Fix source SiteInstance computation for SiteInstanceGroups The NavigationRequest constructor currently has a case where if the navigation originates from a BeginNavigation IPC, the source SiteInstance is set to the current RenderFrameHost's SiteInstance. This is needed to keep navigations to about: or data: URLs in the initiator's SiteInstance, and works due to the assumption that even if the initiator frame is different from the frame that received the BeginNavigation IPC, the two will always be in the same SiteInstance. With SiteInstanceGroups, that assumption no longer holds, as the initiator frame and the navigating frame could be in different SiteInstances in the same SiteInstanceGroup. So, this CL fixes this logic to instead look up the source SiteInstance based on the initiator frame token, using the GetSourceSiteInstanceFromFrameToken() mechanism that was introduced for a similar case with proxy navigations in https://chromium-review.googlesource.com/c/chromium/src/+/5436609. The idea is that if the initiator RFH is still alive, we get the source SiteInstance from it, otherwise we get it from NavigationStateKeepAlive which stores the source SiteInstance if the initiator had gone away. This is covered by the GrandchildToAboutBlank_ABB_CrossSite test running with the default SiteInstanceGroups feature, which will be introduced in https://chromium-review.googlesource.com/c/chromium/src/+/6203249. Note that in an earlier approach, we considered using SetSourceSiteInstanceToInitiatorIfNeeded() to look up the source SiteInstance purely based on the initiator origin, but that turns out to be problematic, because SetSourceSiteInstanceToInitiatorIfNeeded() relies on looking up an existing SiteInstance via GetRelatedSiteInstance() based solely on a URL obtained from the initiator origin. This may end up returning an incorrect SiteInstance if the initiator uses an effective URL, or if there's a mismatch with any other SiteInfo bits, which was seen in practice with at least the PDF and sandboxed bits in existing tests. SetSourceSiteInstanceToInitiatorIfNeeded() seems to only be safe for creating a new related SiteInstance when a source SiteInstance is required (e.g. after session restore), not for looking up an existing one. There is actually a bug filed already that notes this at https://crbug.com/349972037. Bug: 390571607 Change-Id: Id3b155762e7eaefcbfc7c1a40aef4fce0a281482 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/6559448 Reviewed-by: Charlie Reis <creis@chromium.org> Commit-Queue: Alex Moshchuk <alexmos@chromium.org> Reviewed-by: Sharon Yang <yangsharon@chromium.org> Cr-Commit-Position: refs/heads/main@{#1462847}
Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.
The project's web site is https://www.chromium.org.
To check out the source code locally, don't use git clone! Instead, follow the instructions on how to get the code.
Documentation in the source is rooted in docs/README.md.
Learn how to Get Around the Chromium Source Code Directory Structure.
For historical reasons, there are some small top level directories. Now the guidance is that new top level directories are for product (e.g. Chrome, Android WebView, Ash). Even if these products have multiple executables, the code should be in subdirectories of the product.
If you found a bug, please file it at https://crbug.com/new.