716cb28430
* chore: bump chromium in DEPS to 1e9f9a24aa12bea9cf194a82a7e249bd1242ec4f * chore: update patches * Make WebContents' theme color a base::Optional<SkColor> https://chromium-review.googlesource.com/c/chromium/src/+/1540022 * update autofill patch for incorrect header includes * Move Shell messages to web_test and rename to BlinkTest. https://chromium-review.googlesource.com/c/chromium/src/+/1525181 * Make PlatformNotificationServiceImpl a KeyedService. https://chromium-review.googlesource.com/c/chromium/src/+/1336150 * Move MediaPlayerId to its own file. https://chromium-review.googlesource.com/c/chromium/src/+/1547057 * Remove net/base/completion_callback.h, which is no longer used https://chromium-review.googlesource.com/c/chromium/src/+/1552821 * AW NS: support file scheme cookies https://chromium-review.googlesource.com/c/chromium/src/+/1533486 * Remove SecurityInfo and adapt remaining consumers https://chromium-review.googlesource.com/c/chromium/src/+/1509455 * Remove deprecated type-specific number to string conversion functions https://chromium-review.googlesource.com/c/chromium/src/+/1545881 * DevTools: Adding new performance histograms for launch of top 4 tools https://chromium-review.googlesource.com/c/chromium/src/+/1506388 * Update include paths for //base/hash/hash.h https://chromium-review.googlesource.com/c/chromium/src/+/1544630 * build: Disable ensure_gn_version gclient hook for mac CI checkout * update patches * use maybe version of v8::String::NewFromTwoByte * bump appveyor image version * fix mac ci hopefully * Convert enum to enum class for MenuAnchorPosition https://chromium-review.googlesource.com/c/chromium/src/+/1530508 * use maybe version of ToObject * RenderViewHost::GetProcess is no longer const * Unrefcount AuthChallengeInfo https://chromium-review.googlesource.com/c/chromium/src/+/1550631 * MenuButtonController takes Button rather than MenuButton https://chromium-review.googlesource.com/c/chromium/src/+/1500935 * add //ui/views_bridge_mac to deps to fix link error * forward declare views::Button in atom::MenuDelegate * more v8 patches * base/{=> hash}/md5.h https://chromium-review.googlesource.com/c/chromium/src/+/1535124 * gfx::{PlatformFontWin => win}::* https://chromium-review.googlesource.com/c/chromium/src/+/1534178 * fix v8 patches * [base] Rename TaskScheduler to ThreadPool https://chromium-review.googlesource.com/c/chromium/src/+/1561552 * use internal_config_base for bytecode_builtins_list_generator avoids windows link errors * FIXME: temporarily disable v8/breakpad integration * FIXME: temporarily disable prevent-will-redirect test * FIXME: disable neon on aarch64 pending crbug.com/953815 * update to account for WebCursor refactor https://chromium-review.googlesource.com/c/chromium/src/+/1562755 * enable stack dumping on appveyor * Revert "FIXME: disable neon on aarch64 pending crbug.com/953815" This reverts commit 57f082026be3d83069f2a2814684abf4dc9e7b53. * fix: remove const qualifiers to match upstream * fix: remove const qualifiers to match upstream in cc files as well * don't throw an error when testing if an object is an object * use non-deprecated Buffer constructor * Remove net::CookieSameSite::DEFAULT_MODE enum value https://chromium-review.googlesource.com/c/chromium/src/+/1567955 * depend on modded dbus-native to work around buffer deprecation https://github.com/sidorares/dbus-native/pull/262 * revert clang roll to fix arm build on linux * fixup! depend on modded dbus-native to work around buffer deprecation need more coffee * update coffee-script * robustify verify-mksnapshot w.r.t. command-line parameters * Revert "robustify verify-mksnapshot w.r.t. command-line parameters" This reverts commit a49af01411f684f6025528d604895c3696e0bc57. * fix mksnapshot by matching args * update patches * TMP: enable rdp on appveyor * Changed ContentBrowserClient::CreateQuotaPermissionContext() to return scoped_refptr. https://chromium-review.googlesource.com/c/chromium/src/+/1569376 * Make content::ResourceType an enum class. https://chromium-review.googlesource.com/c/chromium/src/+/1569345 * fixup! Make content::ResourceType an enum class. * turn off rdp * use net::CompletionRepeatingCallback instead of base::Callback<void(int)> * remove disable_ensure_gn_version_gclient_hook.patch * copy repeating callback instead of std::move * fix lint * add completion_repeating_callback.h include
300 lines
11 KiB
C++
300 lines
11 KiB
C++
// Copyright (c) 2016 GitHub, Inc.
