Restrict "darwin-notification-post" to a minimal set in the WP sandbox on macOS and iOS.
<rdar://66586792>
Created attachment 441088 [details] Patch
Comment on attachment 441088 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=441088&action=review r=me > Source/WebKit/Resources/SandboxProfiles/ios/com.apple.WebKit.WebContent.sb.in:1577 > +(allow darwin-notification-post (with telemetry) Do we need to collect telemetry on the items we allow? Presumably we allow them because we know we need them?
(In reply to Brent Fulgham from comment #3) > Comment on attachment 441088 [details] > Patch > > View in context: > https://bugs.webkit.org/attachment.cgi?id=441088&action=review > > r=me > > > Source/WebKit/Resources/SandboxProfiles/ios/com.apple.WebKit.WebContent.sb.in:1577 > > +(allow darwin-notification-post (with telemetry) > > Do we need to collect telemetry on the items we allow? Presumably we allow > them because we know we need them? Yes, that is a good point; I'll remove the telemetry. Thanks for reviewing!
Created attachment 441111 [details] Patch
Committed r284119 (242939@main): <https://commits.webkit.org/242939@main> All reviewed patches have been landed. Closing bug and clearing flags on attachment 441111 [details].