1 // Copyright 2013 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file.
5 #include "content/browser/frame_host/render_frame_host_impl.h"
8 #include "base/command_line.h"
9 #include "base/containers/hash_tables.h"
10 #include "base/lazy_instance.h"
11 #include "base/metrics/histogram.h"
12 #include "base/process/kill.h"
13 #include "base/time/time.h"
14 #include "content/browser/accessibility/accessibility_mode_helper.h"
15 #include "content/browser/accessibility/browser_accessibility_manager.h"
16 #include "content/browser/accessibility/browser_accessibility_state_impl.h"
17 #include "content/browser/bad_message.h"
18 #include "content/browser/child_process_security_policy_impl.h"
19 #include "content/browser/frame_host/cross_process_frame_connector.h"
20 #include "content/browser/frame_host/cross_site_transferring_request.h"
21 #include "content/browser/frame_host/frame_accessibility.h"
22 #include "content/browser/frame_host/frame_mojo_shell.h"
23 #include "content/browser/frame_host/frame_tree.h"
24 #include "content/browser/frame_host/frame_tree_node.h"
25 #include "content/browser/frame_host/navigation_request.h"
26 #include "content/browser/frame_host/navigator.h"
27 #include "content/browser/frame_host/navigator_impl.h"
28 #include "content/browser/frame_host/render_frame_host_delegate.h"
29 #include "content/browser/frame_host/render_frame_proxy_host.h"
30 #include "content/browser/frame_host/render_widget_host_view_child_frame.h"
31 #include "content/browser/geolocation/geolocation_service_context.h"
32 #include "content/browser/permissions/permission_service_context.h"
33 #include "content/browser/permissions/permission_service_impl.h"
34 #include "content/browser/presentation/presentation_service_impl.h"
35 #include "content/browser/renderer_host/input/input_router.h"
36 #include "content/browser/renderer_host/input/timeout_monitor.h"
37 #include "content/browser/renderer_host/render_process_host_impl.h"
38 #include "content/browser/renderer_host/render_view_host_delegate.h"
39 #include "content/browser/renderer_host/render_view_host_delegate_view.h"
40 #include "content/browser/renderer_host/render_view_host_impl.h"
41 #include "content/browser/renderer_host/render_widget_host_impl.h"
42 #include "content/browser/renderer_host/render_widget_host_view_base.h"
43 #include "content/common/accessibility_messages.h"
44 #include "content/common/frame_messages.h"
45 #include "content/common/input_messages.h"
46 #include "content/common/inter_process_time_ticks_converter.h"
47 #include "content/common/navigation_params.h"
48 #include "content/common/render_frame_setup.mojom.h"
49 #include "content/common/swapped_out_messages.h"
50 #include "content/public/browser/ax_event_notification_details.h"
51 #include "content/public/browser/browser_accessibility_state.h"
52 #include "content/public/browser/browser_context.h"
53 #include "content/public/browser/browser_plugin_guest_manager.h"
54 #include "content/public/browser/browser_thread.h"
55 #include "content/public/browser/content_browser_client.h"
56 #include "content/public/browser/permission_manager.h"
57 #include "content/public/browser/permission_type.h"
58 #include "content/public/browser/render_process_host.h"
59 #include "content/public/browser/render_widget_host_view.h"
60 #include "content/public/browser/stream_handle.h"
61 #include "content/public/browser/user_metrics.h"
62 #include "content/public/common/content_constants.h"
63 #include "content/public/common/content_switches.h"
64 #include "content/public/common/url_constants.h"
65 #include "content/public/common/url_utils.h"
66 #include "content/public/renderer/isolated_world_ids.h"
67 #include "ui/accessibility/ax_tree.h"
68 #include "ui/accessibility/ax_tree_update.h"
71 #if defined(OS_ANDROID)
72 #include "content/browser/mojo/service_registrar_android.h"
75 #if defined(OS_MACOSX)
76 #include "content/browser/frame_host/popup_menu_helper_mac.h"
79 #if defined(ENABLE_MEDIA_MOJO_RENDERER)
80 #include "media/mojo/interfaces/media_renderer.mojom.h"
81 #include "media/mojo/services/mojo_renderer_service.h"
84 using base::TimeDelta
;
90 // The next value to use for the accessibility reset token.
91 int g_next_accessibility_reset_token
= 1;
93 // The next value to use for the javascript callback id.
94 int g_next_javascript_callback_id
= 1;
96 // The (process id, routing id) pair that identifies one RenderFrame.
97 typedef std::pair
<int32
, int32
> RenderFrameHostID
;
98 typedef base::hash_map
<RenderFrameHostID
, RenderFrameHostImpl
*>
100 base::LazyInstance
<RoutingIDFrameMap
> g_routing_id_frame_map
=
101 LAZY_INSTANCE_INITIALIZER
;
103 // Translate a WebKit text direction into a base::i18n one.
104 base::i18n::TextDirection
WebTextDirectionToChromeTextDirection(
105 blink::WebTextDirection dir
) {
107 case blink::WebTextDirectionLeftToRight
:
108 return base::i18n::LEFT_TO_RIGHT
;
109 case blink::WebTextDirectionRightToLeft
:
110 return base::i18n::RIGHT_TO_LEFT
;
113 return base::i18n::UNKNOWN_DIRECTION
;
120 bool RenderFrameHostImpl::IsRFHStateActive(RenderFrameHostImplState rfh_state
) {
121 return rfh_state
== STATE_DEFAULT
;
125 RenderFrameHost
* RenderFrameHost::FromID(int render_process_id
,
126 int render_frame_id
) {
127 return RenderFrameHostImpl::FromID(render_process_id
, render_frame_id
);
131 RenderFrameHostImpl
* RenderFrameHostImpl::FromID(int process_id
,
133 DCHECK_CURRENTLY_ON(BrowserThread::UI
);
134 RoutingIDFrameMap
* frames
= g_routing_id_frame_map
.Pointer();
135 RoutingIDFrameMap::iterator it
= frames
->find(
136 RenderFrameHostID(process_id
, routing_id
));
137 return it
== frames
->end() ? NULL
: it
->second
;
140 RenderFrameHostImpl::RenderFrameHostImpl(SiteInstance
* site_instance
,
141 RenderViewHostImpl
* render_view_host
,
142 RenderFrameHostDelegate
* delegate
,
143 RenderWidgetHostDelegate
* rwh_delegate
,
144 FrameTree
* frame_tree
,
145 FrameTreeNode
* frame_tree_node
,
148 : render_view_host_(render_view_host
),
150 site_instance_(static_cast<SiteInstanceImpl
*>(site_instance
)),
151 process_(site_instance
->GetProcess()),
152 cross_process_frame_connector_(NULL
),
153 render_frame_proxy_host_(NULL
),
154 frame_tree_(frame_tree
),
155 frame_tree_node_(frame_tree_node
),
156 render_widget_host_(nullptr),
157 routing_id_(routing_id
),
158 render_frame_created_(false),
159 navigations_suspended_(false),
160 is_waiting_for_beforeunload_ack_(false),
161 unload_ack_is_for_navigation_(false),
163 pending_commit_(false),
164 accessibility_reset_token_(0),
165 accessibility_reset_count_(0),
166 no_create_browser_accessibility_manager_for_testing_(false),
167 weak_ptr_factory_(this) {
168 bool is_swapped_out
= !!(flags
& CREATE_RF_SWAPPED_OUT
);
169 bool hidden
= !!(flags
& CREATE_RF_HIDDEN
);
170 frame_tree_
->AddRenderViewHostRef(render_view_host_
);
171 GetProcess()->AddRoute(routing_id_
, this);
172 g_routing_id_frame_map
.Get().insert(std::make_pair(
173 RenderFrameHostID(GetProcess()->GetID(), routing_id_
),
176 if (is_swapped_out
) {
177 rfh_state_
= STATE_SWAPPED_OUT
;
179 rfh_state_
= STATE_DEFAULT
;
180 GetSiteInstance()->increment_active_frame_count();
184 swapout_event_monitor_timeout_
.reset(new TimeoutMonitor(base::Bind(
185 &RenderFrameHostImpl::OnSwappedOut
, weak_ptr_factory_
.GetWeakPtr())));
187 if (flags
& CREATE_RF_NEEDS_RENDER_WIDGET_HOST
) {
188 render_widget_host_
= new RenderWidgetHostImpl(rwh_delegate
, GetProcess(),
189 MSG_ROUTING_NONE
, hidden
);
190 render_widget_host_
->set_owned_by_render_frame_host(true);
194 RenderFrameHostImpl::~RenderFrameHostImpl() {
195 GetProcess()->RemoveRoute(routing_id_
);
196 g_routing_id_frame_map
.Get().erase(
197 RenderFrameHostID(GetProcess()->GetID(), routing_id_
));
199 if (delegate_
&& render_frame_created_
)
200 delegate_
->RenderFrameDeleted(this);
202 FrameAccessibility::GetInstance()->OnRenderFrameHostDestroyed(this);
204 // If this was swapped out, it already decremented the active frame count of
205 // the SiteInstance it belongs to.
