Retrieving Blobs from IndexedDB using cursors fails in WK2 (Sandboxing)
[WebKit-https.git] / Source / WebKit2 / DatabaseProcess / DatabaseProcess.cpp
1 /*
2  * Copyright (C) 2013, 2014, 2015, 2016 Apple Inc. All rights reserved.
3  *
4  * Redistribution and use in source and binary forms, with or without
5  * modification, are permitted provided that the following conditions
6  * are met:
7  * 1. Redistributions of source code must retain the above copyright
8  *    notice, this list of conditions and the following disclaimer.
9  * 2. Redistributions in binary form must reproduce the above copyright
10  *    notice, this list of conditions and the following disclaimer in the
11  *    documentation and/or other materials provided with the distribution.
12  *
13  * THIS SOFTWARE IS PROVIDED BY APPLE INC. AND ITS CONTRIBUTORS ``AS IS''
14  * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
15  * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
16  * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL APPLE INC. OR ITS CONTRIBUTORS
17  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
18  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
19  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
20  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
21  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
22  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
23  * THE POSSIBILITY OF SUCH DAMAGE.
24  */
25
26 #include "config.h"
27 #include "DatabaseProcess.h"
28
29 #if ENABLE(DATABASE_PROCESS)
30
31 #include "DatabaseProcessCreationParameters.h"
32 #include "DatabaseProcessMessages.h"
33 #include "DatabaseProcessProxyMessages.h"
34 #include "DatabaseToWebProcessConnection.h"
35 #include "WebCoreArgumentCoders.h"
36 #include "WebsiteData.h"
37 #include <WebCore/FileSystem.h>
38 #include <WebCore/IDBKeyData.h>
39 #include <WebCore/NotImplemented.h>
40 #include <WebCore/SessionID.h>
41 #include <WebCore/TextEncoding.h>
42 #include <wtf/CrossThreadTask.h>
43 #include <wtf/MainThread.h>
44
45 using namespace WebCore;
46
47 namespace WebKit {
48
49 DatabaseProcess& DatabaseProcess::singleton()
50 {
51     static NeverDestroyed<DatabaseProcess> databaseProcess;
52     return databaseProcess;
53 }
54
55 DatabaseProcess::DatabaseProcess()
56     : m_queue(WorkQueue::create("com.apple.WebKit.DatabaseProcess"))
57 {
58     // Make sure the UTF8Encoding encoding and the text encoding maps have been built on the main thread before a background thread needs it.
59     // FIXME: https://bugs.webkit.org/show_bug.cgi?id=135365 - Need a more explicit way of doing this besides accessing the UTF8Encoding.
60     UTF8Encoding();
61 }
62
63 DatabaseProcess::~DatabaseProcess()
64 {
65 }
66
67 void DatabaseProcess::initializeConnection(IPC::Connection* connection)
68 {
69     ChildProcess::initializeConnection(connection);
70 }
71
72 bool DatabaseProcess::shouldTerminate()
73 {
74     return true;
75 }
76
77 void DatabaseProcess::didClose(IPC::Connection&)
78 {
79     RunLoop::current().stop();
80 }
81
82 void DatabaseProcess::didReceiveMessage(IPC::Connection& connection, IPC::MessageDecoder& decoder)
83 {
84     if (messageReceiverMap().dispatchMessage(connection, decoder))
85         return;
86
87     if (decoder.messageReceiverName() == Messages::DatabaseProcess::messageReceiverName()) {
88         didReceiveDatabaseProcessMessage(connection, decoder);
89         return;
90     }
91 }
92
93 void DatabaseProcess::didReceiveInvalidMessage(IPC::Connection&, IPC::StringReference, IPC::StringReference)
94 {
95     RunLoop::current().stop();
96 }
97
98 #if ENABLE(INDEXED_DATABASE)
99 IDBServer::IDBServer& DatabaseProcess::idbServer()
100 {
101     if (!m_idbServer)
102         m_idbServer = IDBServer::IDBServer::create(indexedDatabaseDirectory(), DatabaseProcess::singleton());
103
104     return *m_idbServer;
105 }
106 #endif
107
108 void DatabaseProcess::initializeDatabaseProcess(const DatabaseProcessCreationParameters& parameters)
109 {
110 #if ENABLE(INDEXED_DATABASE)
111     // *********
112     // IMPORTANT: Do not change the directory structure for indexed databases on disk without first consulting a reviewer from Apple (<rdar://problem/17454712>)
113     // *********
114
115     m_indexedDatabaseDirectory = parameters.indexedDatabaseDirectory;
116     SandboxExtension::consumePermanently(parameters.indexedDatabaseDirectoryExtensionHandle);
117
118     ensureIndexedDatabaseRelativePathExists(StringImpl::empty());
119 #endif
120 }
121
122 #if ENABLE(INDEXED_DATABASE)
123 void DatabaseProcess::ensureIndexedDatabaseRelativePathExists(const String& relativePath)
124 {
125     postDatabaseTask(createCrossThreadTask(*this, &DatabaseProcess::ensurePathExists, absoluteIndexedDatabasePathFromDatabaseRelativePath(relativePath)));
126 }
127 #endif
128
129 void DatabaseProcess::ensurePathExists(const String& path)
130 {
131     ASSERT(!RunLoop::isMain());
132
133     if (!makeAllDirectories(path))
134         LOG_ERROR("Failed to make all directories for path '%s'", path.utf8().data());
135 }
136
137 #if ENABLE(INDEXED_DATABASE)
138 String DatabaseProcess::absoluteIndexedDatabasePathFromDatabaseRelativePath(const String& relativePath)
139 {
140     // FIXME: pathByAppendingComponent() was originally designed to append individual atomic components.