|
|
// Use of this source code is governed by the MIT license that can be
|
|
// found in the LICENSE file.
|
|
|
|
#include "atom/renderer/atom_sandboxed_renderer_client.h"
|
|
|
|
#include "atom/common/api/api_messages.h"
|
|
#include "atom/common/api/electron_bindings.h"
|
|
#include "atom/common/application_info.h"
|
|
#include "atom/common/native_mate_converters/string16_converter.h"
|
|
#include "atom/common/native_mate_converters/value_converter.h"
|
|
#include "atom/common/node_bindings.h"
|
|
#include "atom/common/node_includes.h"
|
|
#include "atom/common/options_switches.h"
|
|
#include "atom/renderer/atom_render_frame_observer.h"
|
|
#include "base/base_paths.h"
|
|
#include "base/command_line.h"
|
|
#include "base/files/file_path.h"
|
|
#include "base/path_service.h"
|
|
#include "base/process/process_handle.h"
|
|
#include "content/public/renderer/render_frame.h"
|
|
#include "gin/converter.h"
|
|
#include "native_mate/dictionary.h"
|
|
#include "third_party/blink/public/web/blink.h"
|
|
#include "third_party/blink/public/web/web_document.h"
|
|
#include "third_party/electron_node/src/node_binding.h"
|
|
#include "third_party/electron_node/src/node_native_module.h"
|
|
|
|
namespace atom {
|
|
|
|
namespace {
|
|
|
|
const char kLifecycleKey[] = "lifecycle";
|
|
const char kModuleCacheKey[] = "native-module-cache";
|
|
|
|
bool IsDevTools(content::RenderFrame* render_frame) {
|
|
return render_frame->GetWebFrame()->GetDocument().Url().ProtocolIs(
|
|
"chrome-devtools");
|
|
}
|
|
|
|
bool IsDevToolsExtension(content::RenderFrame* render_frame) {
|
|
return render_frame->GetWebFrame()->GetDocument().Url().ProtocolIs(
|
|
"chrome-extension");
|
|
}
|
|
|
|
v8::Local<v8::Object> GetModuleCache(v8::Isolate* isolate) {
|
|
auto context = isolate->GetCurrentContext();
|
|
mate::Dictionary global(isolate, context->Global());
|
|
v8::Local<v8::Value> cache;
|
|
|
|
if (!global.GetHidden(kModuleCacheKey, &cache)) {
|
|
cache = v8::Object::New(isolate);
|
|
global.SetHidden(kModuleCacheKey, cache);
|
|
}
|
|
|
|
return cache->ToObject(context).ToLocalChecked();
|
|
}
|
|
|
|
// adapted from node.cc
|
|
v8::Local<v8::Value> GetBinding(v8::Isolate* isolate,
|
|
v8::Local<v8::String> key,
|
|
mate::Arguments* margs) {
|
|
v8::Local<v8::Object> exports;
|
|
std::string module_key = gin::V8ToString(isolate, key);
|
|
mate::Dictionary cache(isolate, GetModuleCache(isolate));
|
|
|
|
if (cache.Get(module_key.c_str(), &exports)) {
|
|
return exports;
|
|
}
|
|
|
|
auto* mod = node::binding::get_linked_module(module_key.c_str());
|
|
|
|
if (!mod) {
|
|
char errmsg[1024];
|
|
snprintf(errmsg, sizeof(errmsg), "No such module: %s", module_key.c_str());
|
|
