Diff
Modified: branches/safari-611-branch/LayoutTests/ChangeLog (276665 => 276666)
--- branches/safari-611-branch/LayoutTests/ChangeLog 2021-04-27 21:07:20 UTC (rev 276665)
+++ branches/safari-611-branch/LayoutTests/ChangeLog 2021-04-27 21:07:24 UTC (rev 276666)
@@ -1,5 +1,49 @@
2021-04-27 Russell Epstein <[email protected]>
+ Cherry-pick r276012. rdar://problem/77211405
+
+ REGRESSION(Safari 14): iframe with blob url does not work with sandboxing
+ https://bugs.webkit.org/show_bug.cgi?id=222312
+ <rdar://problem/74927624>
+
+ Reviewed by Chris Dumez.
+
+ Source/WebCore:
+
+ In https://trac.webkit.org/r275884, we correctly compute whether a blob is to be considered secure or not.
+ For that, we need to have the blob URL registered with its document origin.
+ Update PolicyChecker to properly register the temporoary blob URL with its document origin.
+
+ Test: http/tests/security/sandbox-iframe-and-blob.https.html
+
+ * loader/PolicyChecker.cpp:
+ (WebCore::FrameLoader::PolicyChecker::extendBlobURLLifetimeIfNecessary const):
+
+ LayoutTests:
+
+ * http/tests/security/resources/sandbox-iframe-and-blob-frame.html: Added.
+ * http/tests/security/sandbox-iframe-and-blob.https-expected.txt: Added.
+ * http/tests/security/sandbox-iframe-and-blob.https.html: Added.
+ * platform/win/TestExpectations:
+
+
+ git-svn-id: https://svn.webkit.org/repository/webkit/trunk@276012 268f45cc-cd09-0410-ab3c-d52691b4dbfc
+
+ 2021-04-15 Youenn Fablet <[email protected]>
+
+ REGRESSION(Safari 14): iframe with blob url does not work with sandboxing
+ https://bugs.webkit.org/show_bug.cgi?id=222312
+ <rdar://problem/74927624>
+
+ Reviewed by Chris Dumez.
+
+ * http/tests/security/resources/sandbox-iframe-and-blob-frame.html: Added.
+ * http/tests/security/sandbox-iframe-and-blob.https-expected.txt: Added.
+ * http/tests/security/sandbox-iframe-and-blob.https.html: Added.
+ * platform/win/TestExpectations:
+
+2021-04-27 Russell Epstein <[email protected]>
+
Cherry-pick r274170. rdar://problem/77194450
REGRESSION (r273003): Animated style may lose original display property value
Added: branches/safari-611-branch/LayoutTests/http/tests/security/resources/sandbox-iframe-and-blob-frame.html (0 => 276666)
--- branches/safari-611-branch/LayoutTests/http/tests/security/resources/sandbox-iframe-and-blob-frame.html (rev 0)
+++ branches/safari-611-branch/LayoutTests/http/tests/security/resources/sandbox-iframe-and-blob-frame.html 2021-04-27 21:07:24 UTC (rev 276666)
@@ -0,0 +1,15 @@
+<!DOCTYPE html>
+<html>
+<body>
+ <iframe id="myFrame"></iframe>
+ <script>
+const html = "<body" + ">PASS<script" + ">parent.postMessage('loaded', '*')</"+ "script></" + "body>";
+var blob = new Blob([html], {type: 'text/html'});
+var url = ""
+myFrame.src = ""
+window._onmessage_ = (event) => {
+ parent.postMessage(event.data, '*');
+};
+ </script>
+</body>
+</html>
Added: branches/safari-611-branch/LayoutTests/http/tests/security/sandbox-iframe-and-blob.https-expected.txt (0 => 276666)
--- branches/safari-611-branch/LayoutTests/http/tests/security/sandbox-iframe-and-blob.https-expected.txt (rev 0)
+++ branches/safari-611-branch/LayoutTests/http/tests/security/sandbox-iframe-and-blob.https-expected.txt 2021-04-27 21:07:24 UTC (rev 276666)
@@ -0,0 +1,4 @@
+
+
+PASS Verify blob URLs are loaded with sandbox iframes
+
Added: branches/safari-611-branch/LayoutTests/http/tests/security/sandbox-iframe-and-blob.https.html (0 => 276666)
--- branches/safari-611-branch/LayoutTests/http/tests/security/sandbox-iframe-and-blob.https.html (rev 0)
+++ branches/safari-611-branch/LayoutTests/http/tests/security/sandbox-iframe-and-blob.https.html 2021-04-27 21:07:24 UTC (rev 276666)
@@ -0,0 +1,23 @@
+<!DOCTYPE html>
+<html>
+<head>
+ <meta charset="UTF-8">
+ <script src=""
+ <script src=""
+</head>
+<body>
+ <iframe id="myFrame" sandbox="allow-scripts"></iframe>
+ <script>
+promise_test(async () => {
+ myFrame.src = ""
+ const result = await new Promise((resolve, reject) => {
+ window._onmessage_ = (event) => {
+ resolve(event.data);
+ };
+ setTimeout(() => reject("iframe load timed out"), 5000);
+ });
+ assert_equals(result, 'loaded');
+}, "Verify blob URLs are loaded with sandbox iframes");
+ </script>
+</body>
+</html>
