Files
sousa-gecko/testing/web-platform/tests/gamepad
Rob Pitkin 1f321637b3 Bug 2053684 [wpt PR 61169] - Reland "gamepad: Check Permissions Policy when binding Mojo interfaces", a=testonly
Automatic update from web-platform-tests
Reland "gamepad: Check Permissions Policy when binding Mojo interfaces"

This is a reland of commit db75f6e59c46921c91def1afd42b6f5f6e4246f with
fixes to prevent renderer crashes when gamepad access is blocked.

Original CL description:
> GamepadMonitor::Create() and GamepadHapticsManager::Create() were
> missing browser-side checks for the "gamepad" Permissions Policy. This
> allowed a compromised renderer to bypass renderer-side checks and access
> gamepad data or trigger haptics by binding the Mojo interfaces directly.
>
> This CL adds the missing checks in browser_interface_binders.cc using
> lambda wrappers to check if the feature is enabled for the
> RenderFrameHost before binding the receiver.

Fixes included in this reland:
- In the renderer (`GamepadSharedMemoryReader` and `GamepadDispatcher`),
  verify that `PermissionsPolicyFeature::kGamepad` is enabled before
  attempting to bind `GamepadMonitor` or `GamepadHapticsManager`.
  Previously, these were bound unconditionally, which triggered the
  newly added browser-side bad message enforcement and killed the
  renderer when the policy was blocked (e.g. in WebView).
- Guarding these changes with the `kEnforceGamepadPermissionsPolicy`
  feature flag

Verified locally with a test debug page.

Bug: 490277996
Change-Id: I0702f042e8474710d02ca7c64cde9711e669f540
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7927669
Reviewed-by: Roger McFarlane <rogerm@chromium.org>
Reviewed-by: Avi Drissman <avi@chromium.org>
Reviewed-by: Matt Reynolds <mattreynolds@chromium.org>
Commit-Queue: Rob Pitkin <robpitkin@chromium.org>
Reviewed-by: Fred Shih <ffred@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1659152}

--

wpt-commits: a81cf0688ace0e14ef6732ec4151cfe24ea546a9
wpt-pr: 61169
2026-07-12 11:58:06 +00:00
..
…