margs->ThrowError(errmsg);
|
|
return exports;
|
|
}
|
|
|
|
exports = v8::Object::New(isolate);
|
|
DCHECK_EQ(mod->nm_register_func, nullptr);
|
|
DCHECK_NE(mod->nm_context_register_func, nullptr);
|
|
mod->nm_context_register_func(exports, v8::Null(isolate),
|
|
isolate->GetCurrentContext(), mod->nm_priv);
|
|
cache.Set(module_key.c_str(), exports);
|
|
return exports;
|
|
}
|
|
|
|
v8::Local<v8::Value> CreatePreloadScript(v8::Isolate* isolate,
|
|
v8::Local<v8::String> preloadSrc) {
|
|
return RendererClientBase::RunScript(isolate->GetCurrentContext(),
|
|
preloadSrc);
|
|
}
|
|
|
|
void InvokeHiddenCallback(v8::Handle<v8::Context> context,
|
|
const std::string& hidden_key,
|
|
const std::string& callback_name) {
|
|
auto* isolate = context->GetIsolate();
|
|
auto binding_key = mate::ConvertToV8(isolate, hidden_key)
|
|
->ToString(context)
|
|
.ToLocalChecked();
|
|
auto private_binding_key = v8::Private::ForApi(isolate, binding_key);
|
|
auto global_object = context->Global();
|
|
v8::Local<v8::Value> value;
|
|
if (!global_object->GetPrivate(context, private_binding_key).ToLocal(&value))
|
|
return;
|
|
if (value.IsEmpty() || !value->IsObject())
|
|
return;
|
|
auto binding = value->ToObject(context).ToLocalChecked();
|
|
auto callback_key = mate::ConvertToV8(isolate, callback_name)
|
|
->ToString(context)
|
|
.ToLocalChecked();
|
|
auto callback_value = binding->Get(callback_key);
|
|
DCHECK(callback_value->IsFunction()); // set by sandboxed_renderer/init.js
|
|
auto callback = v8::Handle<v8::Function>::Cast(callback_value);
|
|
ignore_result(callback->Call(context, binding, 0, nullptr));
|
|
}
|
|
|
|
} // namespace
|
|
|
|
AtomSandboxedRendererClient::AtomSandboxedRendererClient() {
|
|
// Explicitly register electron's builtin modules.
|
|
NodeBindings::RegisterBuiltinModules();
|
|
metrics_ = base::ProcessMetrics::CreateCurrentProcessMetrics();
|
|
}
|
|
|
|
AtomSandboxedRendererClient::~AtomSandboxedRendererClient() {}
|
|
|
|
void AtomSandboxedRendererClient::InitializeBindings(
|
|
v8::Local<v8::Object> binding,
|
|
v8::Local<v8::Context> context,
|
|
bool is_main_frame) {
|
|
auto* isolate = context->GetIsolate();
|
|
mate::Dictionary b(isolate, binding);
|
|
b.SetMethod("get", GetBinding);
|
|
b.SetMethod("createPreloadScript", CreatePreloadScript);
|
|
|
|
mate::Dictionary process = mate::Dictionary::CreateEmpty(isolate);
|
|
b.Set("process", process);
|
|
|
|
ElectronBindings::BindProcess(isolate, &process, metrics_.get());
|
|
|
|
process.Set("argv", base::CommandLine::ForCurrentProcess()->argv());
|
|
process.SetReadOnly("pid", base::GetCurrentProcId());
|
|
process.SetReadOnly("sandboxed", true);
|
|
process.SetReadOnly("type", "renderer");
|
|
