<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>54154</bug_id>
          
          <creation_ts>2011-02-09 16:55:34 -0800</creation_ts>
          <short_desc>File uploads do not work within the sandbox</short_desc>
          <delta_ts>2011-02-09 17:18:18 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebKit2</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Mac</rep_platform>
          <op_sys>OS X 10.5</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Sam Weinig">sam</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>348703</commentid>
    <comment_count>0</comment_count>
    <who name="Sam Weinig">sam</who>
    <bug_when>2011-02-09 16:55:34 -0800</bug_when>
    <thetext>File uploads do not work within the sandbox</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>348706</commentid>
    <comment_count>1</comment_count>
      <attachid>81895</attachid>
    <who name="Sam Weinig">sam</who>
    <bug_when>2011-02-09 16:57:49 -0800</bug_when>
    <thetext>Created attachment 81895
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>348710</commentid>
    <comment_count>2</comment_count>
      <attachid>81895</attachid>
    <who name="Darin Adler">darin</who>
    <bug_when>2011-02-09 17:00:51 -0800</bug_when>
    <thetext>Comment on attachment 81895
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=81895&amp;action=review

&gt; Source/WebKit2/UIProcess/WebPageProxy.cpp:2124
&gt; +        SandboxExtension::Handle sandboxExtensionHandle;
&gt; +        SandboxExtension::createHandle(fileURLs[i], SandboxExtension::ReadOnly, sandboxExtensionHandle);

Why does this use an out argument instead of a return value?

&gt; Source/WebKit2/WebProcess/WebPage/WebPage.cpp:1561
&gt; +    RefPtr&lt;SandboxExtension&gt; extension = SandboxExtension::create(handle);
&gt; +    extension-&gt;consumePermanently();

