Title: [240811] trunk/Source/WebKit
Revision
240811
Author
pvol...@apple.com
Date
2019-01-31 13:43:01 -0800 (Thu, 31 Jan 2019)

Log Message

[macOS] Disable permissive call logging in sandbox
https://bugs.webkit.org/show_bug.cgi?id=194061

Reviewed by Alexey Proskuryakov.

Strict call filtering should be reenabled.

* WebProcess/com.apple.WebProcess.sb.in:

Modified Paths

Diff

Modified: trunk/Source/WebKit/ChangeLog (240810 => 240811)


--- trunk/Source/WebKit/ChangeLog	2019-01-31 21:40:59 UTC (rev 240810)
+++ trunk/Source/WebKit/ChangeLog	2019-01-31 21:43:01 UTC (rev 240811)
@@ -1,5 +1,16 @@
 2019-01-31  Per Arne Vollan  <pvol...@apple.com>
 
+        [macOS] Disable permissive call logging in sandbox
+        https://bugs.webkit.org/show_bug.cgi?id=194061
+
+        Reviewed by Alexey Proskuryakov.
+
+        Strict call filtering should be reenabled.
+
+        * WebProcess/com.apple.WebProcess.sb.in:
+
+2019-01-31  Per Arne Vollan  <pvol...@apple.com>
+
         [macOS] Crash when control-clicking or copying text rendered with a web font
         https://bugs.webkit.org/show_bug.cgi?id=193913
         <rdar://problem/47541039>

Modified: trunk/Source/WebKit/WebProcess/com.apple.WebProcess.sb.in (240810 => 240811)


--- trunk/Source/WebKit/WebProcess/com.apple.WebProcess.sb.in	2019-01-31 21:40:59 UTC (rev 240810)
+++ trunk/Source/WebKit/WebProcess/com.apple.WebProcess.sb.in	2019-01-31 21:43:01 UTC (rev 240811)
@@ -830,6 +830,7 @@
 #endif // PLATFORM(MAC)
 
 (when (defined? 'syscall-unix)
+    (deny syscall-unix (with send-signal SIGKILL))
     (allow syscall-unix
         (syscall-number SYS_exit)
         (syscall-number SYS_read)
@@ -959,6 +960,7 @@
         (syscall-number SYS_necp_client_action)
         (syscall-number SYS_ulock_wait)
         (syscall-number SYS_ulock_wake)
+        (syscall-number SYS_work_interval_ctl)
     )
 )
 
_______________________________________________
webkit-changes mailing list
webkit-changes@lists.webkit.org
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to