<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>33277</bug_id>
          
          <creation_ts>2010-01-06 16:55:17 -0800</creation_ts>
          <short_desc>HTML5 iframe sandbox bypass of window.top.location navigation via &lt;form target=&quot;_top&quot;&gt;</short_desc>
          <delta_ts>2010-02-17 12:27:18 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Frames</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>PC</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>33659</dependson>
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Chris Evans">scarybeasts</reporter>
          <assigned_to name="Sam Weinig">sam</assigned_to>
          <cc>abarth</cc>
    
    <cc>darin</cc>
    
    <cc>eric</cc>
    
    <cc>patrik.j.persson</cc>
    
    <cc>sam</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>177870</commentid>
    <comment_count>0</comment_count>
    <who name="Chris Evans">scarybeasts</who>
    <bug_when>2010-01-06 16:55:17 -0800</bug_when>
    <thetext>Demo HTML follows. The sandboxed iframe should not be able to do anything to navigate the top level window, but here is a bypass:

ifsandbox.html:
---
&lt;html&gt;
&lt;body&gt;
Testing iframe sandbox attribute....
&lt;iframe sandbox=&quot;allow-same-origin allow-forms allow-scripts&quot; src=&quot;innerframe.html&quot;&gt;&lt;/iframe&gt;
&lt;/body&gt;
&lt;/html&gt;
---

innerframe.html:
---
&lt;html&gt;
&lt;body&gt;
Hello! I&apos;m the inner frame. I will proceed to try and be irritating.
&lt;form id=&quot;f&quot; action=&quot;http://www.google.com&quot; method=&quot;GET&quot; target=&quot;_top&quot;&gt;
&lt;input type=&quot;submit&quot; value=&quot;Submit&quot;/&gt;
&lt;/form&gt;
&lt;script&gt;
// Does not work.
window.top.location = &apos;http://www.google.com&apos;;
// Works!
e = document.getElementById(&apos;f&apos;);
alert(&apos;about to submit form....&apos;);
e.submit();
&lt;/script&gt;
&lt;/body&gt;
&lt;/html&gt;
---

I haven&apos;t tried other targets (e.g. &quot;_parent&quot;, named iframes etc).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>177871</commentid>
    <comment_count>1</comment_count>
    <who name="Chris Evans">scarybeasts</who>
    <bug_when>2010-01-06 16:58:37 -0800</bug_when>
    <thetext>cc: author of iframe sandbox attribute (thanks for implementing it)!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>177880</commentid>
    <comment_count>2</comment_count>
    <who name="David Kilzer (:ddkilzer)">ddkilzer</who>
    <bug_when>2010-01-06 17:16:30 -0800</bug_when>
    <thetext>&lt;rdar://problem/7517003&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>177889</commentid>
    <comment_count>3</comment_count>
    <who name="Darin Adler">darin</who>
    <bug_when>2010-01-06 17:25:46 -0800</bug_when>
    <thetext>Putting this in the private security area seems unnecessarily cautious, since the sandbox attribute is brand new, hasn’t shipped yet, and isn’t in active use by websites. I think it would be OK to handle this out in the open instead. What do you think?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>177890</commentid>
    <comment_count>4</comment_count>
      <attachid>46011</attachid>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-01-06 17:26:32 -0800</bug_when>
    <thetext>Created attachment 46011
LayoutTest

Here&apos;s a LayoutTest for the issue.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>177891</commentid>
    <comment_count>5</comment_count>
    <who name="Chris Evans">scarybeasts</who>
    <bug_when>2010-01-06 17:27:05 -0800</bug_when>
    <thetext>Darin - agreed!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>177921</commentid>
    <comment_count>6</comment_count>
    <who name="Sam Weinig">sam</who>
    <bug_when>2010-01-06 19:18:41 -0800</bug_when>
    <thetext>I have a fix for this.  I&apos;ll take the bug.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>185307</commentid>
    <comment_count>7</comment_count>
    <who name="Chris Evans">scarybeasts</who>
    <bug_when>2010-01-27 18:20:36 -0800</bug_when>
    <thetext>Was it a simple fix or did complexities arise?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>185357</commentid>
    <comment_count>8</comment_count>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-01-27 23:48:44 -0800</bug_when>
    <thetext>@Sam, I can fix this if you&apos;ve got other things on your plate.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>190257</commentid>
    <comment_count>9</comment_count>
      <attachid>48699</attachid>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-02-12 23:27:23 -0800</bug_when>
    <thetext>Created attachment 48699
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>190258</commentid>
    <comment_count>10</comment_count>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-02-12 23:28:06 -0800</bug_when>
    <thetext>@Sam: I don&apos;t mean to step on your toes, but I&apos;d like to get this bug fixed.  Is this the same as your patch?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>190300</commentid>
    <comment_count>11</comment_count>
      <attachid>48699</attachid>
    <who name="Darin Adler">darin</who>
    <bug_when>2010-02-13 21:23:43 -0800</bug_when>
    <thetext>Comment on attachment 48699
Patch

Fix is fine, r=me.