141     // We don't have a function designed to append a multi-component subpath, but we should.
142     return pathByAppendingComponent(m_indexedDatabaseDirectory, relativePath);
143 }
144 #endif
145
146 void DatabaseProcess::postDatabaseTask(CrossThreadTask&& task)
147 {
148     ASSERT(RunLoop::isMain());
149
150     LockHolder locker(m_databaseTaskMutex);
151
152     m_databaseTasks.append(WTFMove(task));
153
154     m_queue->dispatch([this] {
155         performNextDatabaseTask();
156     });
157 }
158
159 void DatabaseProcess::performNextDatabaseTask()
160 {
161     ASSERT(!RunLoop::isMain());
162
163     CrossThreadTask task;
164     {
165         LockHolder locker(m_databaseTaskMutex);
166         ASSERT(!m_databaseTasks.isEmpty());
167         task = m_databaseTasks.takeFirst();
168     }
169
170     task.performTask();
171 }
172
173 void DatabaseProcess::createDatabaseToWebProcessConnection()
174 {
175 #if USE(UNIX_DOMAIN_SOCKETS)
176     IPC::Connection::SocketPair socketPair = IPC::Connection::createPlatformConnection();
177     m_databaseToWebProcessConnections.append(DatabaseToWebProcessConnection::create(socketPair.server));
178     parentProcessConnection()->send(Messages::DatabaseProcessProxy::DidCreateDatabaseToWebProcessConnection(IPC::Attachment(socketPair.client)), 0);
179 #elif OS(DARWIN)
180     // Create the listening port.
181     mach_port_t listeningPort;
182     mach_port_allocate(mach_task_self(), MACH_PORT_RIGHT_RECEIVE, &listeningPort);
183
184     // Create a listening connection.
185     auto connection = DatabaseToWebProcessConnection::create(IPC::Connection::Identifier(listeningPort));
186     m_databaseToWebProcessConnections.append(WTFMove(connection));
187
188     IPC::Attachment clientPort(listeningPort, MACH_MSG_TYPE_MAKE_SEND);
189     parentProcessConnection()->send(Messages::DatabaseProcessProxy::DidCreateDatabaseToWebProcessConnection(clientPort), 0);
190 #else
191     notImplemented();
192 #endif
193 }
194
195 void DatabaseProcess::fetchWebsiteData(SessionID, OptionSet<WebsiteDataType> websiteDataTypes, uint64_t callbackID)
196 {
197 #if ENABLE(INDEXED_DATABASE)
198     auto completionHandler = [this, callbackID](const WebsiteData& websiteData) {
199         parentProcessConnection()->send(Messages::DatabaseProcessProxy::DidFetchWebsiteData(callbackID, websiteData), 0);
200     };
201
202     if (websiteDataTypes.contains(WebsiteDataType::IndexedDBDatabases)) {
203         // FIXME: Pick the right database store based on the session ID.
