New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 755913 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Sep 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 2
Type: Bug
Team-Security-UX



Sign in to add a comment

Mic permissions stuck on blocked only for http protocol - different behavior than Chrome

Reported by florinju...@gmail.com, Aug 16 2017

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/60.0.3112.78 Chrome/60.0.3112.78 Safari/537.36

Example URL:
http://documentare.ro/webspeech/

Steps to reproduce the problem:
1. Try to launch a webspeech session => mic blocking icon appear in url address bar
2. Click on icon to change permission to "Ask..." and close that mic permission popup
3. Try to launch another webspeech session => nothing changes and mic stays on blocked

What is the expected behavior?
Step 3 should look like this:
3. Try to launch another webspeech session => a popup permission appear to ask for permission, permission changed and voila mic is unblocked

What went wrong?
I don't know, but I've seen that on Chrome 53.0.2785.89 (64-bit) this behaves the same way(I presume this is the expected behavior) for both protocols.

Did this work before? N/A 

Is it a problem with Flash or HTML5? HTML5

Does this work in other browsers? Yes

Chrome version: 60.0.3112.78  Channel: dev
OS Version: Ubuntu 14.04 (64 bit)
Flash Version: Shockwave Flash 25.0 r0

Contents of chrome://gpu: 
Graphics Feature Status
Canvas: Hardware accelerated
CheckerImaging: Disabled
Flash: Hardware accelerated
Flash Stage3D: Hardware accelerated
Flash Stage3D Baseline profile: Hardware accelerated
Compositing: Hardware accelerated
Multiple Raster Threads: Disabled
Native GpuMemoryBuffers: Software only. Hardware acceleration disabled
Rasterization: Software only. Hardware acceleration disabled
Video Decode: Hardware accelerated
Video Encode: Hardware accelerated
WebGL: Hardware accelerated
WebGL2: Hardware accelerated
Driver Bug Workarounds
adjust_src_dst_region_for_blitframebuffer
clear_uniforms_before_first_program_use
count_all_in_varyings_packing
decode_encode_srgb_for_generatemipmap
disable_framebuffer_cmaa
disable_post_sub_buffers_for_onscreen_surfaces
disable_texture_storage
dont_remove_invariant_for_fragment_input
force_cube_map_positive_x_allocation
force_int_or_srgb_cube_texture_complete
init_texture_max_anisotropy
regenerate_struct_names
remove_invariant_and_centroid_for_essl3
scalarize_vec_and_mat_constructor_args
disable_software_to_accelerated_canvas_upgrade
Problems Detected
Clear uniforms before first program use on all platforms: 124764, 349137
Applied Workarounds: clear_uniforms_before_first_program_use
Mesa drivers in Linux handle varyings without static use incorrectly: 333885
Applied Workarounds: count_all_in_varyings_packing
Linux AMD drivers incorrectly return initial value of 1 for TEXTURE_MAX_ANISOTROPY: 348237
Applied Workarounds: init_texture_max_anisotropy
Always rewrite vec/mat constructors to be consistent: 398694
Applied Workarounds: scalarize_vec_and_mat_constructor_args
Linux AMD drivers handle struct scopes incorrectly: 403957
Applied Workarounds: regenerate_struct_names
Linux ATI drivers crash on binding incomplete cube map texture to FBO: 518889
Applied Workarounds: force_cube_map_positive_x_allocation
Linux Mesa drivers crash on glTexSubImage2D() to texture storage bound to FBO: 521904
Applied Workarounds: disable_texture_storage
Limited enabling of Chromium GL_INTEL_framebuffer_CMAA: 535198
Applied Workarounds: disable_framebuffer_cmaa
Disable partial swaps on Mesa drivers (detected with GL_VERSION): 339493