No need to wait on Sam.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>190386</commentid>
    <comment_count>12</comment_count>
      <attachid>48699</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2010-02-14 22:05:34 -0800</bug_when>
    <thetext>Comment on attachment 48699
Patch

Clearing flags on attachment: 48699

Committed r54764: &lt;http://trac.webkit.org/changeset/54764&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>190387</commentid>
    <comment_count>13</comment_count>
      <attachid>48699</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2010-02-14 22:05:47 -0800</bug_when>
    <thetext>Comment on attachment 48699
Patch

Rejecting patch 48699 from commit-queue.

Unexpected failure when landing patch!  Please file a bug against webkit-patch.
Failed to run &quot;[&apos;WebKitTools/Scripts/webkit-patch&apos;, &apos;--status-host=webkit-commit-queue.appspot.com&apos;, &apos;land-attachment&apos;, &apos;--force-clean&apos;, &apos;--non-interactive&apos;, &apos;--no-update&apos;, &apos;--parent-command=commit-queue&apos;, &apos;--build-style=both&apos;, &apos;--quiet&apos;, &apos;48699&apos;]&quot; exit_code: 1
Last 500 characters of output:
all.cache.d/-1555206040/mechanize-0.1.11.zip/mechanize-0.1.11/mechanize/_html.py&quot;, line 546, in __getattr__
  File &quot;/Users/eseidel/Projects/CommitQueue/WebKitTools/Scripts/webkitpy/autoinstall.cache.d/-1555206040/mechanize-0.1.11.zip/mechanize-0.1.11/mechanize/_html.py&quot;, line 559, in forms
  File &quot;/Users/eseidel/Projects/CommitQueue/WebKitTools/Scripts/webkitpy/autoinstall.cache.d/-1555206040/mechanize-0.1.11.zip/mechanize-0.1.11/mechanize/_html.py&quot;, line 228, in forms
mechanize._html.ParseError</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>190456</commentid>
    <comment_count>14</comment_count>
    <who name="Adam Barth">abarth</who>
    <bug_when>2010-02-15 07:37:59 -0800</bug_when>
    <thetext>Looks like this was landed, but CCing Eric because of the strange commit-bot error.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>191150</commentid>
    <comment_count>15</comment_count>
    <who name="Eric Seidel (no email)">eric</who>
    <bug_when>2010-02-17 12:27:18 -0800</bug_when>
    <thetext>That looks like bug 33659.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>46011</attachid>
            <date>2010-01-06 17:26:32 -0800</date>
            <delta_ts>2010-02-12 23:27:18 -0800</delta_ts>
            <desc>LayoutTest</desc>
            <filename>patch</filename>
            <type>text/plain</type>