No need for a local variable here.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>348728</commentid>
    <comment_count>3</comment_count>
    <who name="Sam Weinig">sam</who>
    <bug_when>2011-02-09 17:18:18 -0800</bug_when>
    <thetext>Fixed in http://trac.webkit.org/changeset/78163.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>81895</attachid>
            <date>2011-02-09 16:57:49 -0800</date>
            <delta_ts>2011-02-09 17:00:51 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>patchUploads.diff</filename>
            <type>text/plain</type>
            <size>3895</size>
            <attacher name="Sam Weinig">sam</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJLaXQyL0NoYW5nZUxvZwo9PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2UvV2Vi
S2l0Mi9DaGFuZ2VMb2cJKHJldmlzaW9uIDc4MTYyKQorKysgU291cmNlL1dlYktpdDIvQ2hhbmdl
TG9nCSh3b3JraW5nIGNvcHkpCkBAIC0xLDMgKzEsMTggQEAKKzIwMTEtMDItMDkgIFNhbSBXZWlu
aWcgIDxzYW1Ad2Via2l0Lm9yZz4KKworICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMh
KS4KKworICAgICAgICBGaWxlIHVwbG9hZHMgZG8gbm90IHdvcmsgd2l0aGluIHRoZSBzYW5kYm94
CisgICAgICAgIDxyZGFyOi8vcHJvYmxlbS84OTUwNTE4PgorICAgICAgICBodHRwczovL2J1Z3Mu
d2Via2l0Lm9yZy9zaG93X2J1Zy5jZ2k/aWQ9NTQxNTQKKworICAgICAgICAqIFVJUHJvY2Vzcy9X
ZWJQYWdlUHJveHkuY3BwOgorICAgICAgICAoV2ViS2l0OjpXZWJQYWdlUHJveHk6OmRpZENob29z
ZUZpbGVzRm9yT3BlblBhbmVsKToKKyAgICAgICAgKiBXZWJQcm9jZXNzL1dlYlBhZ2UvV2ViUGFn
ZS5jcHA6CisgICAgICAgIChXZWJLaXQ6OldlYlBhZ2U6OmV4dGVuZFNhbmRib3hGb3JGaWxlRnJv
bU9wZW5QYW5lbCk6CisgICAgICAgICogV2ViUHJvY2Vzcy9XZWJQYWdlL1dlYlBhZ2UuaDoKKyAg
ICAgICAgKiBXZWJQcm9jZXNzL1dlYlBhZ2UvV2ViUGFnZS5tZXNzYWdlcy5pbjoKKwogMjAxMS0w
Mi0wOSAgQWxleGV5IFByb3NrdXJ5YWtvdiAgPGFwQGFwcGxlLmNvbT4KIAogICAgICAgICBSZXZp
ZXdlZCBieSBEYXJpbiBBZGxlci4KSW5kZXg6IFNvdXJjZS9XZWJLaXQyL1VJUHJvY2Vzcy9XZWJQ
YWdlUHJveHkuY3BwCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFNvdXJjZS9XZWJLaXQyL1VJUHJvY2Vzcy9XZWJQ
YWdlUHJveHkuY3BwCShyZXZpc2lvbiA3ODE1OCkKKysrIFNvdXJjZS9XZWJLaXQyL1VJUHJvY2Vz
cy9XZWJQYWdlUHJveHkuY3BwCSh3b3JraW5nIGNvcHkpCkBAIC0yMTE2LDcgKzIxMTYsMTYgQEAg
dm9pZCBXZWJQYWdlUHJveHk6OmRpZENob29zZUZpbGVzRm9yT3BlbgogICAgIGlmICghaXNWYWxp
ZCgpKQogICAgICAgICByZXR1cm47CiAKLSAgICAvLyBGSVhNRTogVGhpcyBhbHNvIG5lZWRzIHRv
IHNlbmQgYSBzYW5kYm94IGV4dGVuc2lvbiBmb3IgdGhlc2UgcGF0aHMuCisjaWYgRU5BQkxFKFdF
Ql9QUk9DRVNTX1NBTkRCT1gpCisgICAgLy8gRklYTUU6IFRoZSBzYW5kYm94IGV4dGVuc2lvbnMg
c2hvdWxkIGJlIHNlbnQgd2l0aCB0aGUgRGlkQ2hvb3NlRmlsZXNGb3JPcGVuUGFuZWwgbWVzc2Fn
ZS4gVGhpcworICAgIC8vIGlzIGdhdGVkIG9uIGEgd2F5IG9mIHBhc3NpbmcgU2FuZGJveEV4dGVu
c2lvbjo6SGFuZGxlcyBpbiBhIFZlY3Rvci4KKyAgICBmb3IgKHNpemVfdCBpID0gMDsgaSA8IGZp
bGVVUkxzLnNpemUoKTsgKytpKSB7CisgICAgICAgIFNhbmRib3hFeHRlbnNpb246OkhhbmRsZSBz
YW5kYm94RXh0ZW5zaW9uSGFuZGxlOworICAgICAgICBTYW5kYm94RXh0ZW5zaW9uOjpjcmVhdGVI
YW5kbGUoZmlsZVVSTHNbaV0sIFNhbmRib3hFeHRlbnNpb246OlJlYWRPbmx5LCBzYW5kYm94RXh0
ZW5zaW9uSGFuZGxlKTsKKyAgICAgICAgcHJvY2VzcygpLT5zZW5kKE1lc3NhZ2VzOjpXZWJQYWdl
OjpFeHRlbmRTYW5kYm94Rm9yRmlsZUZyb21PcGVuUGFuZWwoc2FuZGJveEV4dGVuc2lvbkhhbmRs