206 if (IsRFHStateActive(rfh_state_
))
207 GetSiteInstance()->decrement_active_frame_count();
209 // Notify the FrameTree that this RFH is going away, allowing it to shut down
210 // the corresponding RenderViewHost if it is no longer needed.
211 frame_tree_
->ReleaseRenderViewHostRef(render_view_host_
);
213 // NULL out the swapout timer; in crash dumps this member will be null only if
215 swapout_event_monitor_timeout_
.reset();
217 for (const auto& iter
: visual_state_callbacks_
) {
218 iter
.second
.Run(false);
221 if (render_widget_host_
) {
222 // Shutdown causes the RenderWidgetHost to delete itself.
223 render_widget_host_
->Shutdown();
227 int RenderFrameHostImpl::GetRoutingID() {
231 SiteInstanceImpl
* RenderFrameHostImpl::GetSiteInstance() {
232 return site_instance_
.get();
235 RenderProcessHost
* RenderFrameHostImpl::GetProcess() {
239 RenderFrameHost
* RenderFrameHostImpl::GetParent() {
240 FrameTreeNode
* parent_node
= frame_tree_node_
->parent();
243 return parent_node
->current_frame_host();
246 const std::string
& RenderFrameHostImpl::GetFrameName() {
247 return frame_tree_node_
->frame_name();
250 bool RenderFrameHostImpl::IsCrossProcessSubframe() {
251 FrameTreeNode
* parent_node
= frame_tree_node_
->parent();
254 return GetSiteInstance() !=
255 parent_node
->current_frame_host()->GetSiteInstance();
258 GURL
RenderFrameHostImpl::GetLastCommittedURL() {
259 return frame_tree_node_
->current_url();
262 gfx::NativeView
RenderFrameHostImpl::GetNativeView() {
263 RenderWidgetHostView
* view
= render_view_host_
->GetView();
266 return view
->GetNativeView();
269 void RenderFrameHostImpl::AddMessageToConsole(ConsoleMessageLevel level
,
270 const std::string
& message
) {
271 Send(new FrameMsg_AddMessageToConsole(routing_id_
, level
, message
));
274 void RenderFrameHostImpl::ExecuteJavaScript(
275 const base::string16
& javascript
) {
276 Send(new FrameMsg_JavaScriptExecuteRequest(routing_id_
,
281 void RenderFrameHostImpl::ExecuteJavaScript(
282 const base::string16
& javascript
,
283 const JavaScriptResultCallback
& callback
) {
284 int key
= g_next_javascript_callback_id
++;
285 Send(new FrameMsg_JavaScriptExecuteRequest(routing_id_
,
288 javascript_callbacks_
.insert(std::make_pair(key
, callback
));
291 void RenderFrameHostImpl::ExecuteJavaScriptWithUserGestureForTests(
292 const base::string16
& javascript
) {
293 Send(new FrameMsg_JavaScriptExecuteRequestForTests(routing_id_
,
298 void RenderFrameHostImpl::ExecuteJavaScriptInIsolatedWorld(
299 const base::string16
& javascript
,
300 const JavaScriptResultCallback
& callback
,
302 if (world_id
<= ISOLATED_WORLD_ID_GLOBAL
||
303 world_id
> ISOLATED_WORLD_ID_MAX
) {
304 // Return if the world_id is not valid.
309 int key
= g_next_javascript_callback_id
++;
310 Send(new FrameMsg_JavaScriptExecuteRequestInIsolatedWorld(
311 routing_id_
, javascript
, key
, true, world_id
));
312 javascript_callbacks_
.insert(std::make_pair(key
, callback
));
315 RenderViewHost
* RenderFrameHostImpl::GetRenderViewHost() {
316 return render_view_host_
;
319 ServiceRegistry
* RenderFrameHostImpl::GetServiceRegistry() {
320 return service_registry_
.get();
323 blink::WebPageVisibilityState
RenderFrameHostImpl::GetVisibilityState() {
324 // TODO(mlamouri,kenrb): call GetRenderWidgetHost() directly when it stops
325 // returning nullptr in some cases. See https://crbug.com/455245.
326 blink::WebPageVisibilityState visibility_state
=
327 RenderWidgetHostImpl::From(GetView()->GetRenderWidgetHost())->is_hidden()
328 ? blink::WebPageVisibilityStateHidden
329 : blink::WebPageVisibilityStateVisible
;
330 GetContentClient()->browser()->OverridePageVisibilityState(this,
332 return visibility_state
;
335 bool RenderFrameHostImpl::Send(IPC::Message
* message
) {
336 if (IPC_MESSAGE_ID_CLASS(message
->type()) == InputMsgStart
) {
337 return render_view_host_
->input_router()->SendInput(
338 make_scoped_ptr(message
));
341 return GetProcess()->Send(message
);
344 bool RenderFrameHostImpl::OnMessageReceived(const IPC::Message
&msg
) {
345 // Filter out most IPC messages if this frame is swapped out.
346 // We still want to handle certain ACKs to keep our state consistent.
347 if (is_swapped_out()) {
348 if (!SwappedOutMessages::CanHandleWhileSwappedOut(msg
)) {
349 // If this is a synchronous message and we decided not to handle it,
350 // we must send an error reply, or else the renderer will be stuck
351 // and won't respond to future requests.
353 IPC::Message
* reply
= IPC::SyncMessage::GenerateReply(&msg
);
354 reply
->set_reply_error();
357 // Don't continue looking for someone to handle it.
