<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>231079</bug_id>
          
          <creation_ts>2021-10-01 07:40:07 -0700</creation_ts>
          <short_desc>Block access in sandbox to capability which is allowed by default</short_desc>
          <delta_ts>2021-10-12 02:46:19 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit Misc.</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>REOPENED</bug_status>
          <resolution></resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>231567</dependson>
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Per Arne Vollan">pvollan</reporter>
          <assigned_to name="Per Arne Vollan">pvollan</assigned_to>
          <cc>bfulgham</cc>
    
    <cc>commit-queue</cc>
    
    <cc>gavin.p</cc>
    
    <cc>mazander</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1799295</commentid>
    <comment_count>0</comment_count>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2021-10-01 07:40:07 -0700</bug_when>
    <thetext>Some capabilities are allowed by default, and needs to be explicitly denied in the sandbox.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1799296</commentid>
    <comment_count>1</comment_count>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2021-10-01 07:40:54 -0700</bug_when>
    <thetext>&lt;rdar://66586853&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1799298</commentid>
    <comment_count>2</comment_count>
      <attachid>439859</attachid>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2021-10-01 07:42:52 -0700</bug_when>
    <thetext>Created attachment 439859
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1799337</commentid>
    <comment_count>3</comment_count>
      <attachid>439859</attachid>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2021-10-01 09:23:18 -0700</bug_when>
    <thetext>Comment on attachment 439859
Patch

r=me</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1802569</commentid>
    <comment_count>4</comment_count>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2021-10-11 03:40:49 -0700</bug_when>
    <thetext>(In reply to Brent Fulgham from comment #3)
&gt; Comment on attachment 439859 [details]
&gt; Patch
&gt; 
&gt; r=me

I have tested this change locally, and it does not appear to introduce a regression related to JIT code generation.

Thanks for reviewing!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1802570</commentid>
    <comment_count>5</comment_count>
      <attachid>440772</attachid>
    <who name="Per Arne Vollan">pvollan</who>
    <bug_when>2021-10-11 03:45:54 -0700</bug_when>
    <thetext>Created attachment 440772
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1802576</commentid>
    <comment_count>6</comment_count>
    <who name="EWS">ews-feeder</who>
    <bug_when>2021-10-11 04:50:32 -0700</bug_when>
    <thetext>Committed r283890 (242767@main): &lt;https://commits.webkit.org/242767@main&gt;

