This actor property defaults to false. If it is set to false, and the preference dom.jsipc.check_safeForUntrustedWebProcess is set to true, then the actor cannot be loaded into a web or file process. The idea is that if an actor can be put in a process that can contain web content, then it is be a potential vector for a sandbox escape, so you should have to opt-in to that behavior. In addition to adding some tests for this behavior, this patch also adds the safeForUntrustedWebProcess property to the test actors TestWindow and TestProcessActor in dom/ipc/tests/. The properties are added to actors in earlier patches because the new tests that flip the pref to true will fail otherwise. In other words, those tests serve as a basic smoke test for the browser working when the pref is true. Differential Revision: https://phabricator.services.mozilla.com/D302128
87 lines
2.5 KiB
JavaScript
87 lines
2.5 KiB
JavaScript
/* Any copyright is dedicated to the Public Domain.
|
|
http://creativecommons.org/publicdomain/zero/1.0/ */
|
|
|
|
/**
|
|
* Provide infrastructure for JSProcessActor tests.
|
|
*/
|
|
|
|
const URL = "about:blank";
|
|
const TEST_URL = "http://test2.example.org/";
|
|
let processActorOptions = {
|
|
parent: {
|
|
esModuleURI: "resource://testing-common/TestProcessActorParent.sys.mjs",
|
|
},
|
|
child: {
|
|
esModuleURI: "resource://testing-common/TestProcessActorChild.sys.mjs",
|
|
observers: ["test-js-content-actor-child-observer"],
|
|
},
|
|
};
|
|
|
|
function promiseNotification(aNotification) {
|
|
let notificationResolve;
|
|
let notificationObserver = function observer() {
|
|
notificationResolve();
|
|
Services.obs.removeObserver(notificationObserver, aNotification);
|
|
};
|
|
return new Promise(resolve => {
|
|
notificationResolve = resolve;
|
|
Services.obs.addObserver(notificationObserver, aNotification);
|
|
});
|
|
}
|
|
|
|
function declTest(name, cfg) {
|
|
let {
|
|
url = "about:blank",
|
|
includeParent = false,
|
|
remoteTypes,
|
|
safeForUntrustedWebProcess = true,
|
|
safeForUntrustedWebProcessPref = undefined,
|
|
loadInDevToolsLoader = false,
|
|
test,
|
|
} = cfg;
|
|
|
|
// Build the actor options object which will be used to register & unregister
|
|
// our process actor.
|
|
let actorOptions = {
|
|
parent: Object.assign({}, processActorOptions.parent),
|
|
child: Object.assign({}, processActorOptions.child),
|
|
};
|
|
actorOptions.includeParent = includeParent;
|
|
if (remoteTypes !== undefined) {
|
|
actorOptions.remoteTypes = remoteTypes;
|
|
}
|
|
actorOptions.safeForUntrustedWebProcess = safeForUntrustedWebProcess;
|
|
if (loadInDevToolsLoader) {
|
|
actorOptions.loadInDevToolsLoader = true;
|
|
}
|
|
|
|
// Add a new task for the actor test declared here.
|
|
add_task(async function () {
|
|
info("Entering test: " + name);
|
|
|
|
if (safeForUntrustedWebProcessPref !== undefined) {
|
|
await SpecialPowers.pushPrefEnv({
|
|
set: [
|
|
[
|
|
"dom.jsipc.check_safeForUntrustedWebProcess",
|
|
safeForUntrustedWebProcessPref,
|
|
],
|
|
],
|
|
});
|
|
}
|
|
|
|
// Register our actor, and load a new tab with the provided URL
|
|
ChromeUtils.registerProcessActor("TestProcessActor", actorOptions);
|
|
try {
|
|
await BrowserTestUtils.withNewTab(url, async browser => {
|
|
info("browser ready");
|
|
await Promise.resolve(test(browser, window));
|
|
});
|
|
} finally {
|
|
// Unregister the actor after the test is complete.
|
|
ChromeUtils.unregisterProcessActor("TestProcessActor");
|
|
info("Exiting test: " + name);
|
|
}
|
|
});
|
|
}
|