Bug 237009

Summary: Allow adattributiond to start on iOS devices
Product: WebKit Reporter: Alex Christensen <achristensen>
Component: New BugsAssignee: Alex Christensen <achristensen>
Status: RESOLVED FIXED    
Severity: Normal CC: pvollan, webkit-bug-importer
Priority: P2 Keywords: InRadar
Version: WebKit Nightly Build   
Hardware: Unspecified   
OS: Unspecified   
Attachments:
Description Flags
Patch
none
Patch achristensen: commit-queue+

Alex Christensen
Reported 2022-02-21 17:11:16 PST
Allow adattributiond to start on iOS devices
Attachments
Patch (2.67 KB, patch)
2022-02-21 17:13 PST, Alex Christensen
no flags
Patch (3.99 KB, patch)
2022-02-21 17:47 PST, Alex Christensen
achristensen: commit-queue+
Alex Christensen
Comment 1 2022-02-21 17:13:45 PST
Alex Christensen
Comment 2 2022-02-21 17:13:49 PST
Per Arne Vollan
Comment 3 2022-02-21 17:16:29 PST
Comment on attachment 452801 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=452801&action=review R=me. > Source/WebKit/Resources/SandboxProfiles/ios/com.apple.WebKit.adattributiond.sb:79 > +(allow file-read* file-map-executable > + (subpath "/System/Library/Frameworks") > + (subpath "/System/Library/PrivateFrameworks")) > + Could this be limited to only the WebKit framework?
Alex Christensen
Comment 4 2022-02-21 17:47:33 PST
Alex Christensen
Comment 5 2022-02-21 17:48:48 PST
(In reply to Per Arne Vollan from comment #3) > Comment on attachment 452801 [details] > Patch > > View in context: > https://bugs.webkit.org/attachment.cgi?id=452801&action=review > > R=me. > > > Source/WebKit/Resources/SandboxProfiles/ios/com.apple.WebKit.adattributiond.sb:79 > > +(allow file-read* file-map-executable > > + (subpath "/System/Library/Frameworks") > > + (subpath "/System/Library/PrivateFrameworks")) > > + > > Could this be limited to only the WebKit framework? We need CFNetwork, among others. I'm basing the abilities I'm adding on what the network process has access to.
Alex Christensen
Comment 6 2022-02-21 20:57:57 PST
Note You need to log in before you can comment on or make changes to this bug.