All reviewed patches have been landed. Closing bug and clearing flags on attachment 440772.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1803048</commentid>
    <comment_count>7</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2021-10-12 02:46:19 -0700</bug_when>
    <thetext>Re-opened since this is blocked by bug 231567</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>439859</attachid>
            <date>2021-10-01 07:42:52 -0700</date>
            <delta_ts>2021-10-01 09:23:18 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-231079-20211001164248.patch</filename>
            <type>text/plain</type>
            <size>1689</size>
            <attacher name="Per Arne Vollan">pvollan</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCj09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFNvdXJjZS9XZWJL
aXQvQ2hhbmdlTG9nCShyZXZpc2lvbiAyODMzNjYpCisrKyBTb3VyY2UvV2ViS2l0L0NoYW5nZUxv
Zwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDE2IEBACisyMDIxLTEwLTAxICBQZXIgQXJuZSAg
PHB2b2xsYW5AYXBwbGUuY29tPgorCisgICAgICAgIEJsb2NrIGFjY2VzcyBpbiBzYW5kYm94IHRv
IGNhcGFiaWxpdHkgd2hpY2ggaXMgYWxsb3dlZCBieSBkZWZhdWx0CisgICAgICAgIGh0dHBzOi8v
YnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0yMzEwNzkKKyAgICAgICAgPHJkYXI6Ly82
NjU4Njg1Mz4KKworICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAg
ICBTb21lIGNhcGFiaWxpdGllcyBhcmUgYWxsb3dlZCBieSBkZWZhdWx0LCBhbmQgbmVlZHMgdG8g
YmUgZXhwbGljaXRseSBkZW5pZWQgaW4gdGhlIHNhbmRib3guCisKKyAgICAgICAgKiBSZXNvdXJj
ZXMvU2FuZGJveFByb2ZpbGVzL2lvcy9jb20uYXBwbGUuV2ViS2l0LldlYkNvbnRlbnQuc2IuaW46
CisgICAgICAgICogV2ViUHJvY2Vzcy9jb20uYXBwbGUuV2ViUHJvY2Vzcy5zYi5pbjoKKwogMjAy
MS0xMC0wMSAgQ2FybG9zIEdhcmNpYSBDYW1wb3MgIDxjZ2FyY2lhQGlnYWxpYS5jb20+CiAKICAg
ICAgICAgW0dUS11bYTExeV0gQWRkIGluaXRpYWwgaW1wbGVtZW50YXRpb24gb2YgYWNjZXNzaWJs
ZSBpbnRlcmZhY2Ugd2hlbiBidWlsZGluZyB3aXRoIEFUU1BJCkluZGV4OiBTb3VyY2UvV2ViS2l0
L1Jlc291cmNlcy9TYW5kYm94UHJvZmlsZXMvaW9zL2NvbS5hcHBsZS5XZWJLaXQuV2ViQ29udGVu
dC5zYi5pbgo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2UvV2ViS2l0L1Jlc291cmNlcy9TYW5kYm94UHJv
ZmlsZXMvaW9zL2NvbS5hcHBsZS5XZWJLaXQuV2ViQ29udGVudC5zYi5pbgkocmV2aXNpb24gMjgz
MzYwKQorKysgU291cmNlL1dlYktpdC9SZXNvdXJjZXMvU2FuZGJveFByb2ZpbGVzL2lvcy9jb20u
YXBwbGUuV2ViS2l0LldlYkNvbnRlbnQuc2IuaW4JKHdvcmtpbmcgY29weSkKQEAgLTE1NjUsMyAr
MTU2NSw1IEBACiAod2hlbiAoZGVmaW5lZD8gJ2Rhcndpbi1ub3RpZmljYXRpb24tcG9zdCkKICAg
ICAoYWxsb3cgZGFyd2luLW5vdGlmaWNhdGlvbi1wb3N0ICh3aXRoIHRlbGVtZXRyeSkpCiApCisK
KyhkZW55IGR5bmFtaWMtY29kZS1nZW5lcmF0aW9uKQpJbmRleDogU291cmNlL1dlYktpdC9XZWJQ
cm9jZXNzL2NvbS5hcHBsZS5XZWJQcm9jZXNzLnNiLmluCj09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFNvdXJjZS9X
ZWJLaXQvV2ViUHJvY2Vzcy9jb20uYXBwbGUuV2ViUHJvY2Vzcy5zYi5pbgkocmV2aXNpb24gMjgz
MzYwKQorKysgU291cmNlL1dlYktpdC9XZWJQcm9jZXNzL2NvbS5hcHBsZS5XZWJQcm9jZXNzLnNi
LmluCSh3b3JraW5nIGNvcHkpCkBAIC0yMzAwLDMgKzIzMDAsNSBAQAogICAgICkKICkKICNlbmRp
