[Extensions] Validate process authorization in AutomationEventRouter::BindAutomation [chromium/src : main]

0 views
Skip to first unread message

Devlin Cronin (Gerrit)

unread,
Aug 14, 2026, 4:40:18 PM (2 days ago) Aug 14
to David Tseng, Andrea Orru, Devlin Cronin, Chromium LUCI CQ, Chromium Metrics Reviews, chromium...@chromium.org, asvitkine...@chromium.org, chromium-a...@chromium.org, extension...@chromium.org
Attention needed from Andrea Orru and David Tseng

Devlin Cronin added 2 comments

Patchset-level comments
File-level comment, Patchset 3 (Latest):
Devlin Cronin . resolved

Thanks, David! I'm going to punt this one to Andrea, who knows mojo better than I do, but one comment. (Andrea, feel free to confirm / deny / expand : ))

File extensions/browser/api/automation_internal/automation_event_router.cc
Line 345, Patchset 3 (Latest):void AutomationEventRouter::BindAutomation(
Devlin Cronin . unresolved

Interestingly, this binds *another* interface, but this method itself is an IPC from the renderer to the RendererAutomationRegistry -- which was already bound. This means that we'll prevent binding of this new interface (which is good), but I think it'd be better to pull it a step higher and prevent binding the RendererAutomationRegistry at all (which I think happens [here](https://source.chromium.org/chromium/chromium/src/+/main:extensions/browser/api/automation_internal/automation_event_router.cc;l=348-356;drc=2f59ca9d5a2454810abc62d5a235b4347c7e90c4)).

Would that work?

Open in Gerrit

Related details

Attention is currently required from:
  • Andrea Orru
  • David Tseng
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement is not satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement is not satisfiedNo-Unresolved-Comments
  • requirement is not satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I107134d7419d5b797a3068932972feb097bb3f9c
Gerrit-Change-Number: 8259787
Gerrit-PatchSet: 3
Gerrit-Owner: David Tseng <dts...@chromium.org>
Gerrit-Reviewer: Andrea Orru <andre...@chromium.org>
Gerrit-Reviewer: David Tseng <dts...@chromium.org>
Gerrit-Reviewer: Devlin Cronin <rdevlin...@chromium.org>
Gerrit-CC: Chromium Metrics Reviews <chromium-met...@google.com>
Gerrit-Attention: Andrea Orru <andre...@chromium.org>
Gerrit-Attention: David Tseng <dts...@chromium.org>
Gerrit-Comment-Date: Fri, 14 Aug 2026 20:40:05 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
satisfied_requirement
unsatisfied_requirement
open
diffy

David Tseng (Gerrit)

unread,
Aug 14, 2026, 7:24:09 PM (2 days ago) Aug 14
to Andrea Orru, Devlin Cronin, Chromium LUCI CQ, Chromium Metrics Reviews, chromium...@chromium.org, asvitkine...@chromium.org, chromium-a...@chromium.org, extension...@chromium.org
Attention needed from Andrea Orru and Devlin Cronin

David Tseng added 1 comment

File extensions/browser/api/automation_internal/automation_event_router.cc
Line 345, Patchset 3:void AutomationEventRouter::BindAutomation(
Devlin Cronin . resolved

Interestingly, this binds *another* interface, but this method itself is an IPC from the renderer to the RendererAutomationRegistry -- which was already bound. This means that we'll prevent binding of this new interface (which is good), but I think it'd be better to pull it a step higher and prevent binding the RendererAutomationRegistry at all (which I think happens [here](https://source.chromium.org/chromium/chromium/src/+/main:extensions/browser/api/automation_internal/automation_event_router.cc;l=348-356;drc=2f59ca9d5a2454810abc62d5a235b4347c7e90c4)).

Would that work?

David Tseng

Good call; done :).

Open in Gerrit

Related details

Attention is currently required from:
  • Andrea Orru
  • Devlin Cronin
Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement is not satisfiedCode-Owners
    • requirement is not satisfiedCode-Review
    • requirement is not satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I107134d7419d5b797a3068932972feb097bb3f9c
    Gerrit-Change-Number: 8259787
    Gerrit-PatchSet: 4
    Gerrit-Owner: David Tseng <dts...@chromium.org>
    Gerrit-Reviewer: Andrea Orru <andre...@chromium.org>
    Gerrit-Reviewer: David Tseng <dts...@chromium.org>
    Gerrit-Reviewer: Devlin Cronin <rdevlin...@chromium.org>
    Gerrit-CC: Chromium Metrics Reviews <chromium-met...@google.com>
    Gerrit-Attention: Devlin Cronin <rdevlin...@chromium.org>
    Gerrit-Attention: Andrea Orru <andre...@chromium.org>
    Gerrit-Comment-Date: Fri, 14 Aug 2026 23:23:51 +0000
    Gerrit-HasComments: Yes
    Gerrit-Has-Labels: No
    Comment-In-Reply-To: Devlin Cronin <rdevlin...@chromium.org>
    satisfied_requirement
    unsatisfied_requirement
    open
    diffy
    Reply all
    Reply to author
    Forward
    0 new messages