362 if (delegate_
->OnMessageReceived(this, msg
))
365 RenderFrameProxyHost
* proxy
=
366 frame_tree_node_
->render_manager()->GetProxyToParent();
367 if (proxy
&& proxy
->cross_process_frame_connector() &&
368 proxy
->cross_process_frame_connector()->OnMessageReceived(msg
))
372 IPC_BEGIN_MESSAGE_MAP(RenderFrameHostImpl
, msg
)
373 IPC_MESSAGE_HANDLER(FrameHostMsg_AddMessageToConsole
, OnAddMessageToConsole
)
374 IPC_MESSAGE_HANDLER(FrameHostMsg_Detach
, OnDetach
)
375 IPC_MESSAGE_HANDLER(FrameHostMsg_FrameFocused
, OnFrameFocused
)
376 IPC_MESSAGE_HANDLER(FrameHostMsg_DidStartProvisionalLoadForFrame
,
377 OnDidStartProvisionalLoadForFrame
)
378 IPC_MESSAGE_HANDLER(FrameHostMsg_DidFailProvisionalLoadWithError
,
379 OnDidFailProvisionalLoadWithError
)
380 IPC_MESSAGE_HANDLER(FrameHostMsg_DidFailLoadWithError
,
381 OnDidFailLoadWithError
)
382 IPC_MESSAGE_HANDLER_GENERIC(FrameHostMsg_DidCommitProvisionalLoad
,
383 OnDidCommitProvisionalLoad(msg
))
384 IPC_MESSAGE_HANDLER(FrameHostMsg_DidDropNavigation
, OnDidDropNavigation
)
385 IPC_MESSAGE_HANDLER(FrameHostMsg_OpenURL
, OnOpenURL
)
386 IPC_MESSAGE_HANDLER(FrameHostMsg_DocumentOnLoadCompleted
,
387 OnDocumentOnLoadCompleted
)
388 IPC_MESSAGE_HANDLER(FrameHostMsg_BeforeUnload_ACK
, OnBeforeUnloadACK
)
389 IPC_MESSAGE_HANDLER(FrameHostMsg_SwapOut_ACK
, OnSwapOutACK
)
390 IPC_MESSAGE_HANDLER(FrameHostMsg_ContextMenu
, OnContextMenu
)
391 IPC_MESSAGE_HANDLER(FrameHostMsg_JavaScriptExecuteResponse
,
392 OnJavaScriptExecuteResponse
)
393 IPC_MESSAGE_HANDLER(FrameHostMsg_VisualStateResponse
,
394 OnVisualStateResponse
)
395 IPC_MESSAGE_HANDLER_DELAY_REPLY(FrameHostMsg_RunJavaScriptMessage
,
396 OnRunJavaScriptMessage
)
397 IPC_MESSAGE_HANDLER_DELAY_REPLY(FrameHostMsg_RunBeforeUnloadConfirm
,
398 OnRunBeforeUnloadConfirm
)
399 IPC_MESSAGE_HANDLER(FrameHostMsg_DidAccessInitialDocument
,
400 OnDidAccessInitialDocument
)
401 IPC_MESSAGE_HANDLER(FrameHostMsg_DidDisownOpener
, OnDidDisownOpener
)
402 IPC_MESSAGE_HANDLER(FrameHostMsg_DidChangeName
, OnDidChangeName
)
403 IPC_MESSAGE_HANDLER(FrameHostMsg_DidAssignPageId
, OnDidAssignPageId
)
404 IPC_MESSAGE_HANDLER(FrameHostMsg_DidChangeSandboxFlags
,
405 OnDidChangeSandboxFlags
)
406 IPC_MESSAGE_HANDLER(FrameHostMsg_UpdateTitle
, OnUpdateTitle
)
407 IPC_MESSAGE_HANDLER(FrameHostMsg_UpdateEncoding
, OnUpdateEncoding
)
408 IPC_MESSAGE_HANDLER(FrameHostMsg_BeginNavigation
,
410 IPC_MESSAGE_HANDLER(FrameHostMsg_DispatchLoad
, OnDispatchLoad
)
411 IPC_MESSAGE_HANDLER(FrameHostMsg_TextSurroundingSelectionResponse
,
412 OnTextSurroundingSelectionResponse
)
413 IPC_MESSAGE_HANDLER(AccessibilityHostMsg_Events
, OnAccessibilityEvents
)
414 IPC_MESSAGE_HANDLER(AccessibilityHostMsg_LocationChanges
,
415 OnAccessibilityLocationChanges
)
416 IPC_MESSAGE_HANDLER(AccessibilityHostMsg_FindInPageResult
,
417 OnAccessibilityFindInPageResult
)
418 IPC_MESSAGE_HANDLER(AccessibilityHostMsg_SnapshotResponse
,
419 OnAccessibilitySnapshotResponse
)
420 IPC_MESSAGE_HANDLER(FrameHostMsg_ToggleFullscreen
, OnToggleFullscreen
)
421 // The following message is synthetic and doesn't come from RenderFrame, but
422 // from RenderProcessHost.
423 IPC_MESSAGE_HANDLER(FrameHostMsg_RenderProcessGone
, OnRenderProcessGone
)
424 IPC_MESSAGE_HANDLER(FrameHostMsg_DidStartLoading
, OnDidStartLoading
)
425 IPC_MESSAGE_HANDLER(FrameHostMsg_DidStopLoading
, OnDidStopLoading
)
426 IPC_MESSAGE_HANDLER(FrameHostMsg_DidChangeLoadProgress
,
427 OnDidChangeLoadProgress
)
428 #if defined(OS_MACOSX) || defined(OS_ANDROID)
429 IPC_MESSAGE_HANDLER(FrameHostMsg_ShowPopup
, OnShowPopup
)
430 IPC_MESSAGE_HANDLER(FrameHostMsg_HidePopup
, OnHidePopup
)
432 IPC_END_MESSAGE_MAP()
434 // No further actions here, since we may have been deleted.
438 void RenderFrameHostImpl::AccessibilitySetFocus(int object_id
) {
439 Send(new AccessibilityMsg_SetFocus(routing_id_
, object_id
));
442 void RenderFrameHostImpl::AccessibilityDoDefaultAction(int object_id
) {
443 Send(new AccessibilityMsg_DoDefaultAction(routing_id_
, object_id
));
446 void RenderFrameHostImpl::AccessibilityShowContextMenu(int acc_obj_id
) {
447 Send(new AccessibilityMsg_ShowContextMenu(routing_id_
, acc_obj_id
));
450 void RenderFrameHostImpl::AccessibilityScrollToMakeVisible(
451 int acc_obj_id
, const gfx::Rect
& subfocus
) {
452 Send(new AccessibilityMsg_ScrollToMakeVisible(
453 routing_id_
, acc_obj_id
, subfocus
));
456 void RenderFrameHostImpl::AccessibilityScrollToPoint(
457 int acc_obj_id
, const gfx::Point
& point
) {
458 Send(new AccessibilityMsg_ScrollToPoint(
459 routing_id_
, acc_obj_id
, point
));
462 void RenderFrameHostImpl::AccessibilitySetTextSelection(
463 int object_id
, int start_offset
, int end_offset
) {
464 Send(new AccessibilityMsg_SetTextSelection(
465 routing_id_
, object_id
, start_offset
, end_offset
));
468 void RenderFrameHostImpl::AccessibilitySetValue(
469 int object_id
, const base::string16
& value
) {
470 Send(new AccessibilityMsg_SetValue(routing_id_
, object_id
, value
));
473 bool RenderFrameHostImpl::AccessibilityViewHasFocus() const {
474 RenderWidgetHostView
* view
= render_view_host_
->GetView();
476 return view
->HasFocus();
480 gfx::Rect
RenderFrameHostImpl::AccessibilityGetViewBounds() const {
481 RenderWidgetHostView
* view
= render_view_host_
->GetView();
483 return view
->GetViewBounds();
487 gfx::Point
RenderFrameHostImpl::AccessibilityOriginInScreen(
488 const gfx::Rect
& bounds
) const {
489 RenderWidgetHostViewBase
* view
= static_cast<RenderWidgetHostViewBase
*>(
490 render_view_host_
->GetView());
492 return view
->AccessibilityOriginInScreen(bounds
);
496 void RenderFrameHostImpl::AccessibilityHitTest(const gfx::Point
& point
) {
497 Send(new AccessibilityMsg_HitTest(routing_id_
, point
));
500 void RenderFrameHostImpl::AccessibilitySetAccessibilityFocus(int acc_obj_id
) {
501 Send(new AccessibilityMsg_SetAccessibilityFocus(routing_id_
, acc_obj_id
));
504 void RenderFrameHostImpl::AccessibilityFatalError() {
505 browser_accessibility_manager_
.reset(NULL
);
506 if (accessibility_reset_token_
)
509 accessibility_reset_count_
++;
510 if (accessibility_reset_count_
>= kMaxAccessibilityResets
) {
511 Send(new AccessibilityMsg_FatalError(routing_id_
));
513 accessibility_reset_token_
= g_next_accessibility_reset_token
++;
514 UMA_HISTOGRAM_COUNTS("Accessibility.FrameResetCount", 1);
515 Send(new AccessibilityMsg_Reset(routing_id_
, accessibility_reset_token_
));
519 gfx::AcceleratedWidget
520 RenderFrameHostImpl::AccessibilityGetAcceleratedWidget() {
521 RenderWidgetHostViewBase
* view
= static_cast<RenderWidgetHostViewBase
*>(
522 render_view_host_
