🔒 全面加固跨世界 GM RPC、用户脚本、Sandbox 与 Agent 边界 - #1747
Draft
cyfung1031 wants to merge 242 commits into
Draft
cyfung1031 wants to merge 242 commits into
cyfung1031 wants to merge 242 commits into
Conversation
cyfung1031
marked this pull request as draft
September 16, 2026 23:03
Bind USER_SCRIPT bootstrap data to the service-worker-issued document token, preserve sender provenance, and enforce per-execution GM capabilities across page RPC and native message paths. Harden captured collection operations and exact-match early startup handling.
2 of 3 tasks
说明原生方法捕获、USER_SCRIPT 来源校验、页面 RPC 句柄生命周期、脚本包装完整性和回调收尾约束,降低后续维护时误改安全契约的风险。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Checklist / 检查清单
背景
本 PR 的说明仅以当前完整代码树为准:
scriptscat:main80854540dd1759e55ce79f541fcf582ba9c0a499对比 PR headcc195781d048b7961e6af7d14029ce739998c73c。以下内容描述这两个最终状态之间的净差异,不引用 PR 中间 commits 曾经采用、随后修改或回退的方案。相较
main,本 PR 主要加固 MAIN world、USER_SCRIPT、Service Worker、Offscreen/Sandbox 与 Agent/CAT API 的跨上下文身份、传输、数据和生命周期边界;同时补齐 early-start 同步状态、GM storage 持久化兼容语义,以及异步 GM/RPC 收尾行为。变更总览
main的净变化scripting使用新增的PageEventMessage,以每个 document 的随机eventFlag派生performanceCustomEvent名称;pageLoad、value/event、external API 与 GM RPC 共用该 keyed bridgewindow.message总线上;随机 key 只降低被动可观察性,不承担授权PageRpcRegistry与 Service Worker execution binding;Page RPC v2 wire 使用handle + sequence + api + params,canonical UUID/run flag/envTag/grant 由 Service Worker 根据 handle 与真实 sender 解析RequestSequenceWindow;重复序列和窗口外旧序列拒绝,合法的大幅前向 gap 可按固定成本推进窗口content的普通 GM RPC、bootstrap、value update 与 event callback 使用浏览器原生 ExtensionMessage / user-script connection;同步 DOM 节点辅助仍单独使用 CustomEvent 路径;专用 user-script listener 不可用时可走 document token 绑定的 extension-port compatibility pathmain的 Offscreen/EventPage ↔ SandboxWindowMessage数据通道改为一次性 Window bootstrap + privateMessagePort;parent 校验 exact iframe source、固定 marker 与 exactly one transferred port,随后移除 Window listener;port attachment 同时作为 readinesswindow.message,也不能被动看到后续 sandbox 内部 GM/lifecycle/value/event/skill payloadMessagePort方法和原生MessageEvent.datagetter,wire envelope 继续做 data-property/shape 校验Document、metadata,并记录 UUID/flag/scriptRevision;执行前用捕获的原生Function.prototype.toString和当前Document读取 metadata,再与 authoritative script revision 对齐Object.assign的普通赋值语义Object.prototypesetter、__proto__等页面可控原型行为影响内部权威状态更新main会把 early-startscriptInfo放入 page-visible bootstrap event;HEAD 的 event detail 只保留scriptFlag,同步 value/config/userConfig/resource snapshot 保留在 registered wrapper closure;execution binding 仍由 authoritative pageLoad 下发scriptRevision/execution binding,并保留 bootstrap 前脚本自身已完成的 set/delete keystorageName串行 DB commit、value delivery 与 registered snapshot refresh;shared storage 同批更新;value-only refresh 不推进 static code/resource revision,并有 dirty/repair 路径null;cycle 无效;top-level Function/Symbol/BigInt 继续使用 ScriptCat 的删除语义;getter/Proxy property read 在此 compatibility surface 可观察REncoded增加NaN、Infinity、-Infinity显式 tag;all-values 路径返回 null-prototype dictionary,并安全保留__proto__等 own keyGM.setValue/ batch/delete 以 Service Worker RPC 与 freshness barrier 完成为准,不再依赖 valueUpdate broadcast 来 resolve;legacy 同步 API 仍立即返回request.script.uuid覆盖/注入 script identity;conversation/task/attachment/OPFS/DOM monitor 的访问检查使用该 canonical identityscriptUuid访问另一脚本资源ownerScriptUuid并按 owner 检查;task CRUD/run/history 按 owner scope;task 使用 generation/revision;attachment read 需在调用脚本拥有的持久化 conversation 中可达WindowMessageConnect减少重复实现main的边界和兼容语义固定为可重复验证PR 范围
scriptscat:main@80854540dd1759e55ce79f541fcf582ba9c0a499codex/main-world-security-refactor@cc195781d048b7961e6af7d14029ce739998c73c实现考虑
scriptRevision表示 compiled artifact;closure capturedDocument与 SW execution binding 表示具体运行实例/transport identity,三者不互相替代request.script.uuid决定 owner;UI/extension-internal 调用与 script-scoped 调用继续走各自现有权限模型已知限制
PageEventMessage仍是 page-visible transport。随机eventFlag不是 bearer secret,也不能替代 broker/Service Worker authorization。PageEventMessage没有通用 ready buffer;当前入口在 eventFlag negotiation 前预取 authoritative pageLoad,但只在 bridge 建立后消费并发送页面 payload。未来新增更早发送的 caller 时仍需单独证明 ordering。MessagePort,parent 不会报告 verified readiness,也不会 replay background/scheduled script;当前没有 timeout-ready 路径。chrome.userScripts.update/registration failure 下,storage 已成功但下一次 wrapper snapshot 可暂时 dirty,后续 repair/registration mutation 会再尝试恢复。undefined表现可不同。建议审查重点
PageEventMessage上所有 privileged request 是否都经过 shape/clone、handle、grant、sequence 与真实 sender 校验scriptRevision、authoritative reconcile 和 bootstrap 前本地写入是否组成一致生命周期验证
scriptscat:main80854540dd1759e55ce79f541fcf582ba9c0a499→ PR headcc195781d048b7961e6af7d14029ce739998c73c;ahead 239 / behind 0;143 files;+16,266 / -2,000e2e/main-world-keyed-bridge.spec.ts、page_event_message.test.ts、page_rpc.test.ts覆盖 keyed bridge、message envelope 与 handle/grant/sequence policye2e/sandbox-message-port.spec.ts、sandbox_message_channel.test.ts、message_port_message.ts相关测试覆盖 source/marker/one-port bootstrap、listener removal、private traffic 与 prototype poisoningexample/tests/gm_storage_test.js与e2e/gm-api.spec.ts覆盖 clone/normalization、unsupported value、special object、non-finite number,以及 immediate / RPC-settled / reload-persisted 三阶段