File: isolation_key_provider.h

package info (click to toggle)
chromium 120.0.6099.224-1~deb11u1
  • links: PTS, VCS
  • area: main
  • in suites: bullseye
  • size: 6,112,112 kB
  • sloc: cpp: 32,907,025; ansic: 8,148,123; javascript: 3,679,536; python: 2,031,248; asm: 959,718; java: 804,675; xml: 617,256; sh: 111,417; objc: 100,835; perl: 88,443; cs: 53,032; makefile: 29,579; fortran: 24,137; php: 21,162; tcl: 21,147; sql: 20,809; ruby: 17,735; pascal: 12,864; yacc: 8,045; lisp: 3,388; lex: 1,323; ada: 727; awk: 329; jsp: 267; csh: 117; exp: 43; sed: 37
file content (39 lines) | stat: -rw-r--r-- 1,659 bytes parent folder | download | duplicates (8)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
// Copyright (c) 2022 The Chromium Authors
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.

#ifndef GPU_COMMAND_BUFFER_SERVICE_ISOLATION_KEY_PROVIDER_H_
#define GPU_COMMAND_BUFFER_SERVICE_ISOLATION_KEY_PROVIDER_H_

#include "base/functional/callback.h"
#include "gpu/gpu_gles2_export.h"
#include "third_party/blink/public/common/tokens/tokens.h"

namespace gpu {

// Interface that can be implemented and passed to users (i.e. decoders) to get
// an isolation key given an token. Note that in most cases, the token is
// passed via the client so it cannot necessarily be trusted. As a result, this
// provider is a layer of security that may either do validation on the token,
// or ask a trusted source for an isolation key given the client and frame. This
// way, the potential vulnerability surface is limited to at most the
// untrusted client.
// TODO(dawn:549) The interface is taking a WebGPUExecutionContextToken since it
//     is only used in WebGPU, and DocumentToken is not included in the default
//     ExecutionContextToken yet. This interface may be updated to use the
//     ExecutionContextToken should DocumentToken become a part of it.
class GPU_GLES2_EXPORT IsolationKeyProvider {
 public:
  using GetIsolationKeyCallback =
      base::OnceCallback<void(const std::string& isolation_key)>;

  virtual void GetIsolationKey(const blink::WebGPUExecutionContextToken& token,
                               GetIsolationKeyCallback cb) = 0;

 protected:
  virtual ~IsolationKeyProvider() = default;
};

}  // namespace gpu

#endif  // GPU_COMMAND_BUFFER_SERVICE_ISOLATION_KEY_PROVIDER_H_