->GetView());
524 return view
->AccessibilityGetAcceleratedWidget();
525 return gfx::kNullAcceleratedWidget
;
528 gfx::NativeViewAccessible
529 RenderFrameHostImpl::AccessibilityGetNativeViewAccessible() {
530 RenderWidgetHostViewBase
* view
= static_cast<RenderWidgetHostViewBase
*>(
531 render_view_host_
->GetView());
533 return view
->AccessibilityGetNativeViewAccessible();
537 BrowserAccessibilityManager
* RenderFrameHostImpl::AccessibilityGetChildFrame(
538 int accessibility_node_id
) {
539 RenderFrameHostImpl
* child_frame
=
540 FrameAccessibility::GetInstance()->GetChild(this, accessibility_node_id
);
541 if (!child_frame
|| IsSameSiteInstance(child_frame
))
544 return child_frame
->GetOrCreateBrowserAccessibilityManager();
547 void RenderFrameHostImpl::AccessibilityGetAllChildFrames(
548 std::vector
<BrowserAccessibilityManager
*>* child_frames
) {
549 std::vector
<RenderFrameHostImpl
*> child_frame_hosts
;
550 FrameAccessibility::GetInstance()->GetAllChildFrames(
551 this, &child_frame_hosts
);
552 for (size_t i
= 0; i
< child_frame_hosts
.size(); ++i
) {
553 RenderFrameHostImpl
* child_frame_host
= child_frame_hosts
[i
];
554 if (!child_frame_host
|| IsSameSiteInstance(child_frame_host
))
557 BrowserAccessibilityManager
* manager
=
558 child_frame_host
->GetOrCreateBrowserAccessibilityManager();
560 child_frames
->push_back(manager
);
564 BrowserAccessibility
* RenderFrameHostImpl::AccessibilityGetParentFrame() {
565 RenderFrameHostImpl
* parent_frame
= NULL
;
566 int parent_node_id
= 0;
567 if (!FrameAccessibility::GetInstance()->GetParent(
568 this, &parent_frame
, &parent_node_id
)) {
572 // As a sanity check, make sure the frame we're going to return belongs
573 // to the same BrowserContext.
574 if (GetSiteInstance()->GetBrowserContext() !=
575 parent_frame
->GetSiteInstance()->GetBrowserContext()) {
580 BrowserAccessibilityManager
* manager
=
581 parent_frame
->browser_accessibility_manager();
585 return manager
->GetFromID(parent_node_id
);
588 bool RenderFrameHostImpl::CreateRenderFrame(int parent_routing_id
,
589 int previous_sibling_routing_id
,
590 int proxy_routing_id
) {
591 TRACE_EVENT0("navigation", "RenderFrameHostImpl::CreateRenderFrame");
592 DCHECK(!IsRenderFrameLive()) << "Creating frame twice";
594 // The process may (if we're sharing a process with another host that already
595 // initialized it) or may not (we have our own process or the old process
596 // crashed) have been initialized. Calling Init multiple times will be
597 // ignored, so this is safe.
598 if (!GetProcess()->Init())
601 DCHECK(GetProcess()->HasConnection());
603 FrameMsg_NewFrame_Params params
;
604 params
.routing_id
= routing_id_
;
605 params
.parent_routing_id
= parent_routing_id
;
606 params
.proxy_routing_id
= proxy_routing_id
;
607 params
.previous_sibling_routing_id
= previous_sibling_routing_id
;
608 params
.replication_state
= frame_tree_node()->current_replication_state();
610 if (render_widget_host_
) {
611 params
.widget_params
.routing_id
= render_widget_host_
->GetRoutingID();
612 params
.widget_params
.surface_id
= render_widget_host_
->surface_id();
613 params
.widget_params
.hidden
= render_widget_host_
->is_hidden();
615 // MSG_ROUTING_NONE will prevent a new RenderWidget from being created in
616 // the renderer process.
617 params
.widget_params
.routing_id
= MSG_ROUTING_NONE
;
618 params
.widget_params
.surface_id
= 0;
619 params
.widget_params
.hidden
= true;
622 Send(new FrameMsg_NewFrame(params
));
624 // The RenderWidgetHost takes ownership of its view. It is tied to the
625 // lifetime of the current RenderProcessHost for this RenderFrameHost.
626 if (render_widget_host_
) {
627 RenderWidgetHostView
* rwhv
=
628 new RenderWidgetHostViewChildFrame(render_widget_host_
);
632 if (proxy_routing_id
!= MSG_ROUTING_NONE
) {
633 RenderFrameProxyHost
* proxy
= RenderFrameProxyHost::FromID(
634 GetProcess()->GetID(), proxy_routing_id
);
635 // We have also created a RenderFrameProxy in FrameMsg_NewFrame above, so
637 proxy
->set_render_frame_proxy_created(true);
640 // The renderer now has a RenderFrame for this RenderFrameHost. Note that
641 // this path is only used for out-of-process iframes. Main frame RenderFrames
642 // are created with their RenderView, and same-site iframes are created at the
643 // time of OnCreateChildFrame.
644 SetRenderFrameCreated(true);
649 bool RenderFrameHostImpl::IsRenderFrameLive() {
650 bool is_live
= GetProcess()->HasConnection() && render_frame_created_
;
652 // Sanity check: the RenderView should always be live if the RenderFrame is.
653 DCHECK_IMPLIES(is_live
, render_view_host_
->IsRenderViewLive());
658 void RenderFrameHostImpl::SetRenderFrameCreated(bool created
) {
659 bool was_created
= render_frame_created_
;
660 render_frame_created_
= created
;
662 // If the current status is different than the new status, the delegate
663 // needs to be notified.
664 if (delegate_
&& (created
!= was_created
)) {
666 delegate_
->RenderFrameCreated(this);
668 delegate_
->RenderFrameDeleted(this);
671 if (created
&& render_widget_host_
)
672 render_widget_host_
->InitForFrame();
675 void RenderFrameHostImpl::Init() {
676 GetProcess()->ResumeRequestsForView(routing_id_
);
679 void RenderFrameHostImpl::OnAddMessageToConsole(
681 const base::string16
& message
,
683 const base::string16
& source_id
) {
684 if (delegate_
->AddMessageToConsole(level
, message
, line_no
, source_id
))
687 // Pass through log level only on WebUI pages to limit console spew.
688 const bool is_web_ui
=
689 HasWebUIScheme(delegate_
->GetMainFrameLastCommittedURL());
690 const int32 resolved_level
= is_web_ui
? level
: ::logging::LOG_INFO
;
692 // LogMessages can be persisted so this shouldn't be logged in incognito mode.
693 // This rule is not applied to WebUI pages, because source code of WebUI is a
694 // part of Chrome source code, and we want to treat messages from WebUI the
695 // same way as we treat log messages from native code.
696 if (::logging::GetMinLogLevel() <= resolved_level
&&
698 !GetSiteInstance()->GetBrowserContext()->IsOffTheRecord())) {
699 logging::LogMessage("CONSOLE", line_no
, resolved_level
).stream()
700 << "\"" << message
<< "\", source: " << source_id
<< " (" << line_no
705 void RenderFrameHostImpl::OnCreateChildFrame(
707 blink::WebTreeScopeType scope
,
708 const std::string
& frame_name
,
709 blink::WebSandboxFlags sandbox_flags
) {
710 // It is possible that while a new RenderFrameHost was committed, the
711 // RenderFrame corresponding to this host sent an IPC message to create a
712 // frame and it is delivered after this host is swapped out.