            <size>1480</size>
            <attacher name="Adam Barth">abarth</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL2h0dHAvdGVzdHMvc2VjdXJpdHkvcmVzb3VyY2VzL2Zh
aWwuaHRtbCBiL0xheW91dFRlc3RzL2h0dHAvdGVzdHMvc2VjdXJpdHkvcmVzb3VyY2VzL2ZhaWwu
aHRtbApuZXcgZmlsZSBtb2RlIDEwMDY0NAppbmRleCAwMDAwMDAwLi5lZWEyMzg0Ci0tLSAvZGV2
L251bGwKKysrIGIvTGF5b3V0VGVzdHMvaHR0cC90ZXN0cy9zZWN1cml0eS9yZXNvdXJjZXMvZmFp
bC5odG1sCkBAIC0wLDAgKzEsNSBAQAorPGh0bWw+Cis8Ym9keT4KK0ZBSUwKKzwvYm9keT4KKzwv
aHRtbD4KZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL2h0dHAvdGVzdHMvc2VjdXJpdHkvcmVzb3Vy
Y2VzL3NhbmRib3hlZC1pZnJhbWUtZm9ybS10b3AuaHRtbCBiL0xheW91dFRlc3RzL2h0dHAvdGVz
dHMvc2VjdXJpdHkvcmVzb3VyY2VzL3NhbmRib3hlZC1pZnJhbWUtZm9ybS10b3AuaHRtbApuZXcg
ZmlsZSBtb2RlIDEwMDY0NAppbmRleCAwMDAwMDAwLi5jNmNiNmY2Ci0tLSAvZGV2L251bGwKKysr
IGIvTGF5b3V0VGVzdHMvaHR0cC90ZXN0cy9zZWN1cml0eS9yZXNvdXJjZXMvc2FuZGJveGVkLWlm
cmFtZS1mb3JtLXRvcC5odG1sCkBAIC0wLDAgKzEsMTIgQEAKKzxodG1sPgorPGJvZHk+Cis8Zm9y
bSBpZD0idGhlRm9ybSIgYWN0aW9uPSJmYWlsLmh0bWwiIG1ldGhvZD0iR0VUIiB0YXJnZXQ9Il90
b3AiPgorPGlucHV0IHR5cGU9InN1Ym1pdCIgdmFsdWU9IlN1Ym1pdCIvPgorPC9mb3JtPgorPHNj
cmlwdD4KK3ZhciBmID0gZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQoJ3RoZUZvcm0nKTsKK2Yuc3Vi
bWl0KCk7Cis8L3NjcmlwdD4KKzwvYm9keT4KKzwvaHRtbD4KKwpkaWZmIC0tZ2l0IGEvTGF5b3V0
VGVzdHMvaHR0cC90ZXN0cy9zZWN1cml0eS9zYW5kYm94ZWQtaWZyYW1lLWZvcm0tdG9wLmh0bWwg
Yi9MYXlvdXRUZXN0cy9odHRwL3Rlc3RzL3NlY3VyaXR5L3NhbmRib3hlZC1pZnJhbWUtZm9ybS10
b3AuaHRtbApuZXcgZmlsZSBtb2RlIDEwMDY0NAppbmRleCAwMDAwMDAwLi4wZGMzNjYzCi0tLSAv
ZGV2L251bGwKKysrIGIvTGF5b3V0VGVzdHMvaHR0cC90ZXN0cy9zZWN1cml0eS9zYW5kYm94ZWQt
aWZyYW1lLWZvcm0tdG9wLmh0bWwKQEAgLTAsMCArMSwxNSBAQAorPGh0bWw+Cis8aGVhZD4KKzxz
Y3JpcHQ+CitpZiAod2luZG93LmxheW91dFRlc3RDb250cm9sbGVyKQorICAgIHdpbmRvdy5sYXlv
dXRUZXN0Q29udHJvbGxlci5kdW1wQXNUZXh0KCk7Cis8L3NjcmlwdD4KKzwvaGVhZD4KKzxib2R5
PgorPHA+VGhpcyB0ZXN0cyBwYXNzZXMgaWYgdGhlIHNhbmRib3hlZCBmcmFtZSBjYW5ub3QgbmF2
aWdhdGUgdGhlIHRvcCBmcmFtZS48L3A+Cis8cD5QQVNTPC9wPgorPGlmcmFtZSBzYW5kYm94PSJh
bGxvdy1mb3JtcyBhbGxvdy1zY3JpcHRzIgorICAgICAgICBzcmM9InJlc291cmNlcy9zYW5kYm94
ZWQtaWZyYW1lLWZvcm0tdG9wLmh0bWwiPgorPC9pZnJhbWU+Cis8L2JvZHk+Cis8L2h0bWw+Cg==
</data>

          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>48699</attachid>
            <date>2010-02-12 23:27:23 -0800</date>
            <delta_ts>2010-02-14 22:05:47 -0800</delta_ts>
            <desc>Patch</desc>
            <filename>bug-33277-20100212232722.patch</filename>
            <type>text/plain</type>
            <size>4321</size>
            <attacher name="Adam Barth">abarth</attacher>
            
