Notify the renderer when a navigation API traverse fails in the browser process There are two main cases where navigation.traverseTo() will reach the browser process, but the browser process will fail to traverse: 1. A race condition, where the renderer sends a navigation API key that is no longer in the joint session history. 2. When the traverse is initiated by a sandboxed iframe, and navigating to the given key would require navigating a frame that it is not permitted to navigate. Notifying the renderer for (1) is trivial. For (2), we need to plumb the key and the frame that initiated the traverse all the way to NavigationControllerImpl::NavigateToExistingPendingEntry(), where the sandboxed frame check occurs. If we pass a RenderFrameHostImpl* all the way there, this allows us to simplify other state that is passed to NavigateToExistingPendingEntry(). Currently we need to pass the sandboxed FTN id, and a bit for whether the navigation is browser initiated. Now, a nullptr RenderFrameHostImpl* param indicates a browser-initiated navigation, and NavigateToExistingPendingEntry() can do the sandbox check directly with the RenderFrameHostImpl*. This causes us to pass the following WPT tests, which were previously skipped because they hung: external/wpt/navigation-api/navigation-methods/sandboxing-back-parent.html external/wpt/navigation-api/navigation-methods/sandboxing-back-sibling.html It also allows us to remove the wpt_internal/ variants of those tests, which existed only to give us test coverage of our current behavior: wpt_internal/navigation-api/sandboxing-back-parent-never-settles.html wpt_internal/navigation-api/sandboxing-back-sibling-never-settles.html Fixed: 1311786 Change-Id: I0a5e88c0123cd20dc6e312896aa2b049713669f9 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/3902543 Reviewed-by: Daniel Cheng <dcheng@chromium.org> Reviewed-by: Charlie Reis <creis@chromium.org> Commit-Queue: Nate Chapin <japhet@chromium.org> Cr-Commit-Position: refs/heads/main@{#1051453}
Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.
The project's web site is https://www.chromium.org.
To check out the source code locally, don't use git clone! Instead, follow the instructions on how to get the code.
Documentation in the source is rooted in docs/README.md.
Learn how to Get Around the Chromium Source Code Directory Structure .
For historical reasons, there are some small top level directories. Now the guidance is that new top level directories are for product (e.g. Chrome, Android WebView, Ash). Even if these products have multiple executables, the code should be in subdirectories of the product.
If you found a bug, please file it at https://crbug.com/new.