713 // Ignore such messages, as we know this RenderFrameHost is going away.
714 if (rfh_state_
!= RenderFrameHostImpl::STATE_DEFAULT
)
717 RenderFrameHostImpl
* new_frame
=
718 frame_tree_
->AddFrame(frame_tree_node_
, GetProcess()->GetID(),
719 new_routing_id
, scope
, frame_name
, sandbox_flags
);
723 // We know that the RenderFrame has been created in this case, immediately
724 // after the CreateChildFrame IPC was sent.
725 new_frame
->SetRenderFrameCreated(true);
728 void RenderFrameHostImpl::OnDetach() {
729 frame_tree_
->RemoveFrame(frame_tree_node_
);
732 void RenderFrameHostImpl::OnFrameFocused() {
733 frame_tree_
->SetFocusedFrame(frame_tree_node_
);
736 void RenderFrameHostImpl::OnOpenURL(const FrameHostMsg_OpenURL_Params
& params
) {
737 OpenURL(params
, GetSiteInstance());
740 void RenderFrameHostImpl::OnDocumentOnLoadCompleted(
741 FrameMsg_UILoadMetricsReportType::Value report_type
,
742 base::TimeTicks ui_timestamp
) {
743 if (report_type
== FrameMsg_UILoadMetricsReportType::REPORT_LINK
) {
744 UMA_HISTOGRAM_CUSTOM_TIMES("Navigation.UI_OnLoadComplete.Link",
745 base::TimeTicks::Now() - ui_timestamp
,
746 base::TimeDelta::FromMilliseconds(10),
747 base::TimeDelta::FromMinutes(10), 100);
748 } else if (report_type
== FrameMsg_UILoadMetricsReportType::REPORT_INTENT
) {
749 UMA_HISTOGRAM_CUSTOM_TIMES("Navigation.UI_OnLoadComplete.Intent",
750 base::TimeTicks::Now() - ui_timestamp
,
751 base::TimeDelta::FromMilliseconds(10),
752 base::TimeDelta::FromMinutes(10), 100);
754 // This message is only sent for top-level frames. TODO(avi): when frame tree
755 // mirroring works correctly, add a check here to enforce it.
756 delegate_
->DocumentOnLoadCompleted(this);
759 void RenderFrameHostImpl::OnDidStartProvisionalLoadForFrame(const GURL
& url
) {
760 frame_tree_node_
->navigator()->DidStartProvisionalLoad(
764 void RenderFrameHostImpl::OnDidFailProvisionalLoadWithError(
765 const FrameHostMsg_DidFailProvisionalLoadWithError_Params
& params
) {
766 frame_tree_node_
->navigator()->DidFailProvisionalLoadWithError(this, params
);
769 void RenderFrameHostImpl::OnDidFailLoadWithError(
772 const base::string16
& error_description
) {
773 GURL
validated_url(url
);
774 GetProcess()->FilterURL(false, &validated_url
);
776 frame_tree_node_
->navigator()->DidFailLoadWithError(
777 this, validated_url
, error_code
, error_description
);
780 // Called when the renderer navigates. For every frame loaded, we'll get this
781 // notification containing parameters identifying the navigation.
783 // Subframes are identified by the page transition type. For subframes loaded
784 // as part of a wider page load, the page_id will be the same as for the top
785 // level frame. If the user explicitly requests a subframe navigation, we will
786 // get a new page_id because we need to create a new navigation entry for that
788 void RenderFrameHostImpl::OnDidCommitProvisionalLoad(const IPC::Message
& msg
) {
789 // Read the parameters out of the IPC message directly to avoid making another
790 // copy when we filter the URLs.
791 base::PickleIterator
iter(msg
);
792 FrameHostMsg_DidCommitProvisionalLoad_Params validated_params
;
793 if (!IPC::ParamTraits
<FrameHostMsg_DidCommitProvisionalLoad_Params
>::
794 Read(&msg
, &iter
, &validated_params
))
796 TRACE_EVENT1("navigation", "RenderFrameHostImpl::OnDidCommitProvisionalLoad",
797 "url", validated_params
.url
.possibly_invalid_spec());
799 // Sanity-check the page transition for frame type.
800 DCHECK_EQ(ui::PageTransitionIsMainFrame(validated_params
.transition
),
803 // If we're waiting for a cross-site beforeunload ack from this renderer and
804 // we receive a Navigate message from the main frame, then the renderer was
805 // navigating already and sent it before hearing the FrameMsg_Stop message.
806 // We do not want to cancel the pending navigation in this case, since the
807 // old page will soon be stopped. Instead, treat this as a beforeunload ack
808 // to allow the pending navigation to continue.
809 if (is_waiting_for_beforeunload_ack_
&&
810 unload_ack_is_for_navigation_
&&
812 base::TimeTicks approx_renderer_start_time
= send_before_unload_start_time_
;
813 OnBeforeUnloadACK(true, approx_renderer_start_time
, base::TimeTicks::Now());
817 // If we're waiting for an unload ack from this renderer and we receive a
818 // Navigate message, then the renderer was navigating before it received the
819 // unload request. It will either respond to the unload request soon or our
820 // timer will expire. Either way, we should ignore this message, because we
821 // have already committed to closing this renderer.
822 if (IsWaitingForUnloadACK())
825 if (validated_params
.report_type
==
826 FrameMsg_UILoadMetricsReportType::REPORT_LINK
) {
827 UMA_HISTOGRAM_CUSTOM_TIMES(
828 "Navigation.UI_OnCommitProvisionalLoad.Link",
829 base::TimeTicks::Now() - validated_params
.ui_timestamp
,
830 base::TimeDelta::FromMilliseconds(10), base::TimeDelta::FromMinutes(10),
832 } else if (validated_params
.report_type
==
833 FrameMsg_UILoadMetricsReportType::REPORT_INTENT
) {
834 UMA_HISTOGRAM_CUSTOM_TIMES(
835 "Navigation.UI_OnCommitProvisionalLoad.Intent",
836 base::TimeTicks::Now() - validated_params
.ui_timestamp
,
837 base::TimeDelta::FromMilliseconds(10), base::TimeDelta::FromMinutes(10),
841 RenderProcessHost
* process
= GetProcess();
843 // Attempts to commit certain off-limits URL should be caught more strictly
844 // than our FilterURL checks below. If a renderer violates this policy, it
846 if (!CanCommitURL(validated_params
.url
)) {
847 VLOG(1) << "Blocked URL " << validated_params
.url
.spec();
848 validated_params
.url
= GURL(url::kAboutBlankURL
);
849 // Kills the process.
850 bad_message::ReceivedBadMessage(process
,
851 bad_message::RFH_CAN_COMMIT_URL_BLOCKED
);
854 // Without this check, an evil renderer can trick the browser into creating
855 // a navigation entry for a banned URL. If the user clicks the back button
856 // followed by the forward button (or clicks reload, or round-trips through
857 // session restore, etc), we'll think that the browser commanded the
858 // renderer to load the URL and grant the renderer the privileges to request
859 // the URL. To prevent this attack, we block the renderer from inserting
860 // banned URLs into the navigation controller in the first place.
861 process
->FilterURL(false, &validated_params
.url
);
862 process
->FilterURL(true, &validated_params
.referrer
.url
);
863 for (std::vector
<GURL
>::iterator
it(validated_params
.redirects
.begin());
864 it
!= validated_params
.redirects
.end(); ++it
) {
865 process
->FilterURL(false, &(*it
));
867 process
->FilterURL(true, &validated_params
.searchable_form_url
);
869 // Without this check, the renderer can trick the browser into using
870 // filenames it can't access in a future session restore.