              <data encoding="base64">ZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL0NoYW5nZUxvZyBiL0xheW91dFRlc3RzL0NoYW5nZUxv
ZwppbmRleCBiZGIxYjlmLi44N2E2YTU4IDEwMDY0NAotLS0gYS9MYXlvdXRUZXN0cy9DaGFuZ2VM
b2cKKysrIGIvTGF5b3V0VGVzdHMvQ2hhbmdlTG9nCkBAIC0xLDMgKzEsMTcgQEAKKzIwMTAtMDIt
MTIgIEFkYW0gQmFydGggIDxhYmFydGhAd2Via2l0Lm9yZz4KKworICAgICAgICBSZXZpZXdlZCBi
eSBOT0JPRFkgKE9PUFMhKS4KKworICAgICAgICBIVE1MNSBpZnJhbWUgc2FuZGJveCBieXBhc3Mg
b2Ygd2luZG93LnRvcC5sb2NhdGlvbiBuYXZpZ2F0aW9uIHZpYSA8Zm9ybSB0YXJnZXQ9Il90b3Ai
PgorICAgICAgICBodHRwczovL2J1Z3Mud2Via2l0Lm9yZy9zaG93X2J1Zy5jZ2k/aWQ9MzMyNzcK
KworICAgICAgICBBZGQgYSB0ZXN0IHRoYXQgX3RvcCBpcyBjb3ZlcmVkIGJ5IEBzYW5kYm94Lgor
CisgICAgICAgICogaHR0cC90ZXN0cy9zZWN1cml0eS9yZXNvdXJjZXMvZmFpbC5odG1sOiBBZGRl
ZC4KKyAgICAgICAgKiBodHRwL3Rlc3RzL3NlY3VyaXR5L3Jlc291cmNlcy9zYW5kYm94ZWQtaWZy
YW1lLWZvcm0tdG9wLmh0bWw6IEFkZGVkLgorICAgICAgICAqIGh0dHAvdGVzdHMvc2VjdXJpdHkv
c2FuZGJveGVkLWlmcmFtZS1mb3JtLXRvcC1leHBlY3RlZC50eHQ6IEFkZGVkLgorICAgICAgICAq
IGh0dHAvdGVzdHMvc2VjdXJpdHkvc2FuZGJveGVkLWlmcmFtZS1mb3JtLXRvcC5odG1sOiBBZGRl
ZC4KKwogMjAxMC0wMi0xMiAgT2phbiBWYWZhaSAgPG9qYW5AY2hyb21pdW0ub3JnPgogCiAgICAg
ICAgIFJldmlld2VkIGJ5IERhbiBCZXJuc3RlaW4uCmRpZmYgLS1naXQgYS9MYXlvdXRUZXN0cy9o
dHRwL3Rlc3RzL3NlY3VyaXR5L3Jlc291cmNlcy9mYWlsLmh0bWwgYi9MYXlvdXRUZXN0cy9odHRw
L3Rlc3RzL3NlY3VyaXR5L3Jlc291cmNlcy9mYWlsLmh0bWwKbmV3IGZpbGUgbW9kZSAxMDA2NDQK
aW5kZXggMDAwMDAwMC4uZWVhMjM4NAotLS0gL2Rldi9udWxsCisrKyBiL0xheW91dFRlc3RzL2h0
dHAvdGVzdHMvc2VjdXJpdHkvcmVzb3VyY2VzL2ZhaWwuaHRtbApAQCAtMCwwICsxLDUgQEAKKzxo
dG1sPgorPGJvZHk+CitGQUlMCis8L2JvZHk+Cis8L2h0bWw+CmRpZmYgLS1naXQgYS9MYXlvdXRU
ZXN0cy9odHRwL3Rlc3RzL3NlY3VyaXR5L3Jlc291cmNlcy9zYW5kYm94ZWQtaWZyYW1lLWZvcm0t
dG9wLmh0bWwgYi9MYXlvdXRUZXN0cy9odHRwL3Rlc3RzL3NlY3VyaXR5L3Jlc291cmNlcy9zYW5k
Ym94ZWQtaWZyYW1lLWZvcm0tdG9wLmh0bWwKbmV3IGZpbGUgbW9kZSAxMDA2NDQKaW5kZXggMDAw
MDAwMC4uYzZjYjZmNgotLS0gL2Rldi9udWxsCisrKyBiL0xheW91dFRlc3RzL2h0dHAvdGVzdHMv
c2VjdXJpdHkvcmVzb3VyY2VzL3NhbmRib3hlZC1pZnJhbWUtZm9ybS10b3AuaHRtbApAQCAtMCww
ICsxLDEyIEBACis8aHRtbD4KKzxib2R5PgorPGZvcm0gaWQ9InRoZUZvcm0iIGFjdGlvbj0iZmFp
