New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 611964 link

Starred by 2 users

Issue metadata

Status: Started
Owner:
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug

Blocking:
issue 611905



Sign in to add a comment

//mash/....*.mojom need a security review

Project Member Reported by dcheng@chromium.org, May 14 2016

Issue description

These interfaces don't appear to have gone through security review. Marking ReleaseBlock-Stable to be on the safe side for now.

I'm not actually sure what mash is, is this related to the mus+ash work?
 

Comment 1 by dcheng@chromium.org, May 14 2016

Blocking: 611905
Labels: Security_Severity-High Security_Impact-None

Comment 3 by sky@chromium.org, May 15 2016

Labels: -Pri-1 -ReleaseBlock-Stable Pri-2
Yes, mash is mus+ash work. I'm removing the release block stable as this work isn't shipping in the next release.

Comment 4 by dcheng@chromium.org, May 15 2016

OK, thanks for the clarification. To make sure I understand correctly, this also means that none of the mojo endpoints are currently exposed in a chrome binary?

Comment 5 by sky@chromium.org, May 16 2016

A chromeos gn build has the end points exposed, but we're not shipping that anywhere yet.
Labels: mash tadpole
Cc: dcheng@chromium.org
Owner: och...@chromium.org
Status: Assigned (was: Available)
Labels: Te-NeedsFurtherTriage
Components: Security
Labels: -Te-NeedsFurtherTriage TE-NeedsfurtherTriage
Status: Started (was: Assigned)
I'm starting to take a look at this. Are there design documents for this somewhere?

Unforunately, most of this is quite foreign to me, and I'd like to understand the relationships between the clients of these interfaces and their implementations (i.e. is the client less trusted than the service implementation? -- it's not very clear to me just looking at these interfaces)

Comment 11 by sky@chromium.org, Aug 9 2016

There is documentation on various parts of mus and mash here: https://drive.google.com/corp/drive/folders/0B8MZXOiSimBbbzhYT0RPdVRqU0k . Before tackling the mash interfaces make sure you read up on mus. Latest design doc for it is here: https://docs.google.com/document/d/17WIE1uA4LrC9mt15ZKBNleT8jtNowBQUl4gE1pmizUU/edit#heading=h.nb23z7tv692y .
Components: Security>Audit
Labels: Type-Bug
Removing from the security sheriff queue.

Comment 13 by e...@chromium.org, Mar 9 2018

Cc: -e...@chromium.org
Un-cc-ing me from all bugs on my final day.

Sign in to add a comment