871 if (!render_view_host_
->CanAccessFilesOfPageState(
872 validated_params
.page_state
)) {
873 bad_message::ReceivedBadMessage(
874 GetProcess(), bad_message::RFH_CAN_ACCESS_FILES_OF_PAGE_STATE
);
878 accessibility_reset_count_
= 0;
879 frame_tree_node()->navigator()->DidNavigate(this, validated_params
);
882 if (base::CommandLine::ForCurrentProcess()->HasSwitch(
883 switches::kEnableBrowserSideNavigation
)) {
884 pending_commit_
= false;
888 void RenderFrameHostImpl::OnDidDropNavigation() {
889 // At the end of Navigate(), the FrameTreeNode's DidStartLoading is called to
890 // force the spinner to start, even if the renderer didn't yet begin the load.
891 // If it turns out that the renderer dropped the navigation, the spinner needs
893 frame_tree_node_
->DidStopLoading();
896 RenderWidgetHostImpl
* RenderFrameHostImpl::GetRenderWidgetHost() {
897 if (render_widget_host_
)
898 return render_widget_host_
;
900 // TODO(kenrb): When RenderViewHost no longer inherits RenderWidgetHost,
901 // we can remove this fallback. Currently it is only used for the main
904 return static_cast<RenderWidgetHostImpl
*>(render_view_host_
);
909 RenderWidgetHostView
* RenderFrameHostImpl::GetView() {
910 RenderFrameHostImpl
* frame
= this;
912 if (frame
->render_widget_host_
)
913 return frame
->render_widget_host_
->GetView();
914 frame
= static_cast<RenderFrameHostImpl
*>(frame
->GetParent());
917 return render_view_host_
->GetView();
920 int RenderFrameHostImpl::GetEnabledBindings() {
921 return render_view_host_
->GetEnabledBindings();
924 void RenderFrameHostImpl::OnCrossSiteResponse(
925 const GlobalRequestID
& global_request_id
,
926 scoped_ptr
<CrossSiteTransferringRequest
> cross_site_transferring_request
,
927 const std::vector
<GURL
>& transfer_url_chain
,
928 const Referrer
& referrer
,
929 ui::PageTransition page_transition
,
930 bool should_replace_current_entry
) {
931 frame_tree_node_
->render_manager()->OnCrossSiteResponse(
932 this, global_request_id
, cross_site_transferring_request
.Pass(),
933 transfer_url_chain
, referrer
, page_transition
,
934 should_replace_current_entry
);
937 void RenderFrameHostImpl::SwapOut(
938 RenderFrameProxyHost
* proxy
,
940 // The end of this event is in OnSwapOutACK when the RenderFrame has completed
941 // the operation and sends back an IPC message.
942 // The trace event may not end properly if the ACK times out. We expect this
943 // to be fixed when RenderViewHostImpl::OnSwapOut moves to RenderFrameHost.
944 TRACE_EVENT_ASYNC_BEGIN0("navigation", "RenderFrameHostImpl::SwapOut", this);
946 // If this RenderFrameHost is not in the default state, it must have already
947 // gone through this, therefore just return.
948 if (rfh_state_
!= RenderFrameHostImpl::STATE_DEFAULT
) {
949 NOTREACHED() << "RFH should be in default state when calling SwapOut.";
953 SetState(RenderFrameHostImpl::STATE_PENDING_SWAP_OUT
);
954 swapout_event_monitor_timeout_
->Start(
955 base::TimeDelta::FromMilliseconds(RenderViewHostImpl::kUnloadTimeoutMS
));
957 // There may be no proxy if there are no active views in the process.
958 int proxy_routing_id
= MSG_ROUTING_NONE
;
959 FrameReplicationState replication_state
;
961 set_render_frame_proxy_host(proxy
);
962 proxy_routing_id
= proxy
->GetRoutingID();
963 replication_state
= proxy
->frame_tree_node()->current_replication_state();
966 if (IsRenderFrameLive()) {
967 Send(new FrameMsg_SwapOut(routing_id_
, proxy_routing_id
, is_loading
,
972 delegate_
->SwappedOut(this);
975 void RenderFrameHostImpl::OnBeforeUnloadACK(
977 const base::TimeTicks
& renderer_before_unload_start_time
,
978 const base::TimeTicks
& renderer_before_unload_end_time
) {
979 TRACE_EVENT_ASYNC_END0(
980 "navigation", "RenderFrameHostImpl::BeforeUnload", this);
981 DCHECK(!GetParent());
982 // If this renderer navigated while the beforeunload request was in flight, we
983 // may have cleared this state in OnDidCommitProvisionalLoad, in which case we
984 // can ignore this message.
985 // However renderer might also be swapped out but we still want to proceed
986 // with navigation, otherwise it would block future navigations. This can
987 // happen when pending cross-site navigation is canceled by a second one just
988 // before OnDidCommitProvisionalLoad while current RVH is waiting for commit
989 // but second navigation is started from the beginning.
990 if (!is_waiting_for_beforeunload_ack_
) {
993 DCHECK(!send_before_unload_start_time_
.is_null());
995 // Sets a default value for before_unload_end_time so that the browser
996 // survives a hacked renderer.
997 base::TimeTicks before_unload_end_time
= renderer_before_unload_end_time
;
998 if (!renderer_before_unload_start_time
.is_null() &&
999 !renderer_before_unload_end_time
.is_null()) {
1000 // When passing TimeTicks across process boundaries, we need to compensate
1001 // for any skew between the processes. Here we are converting the
1002 // renderer's notion of before_unload_end_time to TimeTicks in the browser
1003 // process. See comments in inter_process_time_ticks_converter.h for more.
1004 base::TimeTicks receive_before_unload_ack_time
= base::TimeTicks::Now();
1005 InterProcessTimeTicksConverter
converter(
1006 LocalTimeTicks::FromTimeTicks(send_before_unload_start_time_
),
1007 LocalTimeTicks::FromTimeTicks(receive_before_unload_ack_time
),
1008 RemoteTimeTicks::FromTimeTicks(renderer_before_unload_start_time
),
1009 RemoteTimeTicks::FromTimeTicks(renderer_before_unload_end_time
));
1010 LocalTimeTicks browser_before_unload_end_time
=
1011 converter
.ToLocalTimeTicks(
1012 RemoteTimeTicks::FromTimeTicks(renderer_before_unload_end_time
));
1013 before_unload_end_time
= browser_before_unload_end_time
.ToTimeTicks();
1015 // Collect UMA on the inter-process skew.
1016 bool is_skew_additive
= false;
1017 if (converter
.IsSkewAdditiveForMetrics()) {
1018 is_skew_additive
= true;
1019 base::TimeDelta skew
= converter
.GetSkewForMetrics();
1020 if (skew
>= base::TimeDelta()) {
1021 UMA_HISTOGRAM_TIMES(
1022 "InterProcessTimeTicks.BrowserBehind_RendererToBrowser", skew
);
1024 UMA_HISTOGRAM_TIMES(
1025 "InterProcessTimeTicks.BrowserAhead_RendererToBrowser", -skew
);
1028 UMA_HISTOGRAM_BOOLEAN(
1029 "InterProcessTimeTicks.IsSkewAdditive_RendererToBrowser",
1032 base::TimeDelta on_before_unload_overhead_time
=
1033 (receive_before_unload_ack_time
- send_before_unload_start_time_
) -
1034 (renderer_before_unload_end_time
- renderer_before_unload_start_time
);
1035 UMA_HISTOGRAM_TIMES("Navigation.OnBeforeUnloadOverheadTime",
1036 on_before_unload_overhead_time
);
1038 frame_tree_node_
->navigator()->LogBeforeUnloadTime(
1039 renderer_before_unload_start_time
, renderer_before_unload_end_time
);
1041 // Resets beforeunload waiting state.