process.SetReadOnly("isMainFrame", is_main_frame);
|
|
|
|
// Pass in CLI flags needed to setup the renderer
|
|
base::CommandLine* command_line = base::CommandLine::ForCurrentProcess();
|
|
if (command_line->HasSwitch(switches::kGuestInstanceID))
|
|
b.Set(options::kGuestInstanceID,
|
|
command_line->GetSwitchValueASCII(switches::kGuestInstanceID));
|
|
}
|
|
|
|
void AtomSandboxedRendererClient::RenderFrameCreated(
|
|
content::RenderFrame* render_frame) {
|
|
new AtomRenderFrameObserver(render_frame, this);
|
|
RendererClientBase::RenderFrameCreated(render_frame);
|
|
}
|
|
|
|
void AtomSandboxedRendererClient::RenderViewCreated(
|
|
content::RenderView* render_view) {
|
|
RendererClientBase::RenderViewCreated(render_view);
|
|
}
|
|
|
|
void AtomSandboxedRendererClient::RunScriptsAtDocumentStart(
|
|
content::RenderFrame* render_frame) {
|
|
if (injected_frames_.find(render_frame) == injected_frames_.end())
|
|
return;
|
|
|
|
auto* isolate = blink::MainThreadIsolate();
|
|
v8::HandleScope handle_scope(isolate);
|
|
|
|
v8::Local<v8::Context> context =
|
|
GetContext(render_frame->GetWebFrame(), isolate);
|
|
v8::Context::Scope context_scope(context);
|
|
|
|
InvokeHiddenCallback(context, kLifecycleKey, "onDocumentStart");
|
|
}
|
|
|
|
void AtomSandboxedRendererClient::RunScriptsAtDocumentEnd(
|
|
content::RenderFrame* render_frame) {
|
|
if (injected_frames_.find(render_frame) == injected_frames_.end())
|
|
return;
|
|
|
|
auto* isolate = blink::MainThreadIsolate();
|
|
v8::HandleScope handle_scope(isolate);
|
|
|
|
v8::Local<v8::Context> context =
|
|
GetContext(render_frame->GetWebFrame(), isolate);
|
|
v8::Context::Scope context_scope(context);
|
|
|
|
InvokeHiddenCallback(context, kLifecycleKey, "onDocumentEnd");
|
|
}
|
|
|
|
void AtomSandboxedRendererClient::DidCreateScriptContext(
|
|
v8::Handle<v8::Context> context,
|
|
content::RenderFrame* render_frame) {
|
|
RendererClientBase::DidCreateScriptContext(context, render_frame);
|
|
|
|
// Only allow preload for the main frame or
|
|
// For devtools we still want to run the preload_bundle script
|
|
// Or when nodeSupport is explicitly enabled in sub frames
|
|
bool is_main_frame = render_frame->IsMainFrame();
|
|
bool is_devtools =
|
|
IsDevTools(render_frame) || IsDevToolsExtension(render_frame);
|
|
bool allow_node_in_sub_frames =
|
|
base::CommandLine::ForCurrentProcess()->HasSwitch(
|
|
switches::kNodeIntegrationInSubFrames);
|
|
bool should_load_preload =
|
|
is_main_frame || is_devtools || allow_node_in_sub_frames;
|
|
if (!should_load_preload)
|
|
return;
|
|
|
|
injected_frames_.insert(render_frame);
|
|
|
|
// Wrap the bundle into a function that receives the binding object as
|
|
// argument.