bC5odG1sIiBtZXRob2Q9IkdFVCIgdGFyZ2V0PSJfdG9wIj4KKzxpbnB1dCB0eXBlPSJzdWJtaXQi
IHZhbHVlPSJTdWJtaXQiLz4KKzwvZm9ybT4KKzxzY3JpcHQ+Cit2YXIgZiA9IGRvY3VtZW50Lmdl
dEVsZW1lbnRCeUlkKCd0aGVGb3JtJyk7CitmLnN1Ym1pdCgpOworPC9zY3JpcHQ+Cis8L2JvZHk+
Cis8L2h0bWw+CisKZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL2h0dHAvdGVzdHMvc2VjdXJpdHkv
c2FuZGJveGVkLWlmcmFtZS1mb3JtLXRvcC1leHBlY3RlZC50eHQgYi9MYXlvdXRUZXN0cy9odHRw
L3Rlc3RzL3NlY3VyaXR5L3NhbmRib3hlZC1pZnJhbWUtZm9ybS10b3AtZXhwZWN0ZWQudHh0Cm5l
dyBmaWxlIG1vZGUgMTAwNjQ0CmluZGV4IDAwMDAwMDAuLmQ5NDJjNzUKLS0tIC9kZXYvbnVsbAor
KysgYi9MYXlvdXRUZXN0cy9odHRwL3Rlc3RzL3NlY3VyaXR5L3NhbmRib3hlZC1pZnJhbWUtZm9y
bS10b3AtZXhwZWN0ZWQudHh0CkBAIC0wLDAgKzEsNSBAQAorVGhpcyB0ZXN0cyBwYXNzZXMgaWYg
dGhlIHNhbmRib3hlZCBmcmFtZSBjYW5ub3QgbmF2aWdhdGUgdGhlIHRvcCBmcmFtZS4KKworUEFT
UworCisKZGlmZiAtLWdpdCBhL0xheW91dFRlc3RzL2h0dHAvdGVzdHMvc2VjdXJpdHkvc2FuZGJv
eGVkLWlmcmFtZS1mb3JtLXRvcC5odG1sIGIvTGF5b3V0VGVzdHMvaHR0cC90ZXN0cy9zZWN1cml0
eS9zYW5kYm94ZWQtaWZyYW1lLWZvcm0tdG9wLmh0bWwKbmV3IGZpbGUgbW9kZSAxMDA2NDQKaW5k
ZXggMDAwMDAwMC4uMGRjMzY2MwotLS0gL2Rldi9udWxsCisrKyBiL0xheW91dFRlc3RzL2h0dHAv
dGVzdHMvc2VjdXJpdHkvc2FuZGJveGVkLWlmcmFtZS1mb3JtLXRvcC5odG1sCkBAIC0wLDAgKzEs
MTUgQEAKKzxodG1sPgorPGhlYWQ+Cis8c2NyaXB0PgoraWYgKHdpbmRvdy5sYXlvdXRUZXN0Q29u
dHJvbGxlcikKKyAgICB3aW5kb3cubGF5b3V0VGVzdENvbnRyb2xsZXIuZHVtcEFzVGV4dCgpOwor
PC9zY3JpcHQ+Cis8L2hlYWQ+Cis8Ym9keT4KKzxwPlRoaXMgdGVzdHMgcGFzc2VzIGlmIHRoZSBz
YW5kYm94ZWQgZnJhbWUgY2Fubm90IG5hdmlnYXRlIHRoZSB0b3AgZnJhbWUuPC9wPgorPHA+UEFT
UzwvcD4KKzxpZnJhbWUgc2FuZGJveD0iYWxsb3ctZm9ybXMgYWxsb3ctc2NyaXB0cyIKKyAgICAg
ICAgc3JjPSJyZXNvdXJjZXMvc2FuZGJveGVkLWlmcmFtZS1mb3JtLXRvcC5odG1sIj4KKzwvaWZy
YW1lPgorPC9ib2R5PgorPC9odG1sPgpkaWZmIC0tZ2l0IGEvV2ViQ29yZS9DaGFuZ2VMb2cgYi9X
ZWJDb3JlL0NoYW5nZUxvZwppbmRleCA3NWVmMWMxLi44MjE1YjEwIDEwMDY0NAotLS0gYS9XZWJD
b3JlL0NoYW5nZUxvZworKysgYi9XZWJDb3JlL0NoYW5nZUxvZwpAQCAtMSwzICsxLDIwIEBACisy
MDEwLTAyLTEyICBBZGFtIEJhcnRoICA8YWJhcnRoQHdlYmtpdC5vcmc+CisKKyAgICAgICAgUmV2
aWV3ZWQgYnkgTk9CT0RZIChPT1BTISkuCisKKyAgICAgICAgSFRNTDUgaWZyYW1lIHNhbmRib3gg