1042 is_waiting_for_beforeunload_ack_
= false;
1043 render_view_host_
->decrement_in_flight_event_count();
1044 render_view_host_
->StopHangMonitorTimeout();
1045 send_before_unload_start_time_
= base::TimeTicks();
1047 if (base::CommandLine::ForCurrentProcess()->HasSwitch(
1048 switches::kEnableBrowserSideNavigation
)) {
1049 // TODO(clamy): see if before_unload_end_time should be transmitted to the
1051 frame_tree_node_
->navigator()->OnBeforeUnloadACK(
1052 frame_tree_node_
, proceed
);
1054 frame_tree_node_
->render_manager()->OnBeforeUnloadACK(
1055 unload_ack_is_for_navigation_
, proceed
,
1056 before_unload_end_time
);
1059 // If canceled, notify the delegate to cancel its pending navigation entry.
1061 render_view_host_
->GetDelegate()->DidCancelLoading();
1064 bool RenderFrameHostImpl::IsWaitingForBeforeUnloadACK() const {
1065 if (!base::CommandLine::ForCurrentProcess()->HasSwitch(
1066 switches::kEnableBrowserSideNavigation
)) {
1067 return is_waiting_for_beforeunload_ack_
;
1069 return frame_tree_node_
->navigator()->IsWaitingForBeforeUnloadACK(
1073 bool RenderFrameHostImpl::IsWaitingForUnloadACK() const {
1074 return render_view_host_
->is_waiting_for_close_ack_
||
1075 rfh_state_
== STATE_PENDING_SWAP_OUT
;
1078 void RenderFrameHostImpl::OnSwapOutACK() {
1082 void RenderFrameHostImpl::OnRenderProcessGone(int status
, int exit_code
) {
1083 if (frame_tree_node_
->IsMainFrame()) {
1084 // Keep the termination status so we can get at it later when we
1085 // need to know why it died.
1086 render_view_host_
->render_view_termination_status_
=
1087 static_cast<base::TerminationStatus
>(status
);
1090 // Reset frame tree state associated with this process. This must happen
1091 // before RenderViewTerminated because observers expect the subframes of any
1092 // affected frames to be cleared first.
1093 // Note: When a RenderFrameHost is swapped out there is a different one
1094 // which is the current host. In this case, the FrameTreeNode state must
1096 if (!is_swapped_out())
1097 frame_tree_node_
->ResetForNewProcess();
1099 // Reset state for the current RenderFrameHost once the FrameTreeNode has been
1101 SetRenderFrameCreated(false);
1102 InvalidateMojoConnection();
1104 // Execute any pending AX tree snapshot callbacks with an empty response,
1105 // since we're never going to get a response from this renderer.
1106 for (const auto& iter
: ax_tree_snapshot_callbacks_
)
1107 iter
.second
.Run(ui::AXTreeUpdate());
1108 ax_tree_snapshot_callbacks_
.clear();
1110 // Note: don't add any more code at this point in the function because
1111 // |this| may be deleted. Any additional cleanup should happen before
1112 // the last block of code here.
1115 void RenderFrameHostImpl::OnSwappedOut() {
1116 // Ignore spurious swap out ack.
1117 if (rfh_state_
!= STATE_PENDING_SWAP_OUT
)
1120 TRACE_EVENT_ASYNC_END0("navigation", "RenderFrameHostImpl::SwapOut", this);
1121 swapout_event_monitor_timeout_
->Stop();
1123 if (frame_tree_node_
->render_manager()->DeleteFromPendingList(this)) {
1124 // We are now deleted.
1128 // If this RFH wasn't pending deletion, then it is now swapped out.
1129 SetState(RenderFrameHostImpl::STATE_SWAPPED_OUT
);
1132 void RenderFrameHostImpl::OnContextMenu(const ContextMenuParams
& params
) {
1133 // Validate the URLs in |params|. If the renderer can't request the URLs
1134 // directly, don't show them in the context menu.
1135 ContextMenuParams
validated_params(params
);
1136 RenderProcessHost
* process
= GetProcess();
1138 // We don't validate |unfiltered_link_url| so that this field can be used
1139 // when users want to copy the original link URL.
1140 process
->FilterURL(true, &validated_params
.link_url
);
1141 process
->FilterURL(true, &validated_params
.src_url
);
1142 process
->FilterURL(false, &validated_params
.page_url
);
1143 process
->FilterURL(true, &validated_params
.frame_url
);
1145 delegate_
->ShowContextMenu(this, validated_params
);
1148 void RenderFrameHostImpl::OnJavaScriptExecuteResponse(
1149 int id
, const base::ListValue
& result
) {
1150 const base::Value
* result_value
;
1151 if (!result
.Get(0, &result_value
)) {
1152 // Programming error or rogue renderer.
1153 NOTREACHED() << "Got bad arguments for OnJavaScriptExecuteResponse";
1157 std::map
<int, JavaScriptResultCallback
>::iterator it
=
1158 javascript_callbacks_
.find(id
);
1159 if (it
!= javascript_callbacks_
.end()) {
1160 it
->second
.Run(result_value
);
1161 javascript_callbacks_
.erase(it
);
1163 NOTREACHED() << "Received script response for unknown request";
1167 void RenderFrameHostImpl::OnVisualStateResponse(uint64 id
) {
1168 auto it
= visual_state_callbacks_
.find(id
);
1169 if (it
!= visual_state_callbacks_
.end()) {
1170 it
->second
.Run(true);
1171 visual_state_callbacks_
.erase(it
);
1173 NOTREACHED() << "Received script response for unknown request";
1177 void RenderFrameHostImpl::OnRunJavaScriptMessage(
1178 const base::string16
& message
,
1179 const base::string16
& default_prompt
,
1180 const GURL
& frame_url
,
1181 JavaScriptMessageType type
,
1182 IPC::Message
* reply_msg
) {
1183 // While a JS message dialog is showing, tabs in the same process shouldn't
1184 // process input events.
1185 GetProcess()->SetIgnoreInputEvents(true);
1186 render_view_host_
->StopHangMonitorTimeout();
1187 delegate_
->RunJavaScriptMessage(this, message
, default_prompt
,
1188 frame_url
, type
, reply_msg
);
1191 void RenderFrameHostImpl::OnRunBeforeUnloadConfirm(
1192 const GURL
& frame_url
,
1193 const base::string16
& message
,
1195 IPC::Message
* reply_msg
) {
1196 // While a JS beforeunload dialog is showing, tabs in the same process
1197 // shouldn't process input events.
1198 GetProcess()->SetIgnoreInputEvents(true);
1199 render_view_host_
->StopHangMonitorTimeout();
1200 delegate_
->RunBeforeUnloadConfirm(this, message
, is_reload
, reply_msg
);
1203 void RenderFrameHostImpl::OnTextSurroundingSelectionResponse(
1204 const base::string16
& content
,
1205 size_t start_offset
,
1206 size_t end_offset
) {
1207 render_view_host_
->OnTextSurroundingSelectionResponse(
1208 content
, start_offset
, end_offset
);
1211 void RenderFrameHostImpl::OnDidAccessInitialDocument() {
1212 delegate_
->DidAccessInitialDocument();
1215 void RenderFrameHostImpl::OnDidDisownOpener() {
1216 // This message is only sent for top-level frames for now.
1217 // TODO(alexmos): This should eventually support subframe openers as well,
1218 // and it should allow openers to be updated to another frame (which can
1219 // happen via window.open('','framename')) in addition to being disowned.
1221 // No action is necessary if the opener has already been cleared.
1222 if (!frame_tree_node_
->opener())
1225 // Clear our opener so that future cross-process navigations don't have an
1227 frame_tree_node_
->SetOpener(nullptr);
1229 // Notify all other RenderFrameHosts and RenderFrameProxies for this frame.
1230 // This is important in case we go back to them, or if another window in
1231 // those processes tries to access window.opener.