|
|
auto* isolate = context->GetIsolate();
|
|
auto binding = v8::Object::New(isolate);
|
|
InitializeBindings(binding, context, render_frame->IsMainFrame());
|
|
AddRenderBindings(isolate, binding);
|
|
|
|
std::vector<v8::Local<v8::String>> sandbox_preload_bundle_params = {
|
|
node::FIXED_ONE_BYTE_STRING(isolate, "binding")};
|
|
|
|
std::vector<v8::Local<v8::Value>> sandbox_preload_bundle_args = {binding};
|
|
|
|
node::per_process::native_module_loader.CompileAndCall(
|
|
isolate->GetCurrentContext(), "electron/js2c/sandbox_bundle",
|
|
&sandbox_preload_bundle_params, &sandbox_preload_bundle_args, nullptr);
|
|
|
|
v8::HandleScope handle_scope(isolate);
|
|
v8::Context::Scope context_scope(context);
|
|
InvokeHiddenCallback(context, kLifecycleKey, "onLoaded");
|
|
}
|
|
|
|
void AtomSandboxedRendererClient::SetupMainWorldOverrides(
|
|
v8::Handle<v8::Context> context,
|
|
content::RenderFrame* render_frame) {
|
|
// Setup window overrides in the main world context
|
|
// Wrap the bundle into a function that receives the isolatedWorld as
|
|
// an argument.
|
|
auto* isolate = context->GetIsolate();
|
|
|
|
mate::Dictionary process = mate::Dictionary::CreateEmpty(isolate);
|
|
process.SetMethod("binding", GetBinding);
|
|
|
|
std::vector<v8::Local<v8::String>> isolated_bundle_params = {
|
|
node::FIXED_ONE_BYTE_STRING(isolate, "nodeProcess"),
|
|
node::FIXED_ONE_BYTE_STRING(isolate, "isolatedWorld")};
|
|
|
|
std::vector<v8::Local<v8::Value>> isolated_bundle_args = {
|
|
process.GetHandle(),
|
|
GetContext(render_frame->GetWebFrame(), isolate)->Global()};
|
|
|
|
node::per_process::native_module_loader.CompileAndCall(
|
|
context, "electron/js2c/isolated_bundle", &isolated_bundle_params,
|
|
&isolated_bundle_args, nullptr);
|
|
}
|
|
|
|
void AtomSandboxedRendererClient::SetupExtensionWorldOverrides(
|
|
v8::Handle<v8::Context> context,
|
|
content::RenderFrame* render_frame,
|
|
int world_id) {
|
|
auto* isolate = context->GetIsolate();
|
|
|
|
mate::Dictionary process = mate::Dictionary::CreateEmpty(isolate);
|
|
process.SetMethod("binding", GetBinding);
|
|
|
|
std::vector<v8::Local<v8::String>> isolated_bundle_params = {
|
|
node::FIXED_ONE_BYTE_STRING(isolate, "nodeProcess"),
|
|
node::FIXED_ONE_BYTE_STRING(isolate, "isolatedWorld"),
|
|
node::FIXED_ONE_BYTE_STRING(isolate, "worldId")};
|
|
|
|
std::vector<v8::Local<v8::Value>> isolated_bundle_args = {
|
|
process.GetHandle(),
|
|
GetContext(render_frame->GetWebFrame(), isolate)->Global(),
|
|
v8::Integer::New(isolate, world_id)};
|
|
|
|
node::per_process::native_module_loader.CompileAndCall(
|
|
context, "electron/js2c/content_script_bundle", &isolated_bundle_params,
|
|
&isolated_bundle_args, nullptr);
|
|
}
|
|
|
|
void AtomSandboxedRendererClient::WillReleaseScriptContext(
|
|
v8::Handle<v8::Context> context,
|
|
content::RenderFrame* render_frame) {
|
|
if (injected_frames_.find(render_frame) == injected_frames_.end())
|
|
return;
|
|
injected_frames_.erase(render_frame);
|
|
|
|
auto* isolate = context->GetIsolate();
|
|
v8::HandleScope handle_scope(isolate);
|
|
v8::Context::Scope context_scope(context);
|
|
InvokeHiddenCallback(context, kLifecycleKey, "onExit");
|
|
}
|
|
|
|
} // namespace atom
|