[ios] Mark processes as sandboxed that aren't the browser [chromium/src : main]

0 views
Skip to first unread message

Will Harris (Gerrit)

unread,
Jul 18, 2025, 5:31:23 PM7/18/25
to Dave Tapuska, Will Harris, chromium...@chromium.org
Attention needed from Dave Tapuska

Will Harris added 1 comment

File sandbox/policy/sandbox.cc
Line 117, Patchset 1 (Latest): return !is_browser;
Will Harris . unresolved

does `Seatbelt::IsSandboxed` (aka `::sandbox_check`) not work on iOS?

Open in Gerrit

Related details

Attention is currently required from:
  • Dave Tapuska
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement is not satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement is not satisfiedNo-Unresolved-Comments
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I4c3c7296b758a40e49ef270f420f79b1d4937b1d
Gerrit-Change-Number: 6771247
Gerrit-PatchSet: 1
Gerrit-Owner: Dave Tapuska <dtap...@chromium.org>
Gerrit-Reviewer: Will Harris <w...@chromium.org>
Gerrit-Attention: Dave Tapuska <dtap...@chromium.org>
Gerrit-Comment-Date: Fri, 18 Jul 2025 21:31:13 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
satisfied_requirement
unsatisfied_requirement
open
diffy

Dave Tapuska (Gerrit)

unread,
Jul 18, 2025, 5:39:21 PM7/18/25
to Will Harris, chromium...@chromium.org
Attention needed from Will Harris

Dave Tapuska added 1 comment

File sandbox/policy/sandbox.cc
Line 117, Patchset 1 (Latest): return !is_browser;
Will Harris . unresolved

does `Seatbelt::IsSandboxed` (aka `::sandbox_check`) not work on iOS?

Dave Tapuska

No that isn't going to work. That API is not available for iOS.

Open in Gerrit

Related details

Attention is currently required from:
  • Will Harris
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement is not satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement is not satisfiedNo-Unresolved-Comments
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I4c3c7296b758a40e49ef270f420f79b1d4937b1d
Gerrit-Change-Number: 6771247
Gerrit-PatchSet: 1
Gerrit-Owner: Dave Tapuska <dtap...@chromium.org>
Gerrit-Reviewer: Will Harris <w...@chromium.org>
Gerrit-Attention: Will Harris <w...@chromium.org>
Gerrit-Comment-Date: Fri, 18 Jul 2025 21:39:12 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
Comment-In-Reply-To: Will Harris <w...@chromium.org>
satisfied_requirement
unsatisfied_requirement
open
diffy

Will Harris (Gerrit)

unread,
Jul 18, 2025, 5:41:23 PM7/18/25
to Dave Tapuska, Will Harris, chromium...@chromium.org
Attention needed from Dave Tapuska

Will Harris voted and added 1 comment

Votes added by Will Harris

Code-Review+1

1 comment

File sandbox/policy/sandbox.cc
Line 117, Patchset 1 (Latest): return !is_browser;
Will Harris . resolved

does `Seatbelt::IsSandboxed` (aka `::sandbox_check`) not work on iOS?

Dave Tapuska

No that isn't going to work. That API is not available for iOS.

Will Harris

okay!

Open in Gerrit

Related details

Attention is currently required from:
  • Dave Tapuska
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement satisfiedCode-Owners
  • requirement satisfiedCode-Review
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I4c3c7296b758a40e49ef270f420f79b1d4937b1d
Gerrit-Change-Number: 6771247
Gerrit-PatchSet: 1
Gerrit-Owner: Dave Tapuska <dtap...@chromium.org>
Gerrit-Reviewer: Will Harris <w...@chromium.org>
Gerrit-Attention: Dave Tapuska <dtap...@chromium.org>
Gerrit-Comment-Date: Fri, 18 Jul 2025 21:41:14 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: Yes
Comment-In-Reply-To: Dave Tapuska <dtap...@chromium.org>
Comment-In-Reply-To: Will Harris <w...@chromium.org>
satisfied_requirement
open
diffy