Modified: branches/safari-611-branch/LayoutTests/platform/win/TestExpectations (276665 => 276666)
--- branches/safari-611-branch/LayoutTests/platform/win/TestExpectations 2021-04-27 21:07:20 UTC (rev 276665)
+++ branches/safari-611-branch/LayoutTests/platform/win/TestExpectations 2021-04-27 21:07:24 UTC (rev 276666)
@@ -2330,6 +2330,7 @@
http/tests/security/contentSecurityPolicy/navigate-self-to-blob.html [ Skip ]
http/tests/security/contentSecurityPolicy/report-document-uri-blob.html [ Skip ]
fast/frames/restoring-page-cache-should-not-run-scripts-via-style-update.html [ Skip ]
+http/tests/security/sandbox-iframe-and-blob.https.html [ Skip ]
# Clear Key not implemented
http/tests/media/clearkey/clear-key-hls-aes128.html [ Skip ] # Timeout
Modified: branches/safari-611-branch/Source/WebCore/ChangeLog (276665 => 276666)
--- branches/safari-611-branch/Source/WebCore/ChangeLog 2021-04-27 21:07:20 UTC (rev 276665)
+++ branches/safari-611-branch/Source/WebCore/ChangeLog 2021-04-27 21:07:24 UTC (rev 276666)
@@ -1,5 +1,53 @@
2021-04-27 Russell Epstein <[email protected]>
+ Cherry-pick r276012. rdar://problem/77211405
+
+ REGRESSION(Safari 14): iframe with blob url does not work with sandboxing
+ https://bugs.webkit.org/show_bug.cgi?id=222312
+ <rdar://problem/74927624>
+
+ Reviewed by Chris Dumez.
+
+ Source/WebCore:
+
+ In https://trac.webkit.org/r275884, we correctly compute whether a blob is to be considered secure or not.
+ For that, we need to have the blob URL registered with its document origin.
+ Update PolicyChecker to properly register the temporoary blob URL with its document origin.
+
+ Test: http/tests/security/sandbox-iframe-and-blob.https.html
+
+ * loader/PolicyChecker.cpp:
+ (WebCore::FrameLoader::PolicyChecker::extendBlobURLLifetimeIfNecessary const):
+
+ LayoutTests:
+
+ * http/tests/security/resources/sandbox-iframe-and-blob-frame.html: Added.
+ * http/tests/security/sandbox-iframe-and-blob.https-expected.txt: Added.
+ * http/tests/security/sandbox-iframe-and-blob.https.html: Added.
+ * platform/win/TestExpectations:
+
+
+ git-svn-id: https://svn.webkit.org/repository/webkit/trunk@276012 268f45cc-cd09-0410-ab3c-d52691b4dbfc
+
+ 2021-04-15 Youenn Fablet <[email protected]>
+
+ REGRESSION(Safari 14): iframe with blob url does not work with sandboxing
+ https://bugs.webkit.org/show_bug.cgi?id=222312
+ <rdar://problem/74927624>
+
+ Reviewed by Chris Dumez.
+
+ In https://trac.webkit.org/r275884, we correctly compute whether a blob is to be considered secure or not.
+ For that, we need to have the blob URL registered with its document origin.
+ Update PolicyChecker to properly register the temporoary blob URL with its document origin.
+
+ Test: http/tests/security/sandbox-iframe-and-blob.https.html
+
+ * loader/PolicyChecker.cpp:
+ (WebCore::FrameLoader::PolicyChecker::extendBlobURLLifetimeIfNecessary const):
+
+2021-04-27 Russell Epstein <[email protected]>
+
Cherry-pick r276611. rdar://problem/77211533
Remove redundant frameDetached() from the SVGImage destructor
Modified: branches/safari-611-branch/Source/WebCore/loader/PolicyChecker.cpp (276665 => 276666)
--- branches/safari-611-branch/Source/WebCore/loader/PolicyChecker.cpp 2021-04-27 21:07:20 UTC (rev 276665)
+++ branches/safari-611-branch/Source/WebCore/loader/PolicyChecker.cpp 2021-04-27 21:07:24 UTC (rev 276666)
@@ -47,6 +47,7 @@
#include "HTMLFrameOwnerElement.h"
#include "HTMLPlugInElement.h"
#include "Logging.h"
+#include "ThreadableBlobRegistry.h"
#include <wtf/CompletionHandler.h>
#if USE(QUICK_LOOK)
@@ -111,12 +112,12 @@
// Create a new temporary blobURL in case this one gets revoked during the asynchronous navigation policy decision.
URL temporaryBlobURL = BlobURL::createPublicURL(&m_frame.document()->securityOrigin());
- blobRegistry().registerBlobURL(temporaryBlobURL, request.url());
+ ThreadableBlobRegistry::registerBlobURL(&m_frame.document()->securityOrigin(), temporaryBlobURL, request.url());
request.setURL(temporaryBlobURL);
if (loader)
loader->request().setURL(temporaryBlobURL);
return CompletionHandler<void()>([temporaryBlobURL = WTFMove(temporaryBlobURL)] {
- blobRegistry().unregisterBlobURL(temporaryBlobURL);
+ ThreadableBlobRegistry::unregisterBlobURL(temporaryBlobURL);
});
}