ZSksIG1fcGFnZUlEKTsKKyAgICB9CisjZW5kaWYKKwogICAgIHByb2Nlc3MoKS0+c2VuZChNZXNz
YWdlczo6V2ViUGFnZTo6RGlkQ2hvb3NlRmlsZXNGb3JPcGVuUGFuZWwoZmlsZVVSTHMpLCBtX3Bh
Z2VJRCk7CiAKICAgICBtX29wZW5QYW5lbFJlc3VsdExpc3RlbmVyLT5pbnZhbGlkYXRlKCk7Cklu
ZGV4OiBTb3VyY2UvV2ViS2l0Mi9XZWJQcm9jZXNzL1dlYlBhZ2UvV2ViUGFnZS5jcHAKPT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PQotLS0gU291cmNlL1dlYktpdDIvV2ViUHJvY2Vzcy9XZWJQYWdlL1dlYlBhZ2UuY3BwCShy
ZXZpc2lvbiA3ODE1OCkKKysrIFNvdXJjZS9XZWJLaXQyL1dlYlByb2Nlc3MvV2ViUGFnZS9XZWJQ
YWdlLmNwcAkod29ya2luZyBjb3B5KQpAQCAtMTU1NCw2ICsxNTU0LDE0IEBAIHZvaWQgV2ViUGFn
ZTo6ZGlkQ2hhbmdlU2VsZWN0ZWRJbmRleEZvckEKICAgICBtX2FjdGl2ZVBvcHVwTWVudSA9IDA7
CiB9CiAKKyNpZiBFTkFCTEUoV0VCX1BST0NFU1NfU0FOREJPWCkKK3ZvaWQgV2ViUGFnZTo6ZXh0
ZW5kU2FuZGJveEZvckZpbGVGcm9tT3BlblBhbmVsKGNvbnN0IFNhbmRib3hFeHRlbnNpb246Okhh
bmRsZSYgaGFuZGxlKQoreworICAgIFJlZlB0cjxTYW5kYm94RXh0ZW5zaW9uPiBleHRlbnNpb24g
PSBTYW5kYm94RXh0ZW5zaW9uOjpjcmVhdGUoaGFuZGxlKTsKKyAgICBleHRlbnNpb24tPmNvbnN1
bWVQZXJtYW5lbnRseSgpOworfQorI2VuZGlmCisKIHZvaWQgV2ViUGFnZTo6ZGlkQ2hvb3NlRmls
ZXNGb3JPcGVuUGFuZWwoY29uc3QgVmVjdG9yPFN0cmluZz4mIGZpbGVzKQogewogICAgIGlmICgh
bV9hY3RpdmVPcGVuUGFuZWxSZXN1bHRMaXN0ZW5lcikKSW5kZXg6IFNvdXJjZS9XZWJLaXQyL1dl
YlByb2Nlc3MvV2ViUGFnZS9XZWJQYWdlLmgKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291cmNlL1dlYktpdDIv
V2ViUHJvY2Vzcy9XZWJQYWdlL1dlYlBhZ2UuaAkocmV2aXNpb24gNzgxNTgpCisrKyBTb3VyY2Uv
V2ViS2l0Mi9XZWJQcm9jZXNzL1dlYlBhZ2UvV2ViUGFnZS5oCSh3b3JraW5nIGNvcHkpCkBAIC00
MzIsNiArNDMyLDkgQEAgcHJpdmF0ZToKIAogICAgIHZvaWQgZGlkQ2hvb3NlRmlsZXNGb3JPcGVu
UGFuZWwoY29uc3QgVmVjdG9yPFN0cmluZz4mKTsKICAgICB2b2lkIGRpZENhbmNlbEZvck9wZW5Q
YW5lbCgpOworI2lmIEVOQUJMRShXRUJfUFJPQ0VTU19TQU5EQk9YKQorICAgIHZvaWQgZXh0ZW5k
U2FuZGJveEZvckZpbGVGcm9tT3BlblBhbmVsKGNvbnN0IFNhbmRib3hFeHRlbnNpb246OkhhbmRs
ZSYpOworI2VuZGlmCiAKICAgICB2b2lkIGRpZFJlY2VpdmVHZW9sb2NhdGlvblBlcm1pc3Npb25E
ZWNpc2lvbih1aW50NjRfdCBnZW9sb2NhdGlvbklELCBib29sIGFsbG93ZWQpOwogCkluZGV4OiBT
b3VyY2UvV2ViS2l0Mi9XZWJQcm9jZXNzL1dlYlBhZ2UvV2ViUGFnZS5tZXNzYWdlcy5pbgo9PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09Ci0tLSBTb3VyY2UvV2ViS2l0Mi9XZWJQcm9jZXNzL1dlYlBhZ2UvV2ViUGFnZS5tZXNz
YWdlcy5pbgkocmV2aXNpb24gNzgxNTgpCisrKyBTb3VyY2UvV2ViS2l0Mi9XZWJQcm9jZXNzL1dl
YlBhZ2UvV2ViUGFnZS5tZXNzYWdlcy5pbgkod29ya2luZyBjb3B5KQpAQCAtMTI3LDYgKzEyNyw5
IEBAIG1lc3NhZ2VzIC0+IFdlYlBhZ2UgewogICAgICMgT3BlbiBwYW5lbC4KICAgICBEaWRDaG9v
c2VGaWxlc0Zvck9wZW5QYW5lbChWZWN0b3I8V1RGOjpTdHJpbmc+IGZpbGVVUkxzKQogICAgIERp
ZENhbmNlbEZvck9wZW5QYW5lbCgpCisjaWYgRU5BQkxFKFdFQl9QUk9DRVNTX1NBTkRCT1gpCisg
ICAgRXh0ZW5kU2FuZGJveEZvckZpbGVGcm9tT3BlblBhbmVsKFdlYktpdDo6U2FuZGJveEV4dGVu
c2lvbjo6SGFuZGxlIHNhbmRib3hFeHRlbnNpb25IYW5kbGUpCisjZW5kaWYKIAogICAgICMgU3Bl
bGxpbmcgYW5kIGdyYW1tYXIuCiAgICAgQWR2YW5jZVRvTmV4dE1pc3NwZWxsaW5nKGJvb2wgc3Rh
cnRCZWZvcmVTZWxlY3Rpb24pCg==
</data>
<flag name="review"
          id="73506"
          type_id="1"
          status="+"
          setter="darin"
    />
          </attachment>
      

    </bug>

</bugzilla>