Dave Tapuska (Gerrit)

unread,
Jul 18, 2025, 5:45:08 PM7/18/25
to Will Harris, chromium...@chromium.org

Dave Tapuska voted Commit-Queue+2

Commit-Queue+2
Open in Gerrit

Related details

Attention set is empty
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement satisfiedCode-Owners
  • requirement satisfiedCode-Review
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I4c3c7296b758a40e49ef270f420f79b1d4937b1d
Gerrit-Change-Number: 6771247
Gerrit-PatchSet: 1
Gerrit-Owner: Dave Tapuska <dtap...@chromium.org>
Gerrit-Reviewer: Dave Tapuska <dtap...@chromium.org>
Gerrit-Reviewer: Will Harris <w...@chromium.org>
Gerrit-Comment-Date: Fri, 18 Jul 2025 21:44:59 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: Yes
satisfied_requirement
open
diffy

Chromium LUCI CQ (Gerrit)

unread,
Jul 18, 2025, 6:33:36 PM7/18/25
to Dave Tapuska, Will Harris, chromium...@chromium.org

Chromium LUCI CQ submitted the change

Change information

Commit message:
[ios] Mark processes as sandboxed that aren't the browser

BrowserEngineKit sandboxes processes it launches so return
that anything that isn't the browser is sandboxed.
Bug: 40254930
Change-Id: I4c3c7296b758a40e49ef270f420f79b1d4937b1d
Reviewed-by: Will Harris <w...@chromium.org>
Commit-Queue: Dave Tapuska <dtap...@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1489072}
Files:
  • M sandbox/policy/sandbox.cc
Change size: XS
Delta: 1 file changed, 4 insertions(+), 0 deletions(-)
Branch: refs/heads/main
Submit Requirements:
  • requirement satisfiedCode-Review: +1 by Will Harris
Open in Gerrit
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: merged
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I4c3c7296b758a40e49ef270f420f79b1d4937b1d
Gerrit-Change-Number: 6771247
Gerrit-PatchSet: 2
Gerrit-Owner: Dave Tapuska <dtap...@chromium.org>
Gerrit-Reviewer: Chromium LUCI CQ <chromiu...@luci-project-accounts.iam.gserviceaccount.com>
open
diffy
satisfied_requirement

luci-bisection@appspot.gserviceaccount.com (Gerrit)

unread,
Jul 18, 2025, 10:05:48 PM7/18/25
to Dave Tapuska, Chromium LUCI CQ, Will Harris, chromium...@chromium.org

Message from luci-bi...@appspot.gserviceaccount.com

LUCI Bisection has identified this change as the cause of a test failure. See the analysis: https://ci.chromium.org/ui/p/chromium/bisection/test-analysis/b/5113083862188032

Sample build with failed test: https://ci.chromium.org/b/8708966394389317473
Affected test(s):
[ninja://content/test:content_browsertests/MojoSandboxTest.NotIsProcessSandboxed](https://ci.chromium.org/ui/test/chromium/ninja:%2F%2Fcontent%2Ftest:content_browsertests%2FMojoSandboxTest.NotIsProcessSandboxed?q=VHash%3Aa70550d9f332f1c1)
A revert for this change was not created because the builder that this CL broke is not watched by gardeners, therefore less important. You can consider revert this CL, fix forward or let builder owners resolve it themselves.

If this is a false positive, please report it at http://b.corp.google.com/createIssue?component=1199205&description=Analysis%3A+https%3A%2F%2Fci.chromium.org%2Fui%2Fp%2Fchromium%2Fbisection%2Ftest-analysis%2Fb%2F5113083862188032&format=PLAIN&priority=P3&title=Wrongly+blamed+https%3A%2F%2Fchromium-review.googlesource.com%2Fc%2Fchromium%2Fsrc%2F%2B%2F6771247&type=BUG

Open in Gerrit

Related details

Attention set is empty
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement satisfiedCode-Owners
  • requirement satisfiedCode-Review
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I4c3c7296b758a40e49ef270f420f79b1d4937b1d
Gerrit-Change-Number: 6771247
Gerrit-PatchSet: 2
Gerrit-Owner: Dave Tapuska <dtap...@chromium.org>
Gerrit-Reviewer: Chromium LUCI CQ <chromiu...@luci-project-accounts.iam.gserviceaccount.com>
Gerrit-Reviewer: Dave Tapuska <dtap...@chromium.org>
Gerrit-Reviewer: Will Harris <w...@chromium.org>
Gerrit-Comment-Date: Sat, 19 Jul 2025 02:05:39 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: No
satisfied_requirement
open
diffy
Reply all
Reply to author
Forward
0 new messages