Feature policy allow attribute causes crash with --site-per-process |
||
Issue descriptionIf a pages includes an iframe with an allow attribute, the renderer will crash, if running in site-isolation mode. The vector equality check in content/common/frame_owner_properties.cc doesn't take into account the fact that other.allowed_features may have fewer elements than this->allowed_features, and can run past the end of the vector during the compare.
,
Mar 31 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/aee9dcacf21624198c60857788c35906fffa97ad commit aee9dcacf21624198c60857788c35906fffa97ad Author: iclelland <iclelland@chromium.org> Date: Fri Mar 31 14:08:09 2017 Fix crash in frame owner property replication. Also updated the test that can trigger it, removing the unnecessary name attributes that were masking the error. BUG= 705658 Review-Url: https://codereview.chromium.org/2775393003 Cr-Commit-Position: refs/heads/master@{#461111} [modify] https://crrev.com/aee9dcacf21624198c60857788c35906fffa97ad/content/common/frame_owner_properties.cc [modify] https://crrev.com/aee9dcacf21624198c60857788c35906fffa97ad/content/test/data/allowed_frames.html
,
May 3 2017
|
||
►
Sign in to add a comment |
||
Comment 1 by iclell...@chromium.org
, Mar 31 2017