<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>168243</bug_id>
          
          <creation_ts>2017-02-13 12:12:34 -0800</creation_ts>
          <short_desc>[WebRTC][Mac][WebKit2] Only expand the sandbox for a specific WebRTC port</short_desc>
          <delta_ts>2017-08-24 19:12:15 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebRTC</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>All</rep_platform>
          <op_sys>macOS 10.12</op_sys>
          <bug_status>NEW</bug_status>
          <resolution></resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>168010</dependson>
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Brent Fulgham">bfulgham</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>bfulgham</cc>
    
    <cc>jonlee</cc>
    
    <cc>webkit-bug-importer</cc>
    
    <cc>youennf</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1276288</commentid>
    <comment_count>0</comment_count>
    <who name="Brent Fulgham">bfulgham</who>
    <bug_when>2017-02-13 12:12:34 -0800</bug_when>
    <thetext>In Bug 168010 we added the ability for the UIProcess to extend the NetworkProcess sandbox to include WebRTC connections.

Currently, we expand the sandbox to encompass all network activity, which is not a great security model. For the complete feature, we need the sandbox to expand just enough to support the WebRTC communication.

This bug tracks that task.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1276291</commentid>
    <comment_count>1</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2017-02-13 12:17:02 -0800</bug_when>
    <thetext>&lt;rdar://problem/30496479&gt;</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>