ZgorCisoZGVueSBkeW5hbWljLWNvZGUtZ2VuZXJhdGlvbikK
</data>
<flag name="review"
          id="463606"
          type_id="1"
          status="+"
          setter="bfulgham"
    />
          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>440772</attachid>
            <date>2021-10-11 03:45:54 -0700</date>
            <delta_ts>2021-10-11 04:50:33 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-231079-20211011124552.patch</filename>
            <type>text/plain</type>
            <size>1659</size>
            <attacher name="Per Arne Vollan">pvollan</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJLaXQvQ2hhbmdlTG9nCj09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFNvdXJjZS9XZWJL
aXQvQ2hhbmdlTG9nCShyZXZpc2lvbiAyODM4ODcpCisrKyBTb3VyY2UvV2ViS2l0L0NoYW5nZUxv
Zwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDE2IEBACisyMDIxLTEwLTExICBQZXIgQXJuZSBW
b2xsYW4gPHB2b2xsYW5AYXBwbGUuY29tPgorCisgICAgICAgIEJsb2NrIGFjY2VzcyBpbiBzYW5k
Ym94IHRvIGNhcGFiaWxpdHkgd2hpY2ggaXMgYWxsb3dlZCBieSBkZWZhdWx0CisgICAgICAgIGh0
dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0yMzEwNzkKKyAgICAgICAgPHJk
YXI6Ly82NjU4Njg1Mz4KKworICAgICAgICBSZXZpZXdlZCBieSBCcmVudCBGdWxnaGFtLgorCisg
ICAgICAgIFNvbWUgY2FwYWJpbGl0aWVzIGFyZSBhbGxvd2VkIGJ5IGRlZmF1bHQsIGFuZCBuZWVk
cyB0byBiZSBleHBsaWNpdGx5IGRlbmllZCBpbiB0aGUgc2FuZGJveC4KKworICAgICAgICAqIFJl
c291cmNlcy9TYW5kYm94UHJvZmlsZXMvaW9zL2NvbS5hcHBsZS5XZWJLaXQuV2ViQ29udGVudC5z
Yi5pbjoKKyAgICAgICAgKiBXZWJQcm9jZXNzL2NvbS5hcHBsZS5XZWJQcm9jZXNzLnNiLmluOgor
CiAyMDIxLTEwLTExICBQZXIgQXJuZSBWb2xsYW4gPHB2b2xsYW5AYXBwbGUuY29tPgogCiAgICAg
ICAgIFtpT1NdIEFkZCBtZXNzYWdlIGZpbHRlciBpbiB0aGUgV2ViQ29udGVudCBwcm9jZXNzJyBz
YW5kYm94CkluZGV4OiBTb3VyY2UvV2ViS2l0L1Jlc291cmNlcy9TYW5kYm94UHJvZmlsZXMvaW9z
L2NvbS5hcHBsZS5XZWJLaXQuV2ViQ29udGVudC5zYi5pbgo9PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2Uv
V2ViS2l0L1Jlc291cmNlcy9TYW5kYm94UHJvZmlsZXMvaW9zL2NvbS5hcHBsZS5XZWJLaXQuV2Vi
Q29udGVudC5zYi5pbgkocmV2aXNpb24gMjgzODg3KQorKysgU291cmNlL1dlYktpdC9SZXNvdXJj
ZXMvU2FuZGJveFByb2ZpbGVzL2lvcy9jb20uYXBwbGUuV2ViS2l0LldlYkNvbnRlbnQuc2IuaW4J
KHdvcmtpbmcgY29weSkKQEAgLTE1NzQsMyArMTU3NCw1IEBACiAod2hlbiAoZGVmaW5lZD8gJ2Rh
cndpbi1ub3RpZmljYXRpb24tcG9zdCkKICAgICAoYWxsb3cgZGFyd2luLW5vdGlmaWNhdGlvbi1w
b3N0ICh3aXRoIHRlbGVtZXRyeSkpCiApCisKKyhkZW55IGR5bmFtaWMtY29kZS1nZW5lcmF0aW9u
KQpJbmRleDogU291cmNlL1dlYktpdC9XZWJQcm9jZXNzL2NvbS5hcHBsZS5XZWJQcm9jZXNzLnNi
LmluCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT0KLS0tIFNvdXJjZS9XZWJLaXQvV2ViUHJvY2Vzcy9jb20uYXBwbGUuV2Vi
UHJvY2Vzcy5zYi5pbgkocmV2aXNpb24gMjgzODg3KQorKysgU291cmNlL1dlYktpdC9XZWJQcm9j
ZXNzL2NvbS5hcHBsZS5XZWJQcm9jZXNzLnNiLmluCSh3b3JraW5nIGNvcHkpCkBAIC0yMjg5LDMg
KzIyODksNSBAQAogICAgICkKICkKICNlbmRpZgorCisoZGVueSBkeW5hbWljLWNvZGUtZ2VuZXJh
dGlvbikK
</data>

          </attachment>
      

    </bug>

</bugzilla>