Applied Workarounds: disable_post_sub_buffers_for_onscreen_surfaces
Decode and encode before generateMipmap for srgb format textures on os except macosx: 634519
Applied Workarounds: decode_encode_srgb_for_generatemipmap
adjust src/dst region if blitting pixels outside read framebuffer on Linux AMD: 664740
Applied Workarounds: adjust_src_dst_region_for_blitframebuffer
AMD drivers in Linux require invariant qualifier to match between vertex and fragment shaders: 659326, 639760
Applied Workarounds: remove_invariant_and_centroid_for_essl3, dont_remove_invariant_for_fragment_input
Mesa driver GL 3.3 requires invariant and centroid to match between shaders: 639760, 641129
Applied Workarounds: remove_invariant_and_centroid_for_essl3
Disable KHR_blend_equation_advanced until cc shaders are updated: 661715
Decode and Encode before generateMipmap for srgb format textures on Linux AMD: 634519
Applied Workarounds: decode_encode_srgb_for_generatemipmap
Software to Accelerated canvas update breaks Linux AMD: 710029
Applied Workarounds: disable_software_to_accelerated_canvas_upgrade
Force integer or srgb cube map texture complete on Linux AMD: 712117
Applied Workarounds: force_int_or_srgb_cube_texture_complete
Accelerated rasterization has been disabled, either via blacklist, about:flags or the command line.
Disabled Features: rasterization
Raster is using a single thread.
Disabled Features: multiple_raster_threads
Native GpuMemoryBuffers have been disabled, either via about:flags or command line.
Disabled Features: native_gpu_memory_buffers
Checker-imaging has been disabled via finch trial or the command line.
Disabled Features: checker_imaging
Version Information
Data exported	16.08.2017, 11:31:49
Chrome version	Chrome/60.0.3112.78
Operating system	Linux 4.4.0-91-generic
Software rendering list version	0
Driver bug list version	10.93
ANGLE commit id	unknown hash
2D graphics backend	Skia/60 a20ae70af542208b06c21413f13c4c86269c0b84-
Command Line	/usr/lib/chromium-browser/chromium-browser --ppapi-flash-path=/usr/lib/pepperflashplugin-nonfree/libpepflashplayer.so --ppapi-flash-version=25.0.0.171 --enable-pinch --flag-switches-begin --enable-es3-apis --enable-webgl-draft-extensions --ignore-gpu-blacklist --flag-switches-end
Driver Information
Initialization time	348
In-process GPU	false
Passthrough Command Decoder	false
Supports overlays	false
Sandboxed	false
GPU0	VENDOR = 0x1002, DEVICE= 0x9598
Optimus	false
Optimus	false
AMD switchable	false
Driver vendor	Mesa
Driver version	10.1.3
Driver date	
Pixel shader version	3.30
Vertex shader version	3.30
Max. MSAA samples	8
Machine model name	
Machine model version	
GL_VENDOR	X.Org
GL_RENDERER	Gallium 0.4 on AMD RV635
GL_VERSION	3.3 (Core Profile) Mesa 10.1.3
GL_EXTENSIONS	GL_ARB_ES2_compatibility GL_ARB_base_instance GL_ARB_blend_func_extended GL_ARB_clear_buffer_object GL_ARB_copy_buffer GL_ARB_conservative_depth GL_ARB_debug_output GL_ARB_depth_buffer_float GL_ARB_depth_clamp GL_ARB_draw_buffers GL_ARB_draw_buffers_blend GL_ARB_draw_elements_base_vertex GL_ARB_draw_instanced GL_ARB_explicit_attrib_location GL_ARB_fragment_coord_conventions GL_ARB_fragment_shader GL_ARB_framebuffer_object GL_ARB_framebuffer_sRGB GL_ARB_get_program_binary GL_ARB_half_float_pixel GL_ARB_half_float_vertex GL_ARB_instanced_arrays GL_ARB_internalformat_query GL_ARB_invalidate_subdata GL_ARB_map_buffer_alignment GL_ARB_map_buffer_range GL_ARB_occlusion_query2 GL_ARB_pixel_buffer_object GL_ARB_point_sprite GL_ARB_provoking_vertex GL_ARB_robustness GL_ARB_sampler_objects GL_ARB_seamless_cube_map