204         postDatabaseTask(CrossThreadTask([this, websiteDataTypes, completionHandler = WTFMove(completionHandler)]() mutable {
205             RunLoop::main().dispatch([completionHandler = WTFMove(completionHandler), securityOrigins = indexedDatabaseOrigins()] {
206                 WebsiteData websiteData;
207                 for (const auto& securityOrigin : securityOrigins)
208                     websiteData.entries.append({ securityOrigin, WebsiteDataType::IndexedDBDatabases, 0 });
209
210                 completionHandler(websiteData);
211             });
212         }));
213     }
214 #endif
215 }
216
217 void DatabaseProcess::deleteWebsiteData(WebCore::SessionID, OptionSet<WebsiteDataType> websiteDataTypes, std::chrono::system_clock::time_point modifiedSince, uint64_t callbackID)
218 {
219 #if ENABLE(INDEXED_DATABASE)
220     auto completionHandler = [this, callbackID]() {
221         parentProcessConnection()->send(Messages::DatabaseProcessProxy::DidDeleteWebsiteData(callbackID), 0);
222     };
223
224     if (websiteDataTypes.contains(WebsiteDataType::IndexedDBDatabases))
225         idbServer().closeAndDeleteDatabasesModifiedSince(modifiedSince, WTFMove(completionHandler));
226 #endif
227 }
228
229 void DatabaseProcess::deleteWebsiteDataForOrigins(WebCore::SessionID, OptionSet<WebsiteDataType> websiteDataTypes, const Vector<SecurityOriginData>& securityOriginDatas, uint64_t callbackID)
230 {
231 #if ENABLE(INDEXED_DATABASE)
232     auto completionHandler = [this, callbackID]() {
233         parentProcessConnection()->send(Messages::DatabaseProcessProxy::DidDeleteWebsiteDataForOrigins(callbackID), 0);
234     };
235
236     if (websiteDataTypes.contains(WebsiteDataType::IndexedDBDatabases))
237         idbServer().closeAndDeleteDatabasesForOrigins(securityOriginDatas, WTFMove(completionHandler));
238 #endif
239 }
240
241 void DatabaseProcess::grantSandboxExtensionsForBlobs(const Vector<String>& paths, const SandboxExtension::HandleArray& handles)
242 {
243     ASSERT(paths.size() == handles.size());
244
245     for (size_t i = 0; i < paths.size(); ++i) {
246         auto result = m_blobTemporaryFileSandboxExtensions.add(paths[i], SandboxExtension::create(handles[i]));
247         ASSERT_UNUSED(result, result.isNewEntry);
248     }
249 }
250
251 #if ENABLE(INDEXED_DATABASE)
252 void DatabaseProcess::prepareForAccessToTemporaryFile(const String& path)
253 {
254     if (auto extension = m_blobTemporaryFileSandboxExtensions.get(path))
255         extension->consume();
256 }
257
258 void DatabaseProcess::accessToTemporaryFileComplete(const String& path)
259 {
260     // We've either hard linked the temporary blob file to the database directory, copied it there,
261     // or the transaction is being aborted.
262     // In any of those cases, we can delete the temporary blob file now.
263     deleteFile(path);
264
265     if (auto extension = m_blobTemporaryFileSandboxExtensions.take(path))
266         extension->revoke();
267 }
268
269 Vector<RefPtr<WebCore::SecurityOrigin>> DatabaseProcess::indexedDatabaseOrigins()
270 {
271     if (m_indexedDatabaseDirectory.isEmpty())
272         return { };
273
274     Vector<RefPtr<WebCore::SecurityOrigin>> securityOrigins;
275     for (auto& originPath : listDirectory(m_indexedDatabaseDirectory, "*")) {
276         String databaseIdentifier = pathGetFileName(originPath);
277
278         if (auto securityOrigin = SecurityOrigin::maybeCreateFromDatabaseIdentifier(databaseIdentifier))
279             securityOrigins.append(WTFMove(securityOrigin));
280     }
281
282     return securityOrigins;
283 }
284
285 #endif
286
287 void DatabaseProcess::getSandboxExtensionsForBlobFiles(const Vector<String>& filenames, std::function<void (SandboxExtension::HandleArray&&)> completionHandler)
288 {
289     static uint64_t lastRequestID;
290
291     uint64_t requestID = ++lastRequestID;
292     m_sandboxExtensionForBlobsCompletionHandlers.set(requestID, completionHandler);
293     parentProcessConnection()->send(Messages::DatabaseProcessProxy::GetSandboxExtensionsForBlobFiles(requestID, filenames), 0);
294 }
295
296 void DatabaseProcess::didGetSandboxExtensionsForBlobFiles(uint64_t requestID, SandboxExtension::HandleArray&& handles)
297 {
298     if (auto handler = m_sandboxExtensionForBlobsCompletionHandlers.take(requestID))
299         handler(WTFMove(handles));
300 }
301
302 #if !PLATFORM(COCOA)
303 void DatabaseProcess::initializeProcess(const ChildProcessInitializationParameters&)
304 {
305 }
306
307 void DatabaseProcess::initializeProcessName(const ChildProcessInitializationParameters&)
308 {
309 }
310
311 void DatabaseProcess::initializeSandbox(const ChildProcessInitializationParameters&, SandboxInitializationParameters&)
312 {
313 }
314 #endif
315
316 } // namespace WebKit
317
318 #endif // ENABLE(DATABASE_PROCESS)