Drop transitive trust from transports Untrusted nodes could reflect a broker initiated transport back to a broker. This ultimately allows for handle leaks if the reflected transport was later used to deserialize another transport containing handles in the broker. This CL addresses this along several axes: 1. untrusted transports cannot return new links to brokers. 2. process trustiness on Windows is propagated when a transport is deserialized from a transport. Windows has a special additional level of trustiness associated with mojo peers via the is_remote_process_untrusted attribute (the MOJO_SEND_INVITATION_FLAG_UNTRUSTED_PROCESS in invitations). This affects how handles are sent between processes. This was a bool on all platforms which was confusing. This CL makes this attribute clearer. On Windows it is now a bi-state enum, while on other platforms it is simply kUntracked. This makes it easier to use default constructed values, and the same API on all platforms without using too many buildflag differences. This state was not being propagated correctly during transport deserialization, and is now set as the same trust as the process from which a deserialized transport came. Processes currently default to being kTrusted, which matches the current behavior of the bool flag. Finally, this CL turns a DCHECK into a CHECK to ensure peers are only elevated when expected. Bug: 412578726 Change-Id: I6741a3f53b26c3df854731177cdc886e9c8f7f11 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6497400 Reviewed-by: Daniel Cheng <dcheng@chromium.org> Commit-Queue: Alex Gough <ajgo@chromium.org> Cr-Commit-Position: refs/heads/main@{#1456055}
Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.
The project's web site is https://www.chromium.org.
To check out the source code locally, don't use git clone! Instead, follow the instructions on how to get the code.
Documentation in the source is rooted in docs/README.md.
Learn how to Get Around the Chromium Source Code Directory Structure.
For historical reasons, there are some small top level directories. Now the guidance is that new top level directories are for product (e.g. Chrome, Android WebView, Ash). Even if these products have multiple executables, the code should be in subdirectories of the product.
If you found a bug, please file it at https://crbug.com/new.