GL_ARB_shader_bit_encoding GL_ARB_shader_objects GL_ARB_shader_stencil_export GL_ARB_shader_texture_lod GL_ARB_shading_language_packing GL_ARB_shading_language_420pack GL_ARB_sync GL_ARB_texture_buffer_object GL_ARB_texture_buffer_object_rgb32 GL_ARB_texture_buffer_range GL_ARB_texture_compression_rgtc GL_ARB_texture_float GL_ARB_texture_mirror_clamp_to_edge GL_ARB_texture_multisample GL_ARB_texture_non_power_of_two GL_ARB_texture_rectangle GL_ARB_texture_rgb10_a2ui GL_ARB_texture_rg GL_ARB_texture_storage GL_ARB_texture_storage_multisample GL_ARB_texture_swizzle GL_ARB_timer_query GL_ARB_transform_feedback2 GL_ARB_transform_feedback3 GL_ARB_transform_feedback_instanced GL_ARB_uniform_buffer_object GL_ARB_vertex_array_bgra GL_ARB_vertex_array_object GL_ARB_vertex_attrib_binding GL_ARB_vertex_shader GL_ARB_vertex_type_10f_11f_11f_rev GL_ARB_vertex_type_2_10_10_10_rev GL_EXT_abgr GL_EXT_blend_equation_separate GL_EXT_draw_buffers2 GL_EXT_draw_instanced GL_EXT_framebuffer_blit GL_EXT_framebuffer_multisample GL_EXT_framebuffer_multisample_blit_scaled GL_EXT_framebuffer_sRGB GL_EXT_packed_depth_stencil GL_EXT_packed_float GL_EXT_pixel_buffer_object GL_EXT_provoking_vertex GL_EXT_texture_array GL_EXT_texture_compression_dxt1 GL_ANGLE_texture_compression_dxt3 GL_ANGLE_texture_compression_dxt5 GL_EXT_texture_compression_latc GL_EXT_texture_compression_rgtc GL_EXT_texture_compression_s3tc GL_EXT_texture_filter_anisotropic GL_EXT_texture_integer GL_EXT_texture_mirror_clamp GL_EXT_texture_shared_exponent GL_EXT_texture_snorm GL_EXT_texture_sRGB GL_EXT_texture_sRGB_decode GL_EXT_texture_swizzle GL_EXT_timer_query GL_EXT_transform_feedback GL_EXT_vertex_array_bgra GL_OES_EGL_image GL_OES_read_format GL_KHR_debug GL_AMD_conservative_depth GL_AMD_draw_buffers_blend GL_AMD_shader_stencil_export GL_AMD_shader_trinary_minmax GL_ATI_blend_equation_separate GL_ATI_texture_compression_3dc GL_ATI_texture_float GL_ATI_texture_mirror_once GL_IBM_multimode_draw_arrays GL_MESA_pack_invert GL_MESA_texture_signed_rgba GL_NV_conditional_render GL_NV_depth_clamp GL_NV_packed_depth_stencil GL_NV_texture_barrier GL_NV_vdpau_interop GL_S3_s3tc
Disabled Extensions	GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent
Window system binding vendor	SGI
Window system binding version	1.4
Window system binding extensions	GLX_ARB_create_context GLX_ARB_create_context_profile GLX_ARB_fbconfig_float GLX_ARB_framebuffer_sRGB GLX_ARB_multisample GLX_EXT_create_context_es2_profile GLX_EXT_framebuffer_sRGB GLX_EXT_import_context GLX_EXT_texture_from_pixmap GLX_EXT_visual_info GLX_EXT_visual_rating GLX_MESA_copy_sub_buffer GLX_OML_swap_method GLX_SGI_swap_control GLX_SGIS_multisample GLX_SGIX_fbconfig GLX_SGIX_pbuffer GLX_SGIX_visual_select_group GLX_INTEL_swap_event
Window manager	Metacity (Marco)
XDG_CURRENT_DESKTOP	MATE
GDMSESSION	mate
Compositing manager	No
Direct rendering	Yes
Reset notification strategy	0x8261
GPU process crash count	0
System visual ID	33
RGBA visual ID	108
Compositor Information
Tile Update Mode	One-copy
Partial Raster	Enabled
GpuMemoryBuffers Status
ATC	Software only
ATCIA	Software only
DXT1	Software only
DXT5	Software only
ETC1	Software only
R_8	Software only
RG_88	Software only
BGR_565	Software only
RGBA_4444	Software only
RGBX_8888	Software only
RGBA_8888	Software only
BGRX_8888	Software only
BGRA_8888	Software only
RGBA_F16	Software only
YVU_420	Software only
YUV_420_BIPLANAR	Software only
UYVY_422	Software only
Log Messages
[5496:5496:0816/110325.986559:ERROR:sandbox_linux.cc(344)] : InitializeSandbox() called with multiple threads in process gpu-process.