YnlwYXNzIG9mIHdpbmRvdy50b3AubG9jYXRpb24gbmF2aWdhdGlvbiB2aWEgPGZvcm0gdGFyZ2V0
PSJfdG9wIj4KKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcuY2dpP2lk
PTMzMjc3CisKKyAgICAgICAgc3VibWl0Rm9ybSB3YXNuJ3QgcmVzcGVjdGluZyBzaG91bGRBbGxv
d05hdmlnYXRpb24uICBJbnN0ZWFkIG9mIGNhbGxpbmcKKyAgICAgICAgdGhlIHdyYXBwZXIgZnVu
Y3Rpb24sIHdlIG5lZWQgdG8gY2FsbCBzaG91bGRBbGxvd05hdmlnYXRpb24gYmVjYXVzZSB3ZQor
ICAgICAgICBuZWVkIHRvIGhhbmRsZSB0aGUgImZyYW1lIG5vdCBmb3VuZCIgY2FzZSBkaWZmZXJl
bnRseSB0aGFuIHRoZQorICAgICAgICAibmF2aWdhdGlvbiBkZW5pZWQiIGNhc2UuCisKKyAgICAg
ICAgVGVzdDogaHR0cC90ZXN0cy9zZWN1cml0eS9zYW5kYm94ZWQtaWZyYW1lLWZvcm0tdG9wLmh0
bWwKKworICAgICAgICAqIGxvYWRlci9GcmFtZUxvYWRlci5jcHA6CisgICAgICAgIChXZWJDb3Jl
OjpGcmFtZUxvYWRlcjo6c3VibWl0Rm9ybSk6CisKIDIwMTAtMDEtMDUgIE9qYW4gVmFmYWkgIDxv
amFuQGNocm9taXVtLm9yZz4KIAogICAgICAgICBSZXZpZXdlZCBieSBEYW4gQmVybnN0ZWluLgpk
aWZmIC0tZ2l0IGEvV2ViQ29yZS9sb2FkZXIvRnJhbWVMb2FkZXIuY3BwIGIvV2ViQ29yZS9sb2Fk
ZXIvRnJhbWVMb2FkZXIuY3BwCmluZGV4IGEyMWZmOTMuLjQ3ZjMyYzkgMTAwNjQ0Ci0tLSBhL1dl
YkNvcmUvbG9hZGVyL0ZyYW1lTG9hZGVyLmNwcAorKysgYi9XZWJDb3JlL2xvYWRlci9GcmFtZUxv
YWRlci5jcHAKQEAgLTQ2Myw3ICs0NjMsOSBAQCB2b2lkIEZyYW1lTG9hZGVyOjpzdWJtaXRGb3Jt
KGNvbnN0IGNoYXIqIGFjdGlvbiwgY29uc3QgU3RyaW5nJiB1cmwsIFBhc3NSZWZQdHI8RgogICAg
IEZyYW1lTG9hZFJlcXVlc3QgZnJhbWVSZXF1ZXN0OwogCiAgICAgU3RyaW5nIHRhcmdldE9yQmFz
ZVRhcmdldCA9IHRhcmdldC5pc0VtcHR5KCkgPyBtX2ZyYW1lLT5kb2N1bWVudCgpLT5iYXNlVGFy
Z2V0KCkgOiB0YXJnZXQ7Ci0gICAgRnJhbWUqIHRhcmdldEZyYW1lID0gZmluZEZyYW1lRm9yTmF2
aWdhdGlvbih0YXJnZXRPckJhc2VUYXJnZXQpOworICAgIEZyYW1lKiB0YXJnZXRGcmFtZSA9IG1f
ZnJhbWUtPnRyZWUoKS0+ZmluZCh0YXJnZXRPckJhc2VUYXJnZXQpOworICAgIGlmICghc2hvdWxk
QWxsb3dOYXZpZ2F0aW9uKHRhcmdldEZyYW1lKSkKKyAgICAgICAgcmV0dXJuOwogICAgIGlmICgh
dGFyZ2V0RnJhbWUpIHsKICAgICAgICAgdGFyZ2V0RnJhbWUgPSBtX2ZyYW1lOwogICAgICAgICBm
cmFtZVJlcXVlc3Quc2V0RnJhbWVOYW1lKHRhcmdldE9yQmFzZVRhcmdldCk7Cg==
</data>
<flag name="commit-queue"
          id="31462"
          type_id="3"
          status="-"
          setter="commit-queue"
    />
          </attachment>
      

    </bug>

</bugzilla>