Closed Bug 1360356 Opened 3 years ago Closed 3 years ago

[Mac] Remove "/Library/Caches/TemporaryItems" rule from level 3 Content Sandbox

Categories

(Core :: Security: Process Sandboxing, enhancement)

55 Branch
Unspecified
macOS
enhancement
Not set

Tracking

()

RESOLVED FIXED
mozilla55
Tracking Status
firefox55 --- fixed

People

(Reporter: haik, Assigned: haik)

References

Details

(Whiteboard: sbmc2)

Attachments

(1 file)

In the Mac content sandbox rules, we have the following rule allowing read access to the directory ~/Library/Caches/TemporaryItems.

  ; bug 1201935
    (allow file-read*
        (home-subpath "/Library/Caches/TemporaryItems"))

Bug 1201935 indicates this was to allow WebExtensions tests to pass. We should test if that is still true or not.

If WebExtension tests still depend on reading from this directory, bug 1334550 "Proxy moz-extension protocol requests to the parent process", should fix that.

Marking this as a dependency of 1334550 for now.
Assignee: nobody → haftandilian
Depends on: 1334550
Whiteboard: sbmc2
Duplicate of this bug: 1360556
This rule is still needed for WebExtension tests. Without it, we hit several failures in WebExtensions on try:

  https://treeherder.mozilla.org/#/jobs?repo=try&revision=5d7dc6d776921ed13cedfcc0c33f28115112b8e4

With the dev fix for Bug 1334550 that remotes moz-extension loads to the parent:

  https://treeherder.mozilla.org/#/jobs?repo=try&revision=f9580e6abb1a1e4595bac89fc406c978c7c1c1f9
Comment on attachment 8863049 [details]
Bug 1360356 - [Mac] Remove "/Library/Caches/TemporaryItems" rule from level 3 Content Sandbox;

https://reviewboard.mozilla.org/r/134884/#review138050
Attachment #8863049 - Flags: review?(agaynor) → review+
Pushed by haftandilian@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/ab31c96ca883
[Mac] Remove "/Library/Caches/TemporaryItems" rule from level 3 Content Sandbox; r=Alex_Gaynor
Pushed by ihsiao@mozilla.com:
https://hg.mozilla.org/mozilla-central/rev/5178fedbc8f2
[Mac] Remove "/Library/Caches/TemporaryItems" rule from level 3 Content Sandbox; r=Alex_Gaynor. a=merge
https://hg.mozilla.org/mozilla-central/rev/5178fedbc8f2
Status: NEW → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla55
You need to log in before you can comment on or make changes to this bug.