http://documentare.ro/webspeech/
contains the same webspeech javascript code as:
https://davidwalsh.name/demo/speech-recognition.php
 
I want to emphasize that this bug was seen on Chromium browser, version: 60.0.3112.78, Channel: dev - not in Chrome browser.
Cc: susanjuniab@chromium.org
Labels: Needs-Triage-M60 M-62 OS-Mac OS-Windows
Status: Untriaged (was: Unconfirmed)
florinjurca@ thanks for the issue..

Able to reproduce this issue on Windows 7, Ubuntu 14.04 and Mac OS 10.12.6 using chrome latest stable 60.0.3112.101, canary 62.0.3192.0, dev 62.0.3188.2. 
This is a Non-regression issue which is observed from M45 chrome builds.

Thanks
Components: -Internals>Media Blink>WebRTC>Audio
this is not media bug. give to WebRTC team, please feel free to re-assign if this is not a webrtc issue. thanks
My mistake. Sorry.

Maybe to the following categories can be the correct classification for this bug.

components:Blink>GetUserMedia>Mic
components:Privacy
component:UI>Browser>Permissions>Indicators
component:Internals>Preferences

I can't decide what is the the better one and I don't know how to change the assignment for this issue.
Cc: guidou@chromium.org maxmorin@chromium.org
Components: UI>Browser>Permissions>Indicators
I think it's WAI to refuse to send mic data unencrypted, and this is just the UI being a bit quirky. Guido: Could you confirm?
Status: WontFix (was: Untriaged)
I confirm this is as maxmorin@ says. Closing as WontFix since nothing is broken here.
There is some work going on to improve permissions and its UI, but there is nothing specifically actionable here.
We shouldn't be prompting at all on http sites. Maybe webkitSpeechRecognition does something weird?
I tried http://documentare.ro/webspeech/ and did not get a prompt.
The only visible UI action was that the omnibar shows a microphone-blocked icon after clicking the "Start listening" button.
Did not look like a bug to me.
But did you tried to unblock the mic after you set it as blocked?
That's the weird thing as it wouldn't unblock on http but only on a https page.
And on Chrome browser from Google mic can be unblocked.
I've started to work on webspeech API using Chromium on a http page for a while with no problem until I had to test mic settings than the problem showed up.   
There is no way to authorize mic on http pages. That's why it wouldn't unblock.
The UI for the omnibar icon can certainly improve, but it's working as intended by not allowing mic permissions on http.
So it is intended to be changed as it is on Chrome?

Webspeech does all the working on the client size. It does not send directly any data online(a stream for example) to a server to be a security issue.
It is an unnecessary limitation especially for developers.

Instead of use chromium for dev now I must use Chrome for dev. This is sad.
I love Chromium as it is a free and openource wonderfull browser - wery fast and also secure (maybe too secure ;) ).
  
I hope it will be changed to work also on http pages.

Anyway thanks for the clarification.

Owner: guidou@chromium.org
Status: Assigned (was: WontFix)
Chromium and Chrome are exactly the same in this regard.
There are very good reasons about why the microphone cannot be enabled on insecure sites. Once the app has access to microphone data, nothing prevents the app from sending it to an unauthenticated site, which would be a big privacy issue.
For development, you can of course use http://localhost which is considered a secure domain, or you can set up your own private https servers.

That said, I am reopening this bug because there does appear to be an issue in the webspeech API in that it should fail earlier in insecure domains, just like getUserMedia does.
On a development build I noticed that a DCHECK is hit on a part of the code that assumes that the domain is secure, which is what probably causes the weird UI behavior.
It should just fail with an exception like getUserMedia does.
florinjurca@gmail.com: You say you were able to enable microphone permission on http in Chrome 60.0.3112.78. I think that should be a serious bug, but I have been unable to reproduce it. Can you provide specific reproduction instructions?

I tried with Chrome 60.0.3112.113, 61.0.3163.59 and a development Chromium biold. In all cases find it impossible to authorize the mic on http. My interpretation of comment #2 is that susanjuniab@ had the same result with various other Chrome versions. Maybe you were trying with http://localhost?

I'm closing this bug as WontFix since mic permissions blocked on HTTP is intended behavior. If florinjurca@gmail.com can produce repro instructions for enabling the permission on HTTP, I will file a separate bug.

I also filed Filed bug 761371 to track the official removal of support of Speech Recognition on insecure origins, since it is already nonfunctional on insecure origins due to the microphone permission issue.


Status: WontFix (was: Assigned)
I have tested webspeech API on these 2 browsers: 
- Google Chrome V 53.0.2785.89 (64-bit) Linux Ubuntu-Mate - here the mic can be unblocked on a http page
- Chromium V 60.0.3112.113 (64bit) dev  Linux Ubuntu-Mate - here the mic can not be unblocked on a http page
I thought that was a bug in this version of Chromium because there on Google Chrome was another behaviour.
So mark my word... Now I have installed both browsers on my Ubuntu-Mate and there is no similar behavior regarding to this issue.

As I've said earlier I've started to work with webspeech API using Chromium for some time and I had no issues in the beginning, but seems that the behavior was changed probably in a later version than the version I've started with.
When I couldn't work with Chromium on webspeech I've filled this issue.
This is all that I can say about this problem.
I am not following the development road of Chromium so I do not know anything about the chromium.org decisions regarded to this issue - it was or it was not a security problem or if it must behave like Google Chrome or not.
I just had a blockage and I filled the issue.
So this is it.
florinjurca@: That explains it. The discrepancy you observed was due to the differences between versions 53 and 60.
Thanks for filing the bug, because it let us uncover the issue that results in the misleading dialog in newer versions.

Sign in to add a comment