXJsb2cucGx4
cGNsb2dnZXIueHBjIikgaXMgZmFsc2UKIFBBU1MgaW50ZXJuYWxzLmhhc1NhbmRib3hNYWNoTG9v
a3VwQWNjZXNzVG9HbG9iYWxOYW1lKCJjb20uYXBwbGUuV2ViS2l0LldlYkNvbnRlbnQiLCAiY29t
LmFwcGxlLnN5c3RlbS5sb2dnZXIiKSBpcyBmYWxzZQogUEFTUyBpbnRlcm5hbHMuaGFzU2FuZGJv
eE1hY2hMb29rdXBBY2Nlc3NUb0dsb2JhbE5hbWUoImNvbS5hcHBsZS5XZWJLaXQuV2ViQ29udGVu
dCIsICJjb20uYXBwbGUuYWdncmVnYXRlZCIpIGlzIGZhbHNlCi0KK1BBU1MgaW50ZXJuYWxzLmhh
c1NhbmRib3hNYWNoTG9va3VwQWNjZXNzVG9HbG9iYWxOYW1lKCJjb20uYXBwbGUuV2ViS2l0Lldl
YkNvbnRlbnQiLCAiY29tLmFwcGxlLnRjY2QiKSBpcyBmYWxzZQpJbmRleDogTGF5b3V0VGVzdHMv
ZmFzdC9zYW5kYm94L2lvcy9zYW5kYm94LW1hY2gtbG9va3VwLmh0bWwKPT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0g
TGF5b3V0VGVzdHMvZmFzdC9zYW5kYm94L2lvcy9zYW5kYm94LW1hY2gtbG9va3VwLmh0bWwJKHJl
dmlzaW9uIDI1NjE5NSkKKysrIExheW91dFRlc3RzL2Zhc3Qvc2FuZGJveC9pb3Mvc2FuZGJveC1t
YWNoLWxvb2t1cC5odG1sCSh3b3JraW5nIGNvcHkpCkBAIC0yMCw2ICsyMCw3IEBAIGlmICh3aW5k
b3cuaW50ZXJuYWxzKSB7CiAgICAgc2hvdWxkQmVGYWxzZSgiaW50ZXJuYWxzLmhhc1NhbmRib3hN
YWNoTG9va3VwQWNjZXNzVG9HbG9iYWxOYW1lKFwiY29tLmFwcGxlLldlYktpdC5XZWJDb250ZW50
XCIsIFwiY29tLmFwcGxlLnBvd2VybG9nLnBseHBjbG9nZ2VyLnhwY1wiKSIpOwogICAgIHNob3Vs
ZEJlRmFsc2UoImludGVybmFscy5oYXNTYW5kYm94TWFjaExvb2t1cEFjY2Vzc1RvR2xvYmFsTmFt
ZShcImNvbS5hcHBsZS5XZWJLaXQuV2ViQ29udGVudFwiLCBcImNvbS5hcHBsZS5zeXN0ZW0ubG9n
Z2VyXCIpIik7CiAgICAgc2hvdWxkQmVGYWxzZSgiaW50ZXJuYWxzLmhhc1NhbmRib3hNYWNoTG9v
a3VwQWNjZXNzVG9HbG9iYWxOYW1lKFwiY29tLmFwcGxlLldlYktpdC5XZWJDb250ZW50XCIsIFwi
Y29tLmFwcGxlLmFnZ3JlZ2F0ZWRcIikiKTsKKyAgICBzaG91bGRCZUZhbHNlKCJpbnRlcm5hbHMu
aGFzU2FuZGJveE1hY2hMb29rdXBBY2Nlc3NUb0dsb2JhbE5hbWUoXCJjb20uYXBwbGUuV2ViS2l0
LldlYkNvbnRlbnRcIiwgXCJjb20uYXBwbGUudGNjZFwiKSIpOwogfQogPC9zY3JpcHQ+CiA8L2hl
YWQ+Cg==
</data>

          </attachment>
      

    </bug>

</bugzilla>