RESOLVED FIXED 201810
Create InjectedBundle SPI to better support NSSecureCoding
https://bugs.webkit.org/show_bug.cgi?id=201810
Summary Create InjectedBundle SPI to better support NSSecureCoding
Brent Fulgham
Reported Sunday, September 15, 2019 11:34:11 PM UTC
The encoding/decoding routines used by WebKit’s InjectedBundles are based on NSCoding. While we have changed WebKit internals to use NSSecureCoding, there are a number of injected bundles that need to serialize custom classes between the InjectedBundle and the relevant WebKit UIProcess. We need to lock down this communications channel by enforcing NSSecureCoding. This patch creates new SPI to allow the UIProcess to specify classes that it will accept in messages from the WebContet Process (and Injected Bundle). It adds the following property to the WKProcessPoolConfiguration: @property (nonatomic, copy) NSSet<Class> *customClassesForParameterCoder; Clients that wish to serialize custom classes would do something like the following: _WKProcessPoolConfiguration *configuration = [[_WKProcessPoolConfiguration alloc] init]; ... various setup steps ... // An InjectedBundle will be used: [configuration setInjectedBundleURL:[[NSBundle mainBundle].builtInPlugInsURL URLByAppendingPathComponent:@"Example.wkbundle" isDirectory:YES]]; // So specify any custom classes for the use case: [configuration setCustomClassesForParameterCoder:[NSSet setWithObjects:[Example1 class], [Example2 class], [Example3 class], nil]]; If no custom classes are specified, the standard serialization primitives are supported: NSArray, NSData, NSDate, NSDictionary, NSNull, NSNumber, NSSet, NSString, NSTimeZone, NSURL, and NSUUID.
Attachments
Patch (18.63 KB, patch)
2019-09-15 15:43 PDT, Brent Fulgham
no flags
Patch (18.70 KB, patch)
2019-09-15 15:58 PDT, Brent Fulgham
no flags
Patch for landing (48.73 KB, patch)
2019-09-17 17:25 PDT, Brent Fulgham
no flags
Patch for landing (44.41 KB, patch)
2019-09-17 17:27 PDT, Brent Fulgham
no flags
Patch for landing (43.65 KB, patch)
2019-09-17 17:35 PDT, Brent Fulgham
no flags
Patch (46.13 KB, patch)
2019-09-17 20:14 PDT, Brent Fulgham
no flags
Patch (45.59 KB, patch)
2019-09-18 16:59 PDT, Brent Fulgham
no flags
Patch for landing (45.59 KB, patch)
2019-09-19 08:50 PDT, Brent Fulgham
no flags
Brent Fulgham
Comment 1 Sunday, September 15, 2019 11:36:28 PM UTC
Brent Fulgham
Comment 2 Sunday, September 15, 2019 11:43:07 PM UTC
Brent Fulgham
Comment 3 Sunday, September 15, 2019 11:58:47 PM UTC
Brent Fulgham
Comment 4 Sunday, September 15, 2019 11:59:38 PM UTC
WIP patch uploaded for initial discussion of SPI design.
Brady Eidson
Comment 5 Monday, September 16, 2019 6:50:45 PM UTC
Comment on attachment 378829 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=378829&action=review > Source/WebKit/ChangeLog:7 > + The encoding/decoding routines used by WebKitâs InjectedBundles are based on NSCoding. WebKitâs
Brent Fulgham
Comment 6 Wednesday, September 18, 2019 1:25:37 AM UTC
Created attachment 379009 [details] Patch for landing
Brent Fulgham
Comment 7 Wednesday, September 18, 2019 1:27:25 AM UTC
Created attachment 379010 [details] Patch for landing
Brent Fulgham
Comment 8 Wednesday, September 18, 2019 1:35:13 AM UTC
Created attachment 379012 [details] Patch for landing
Brent Fulgham
Comment 9 Wednesday, September 18, 2019 4:14:41 AM UTC
Brent Fulgham
Comment 10 Thursday, September 19, 2019 12:59:06 AM UTC
Brent Fulgham
Comment 11 Thursday, September 19, 2019 4:34:45 PM UTC
The WinCairo error is a bot issue.
Brent Fulgham
Comment 12 Thursday, September 19, 2019 4:50:59 PM UTC
Created attachment 379135 [details] Patch for landing
WebKit Commit Bot
Comment 13 Thursday, September 19, 2019 5:11:37 PM UTC
Comment on attachment 379135 [details] Patch for landing Clearing flags on attachment: 379135 Committed r250093: <https://trac.webkit.org/changeset/250093>
WebKit Commit Bot
Comment 14 Thursday, September 19, 2019 5:11:39 PM UTC
All reviewed patches have been landed. Closing bug.
Note You need to log in before you can comment on or make changes to this bug.