1232 frame_tree_node_
->render_manager()->DidDisownOpener(this);
1235 void RenderFrameHostImpl::OnDidChangeName(const std::string
& name
) {
1236 frame_tree_node()->SetFrameName(name
);
1237 delegate_
->DidChangeName(this, name
);
1240 void RenderFrameHostImpl::OnDidAssignPageId(int32 page_id
) {
1241 // Update the RVH's current page ID so that future IPCs from the renderer
1242 // correspond to the new page.
1243 render_view_host_
->page_id_
= page_id
;
1246 void RenderFrameHostImpl::OnDidChangeSandboxFlags(
1247 int32 frame_routing_id
,
1248 blink::WebSandboxFlags flags
) {
1249 FrameTree
* frame_tree
= frame_tree_node()->frame_tree();
1250 FrameTreeNode
* child
=
1251 frame_tree
->FindByRoutingID(GetProcess()->GetID(), frame_routing_id
);
1255 // Ensure that a frame can only update sandbox flags for its immediate
1256 // children. If this is not the case, the renderer is considered malicious
1258 if (child
->parent() != frame_tree_node()) {
1259 bad_message::ReceivedBadMessage(GetProcess(),
1260 bad_message::RFH_SANDBOX_FLAGS
);
1264 child
->set_sandbox_flags(flags
);
1266 // Notify the RenderFrame if it lives in a different process from its
1267 // parent. The frame's proxies in other processes also need to learn about
1268 // the updated sandbox flags, but these notifications are sent later in
1269 // RenderFrameHostManager::CommitPendingSandboxFlags(), when the frame
1270 // navigates and the new sandbox flags take effect.
1271 RenderFrameHost
* child_rfh
= child
->current_frame_host();
1272 if (child_rfh
->GetSiteInstance() != GetSiteInstance()) {
1274 new FrameMsg_DidUpdateSandboxFlags(child_rfh
->GetRoutingID(), flags
));
1278 void RenderFrameHostImpl::OnUpdateTitle(
1279 const base::string16
& title
,
1280 blink::WebTextDirection title_direction
) {
1281 // This message is only sent for top-level frames. TODO(avi): when frame tree
1282 // mirroring works correctly, add a check here to enforce it.
1283 if (title
.length() > kMaxTitleChars
) {
1284 NOTREACHED() << "Renderer sent too many characters in title.";
1288 delegate_
->UpdateTitle(this, render_view_host_
->page_id_
, title
,
1289 WebTextDirectionToChromeTextDirection(
1293 void RenderFrameHostImpl::OnUpdateEncoding(const std::string
& encoding_name
) {
1294 // This message is only sent for top-level frames. TODO(avi): when frame tree
1295 // mirroring works correctly, add a check here to enforce it.
1296 delegate_
->UpdateEncoding(this, encoding_name
);
1299 void RenderFrameHostImpl::OnBeginNavigation(
1300 const CommonNavigationParams
& common_params
,
1301 const BeginNavigationParams
& begin_params
,
1302 scoped_refptr
<ResourceRequestBody
> body
) {
1303 CHECK(base::CommandLine::ForCurrentProcess()->HasSwitch(
1304 switches::kEnableBrowserSideNavigation
));
1305 frame_tree_node()->navigator()->OnBeginNavigation(
1306 frame_tree_node(), common_params
, begin_params
, body
);
1309 void RenderFrameHostImpl::OnDispatchLoad() {
1310 CHECK(base::CommandLine::ForCurrentProcess()->HasSwitch(
1311 switches::kSitePerProcess
));
1312 // Only frames with an out-of-process parent frame should be sending this
1314 RenderFrameProxyHost
* proxy
=
1315 frame_tree_node()->render_manager()->GetProxyToParent();
1317 bad_message::ReceivedBadMessage(GetProcess(),
1318 bad_message::RFH_NO_PROXY_TO_PARENT
);
1322 proxy
->Send(new FrameMsg_DispatchLoad(proxy
->GetRoutingID()));
1325 void RenderFrameHostImpl::OnAccessibilityEvents(
1326 const std::vector
<AccessibilityHostMsg_EventParams
>& params
,
1328 // Don't process this IPC if either we're waiting on a reset and this
1329 // IPC doesn't have the matching token ID, or if we're not waiting on a
1330 // reset but this message includes a reset token.
1331 if (accessibility_reset_token_
!= reset_token
) {
1332 Send(new AccessibilityMsg_Events_ACK(routing_id_
));
1335 accessibility_reset_token_
= 0;
1337 RenderWidgetHostViewBase
* view
= static_cast<RenderWidgetHostViewBase
*>(
1338 render_view_host_
->GetView());
1340 AccessibilityMode accessibility_mode
= delegate_
->GetAccessibilityMode();
1341 if ((accessibility_mode
!= AccessibilityModeOff
) && view
&&
1342 RenderFrameHostImpl::IsRFHStateActive(rfh_state())) {
1343 if (accessibility_mode
& AccessibilityModeFlagPlatform
) {
1344 GetOrCreateBrowserAccessibilityManager();
1345 if (browser_accessibility_manager_
)
1346 browser_accessibility_manager_
->OnAccessibilityEvents(params
);
1349 if (browser_accessibility_manager_
) {
1350 // Get the frame routing ids from out-of-process iframes and
1351 // browser plugin instance ids from guests and update the mappings in
1352 // FrameAccessibility.
1353 for (size_t i
= 0; i
< params
.size(); ++i
) {
1354 const AccessibilityHostMsg_EventParams
& param
= params
[i
];
1355 UpdateCrossProcessIframeAccessibility(
1356 param
.node_to_frame_routing_id_map
);
1357 UpdateGuestFrameAccessibility(
1358 param
.node_to_browser_plugin_instance_id_map
);
1362 // Send the updates to the automation extension API.
1363 std::vector
<AXEventNotificationDetails
> details
;
1364 details
.reserve(params
.size());
1365 for (size_t i
= 0; i
< params
.size(); ++i
) {
1366 const AccessibilityHostMsg_EventParams
& param
= params
[i
];
1367 AXEventNotificationDetails
detail(param
.update
.node_id_to_clear
,
1371 GetProcess()->GetID(),
1373 details
.push_back(detail
);
1376 delegate_
->AccessibilityEventReceived(details
);
1379 // Always send an ACK or the renderer can be in a bad state.
1380 Send(new AccessibilityMsg_Events_ACK(routing_id_
));
1382 // The rest of this code is just for testing; bail out if we're not
1384 if (accessibility_testing_callback_
.is_null())
1387 for (size_t i
= 0; i
< params
.size(); i
++) {
1388 const AccessibilityHostMsg_EventParams
& param
= params
[i
];
1389 if (static_cast<int>(param
.event_type
) < 0)
1392 if (!ax_tree_for_testing_
) {
1393 if (browser_accessibility_manager_
) {
1394 ax_tree_for_testing_
.reset(new ui::AXTree(
1395 browser_accessibility_manager_
->SnapshotAXTreeForTesting()));
1397 ax_tree_for_testing_
.reset(new ui::AXTree());
1398 CHECK(ax_tree_for_testing_
->Unserialize(param
.update
))
1399 << ax_tree_for_testing_
->error();
1402 CHECK(ax_tree_for_testing_
->Unserialize(param
.update
))
1403 << ax_tree_for_testing_
->error();
1405 accessibility_testing_callback_
.Run(param
.event_type
, param
.id
);
1409 void RenderFrameHostImpl::OnAccessibilityLocationChanges(
1410 const std::vector
<AccessibilityHostMsg_LocationChangeParams
>& params
) {
1411 if (accessibility_reset_token_
)
1414 RenderWidgetHostViewBase
* view
= static_cast<RenderWidgetHostViewBase
*>(
1415 render_view_host_
->GetView());
1416 if (view
&& RenderFrameHostImpl::IsRFHStateActive(rfh_state())) {
1417 AccessibilityMode accessibility_mode
= delegate_
->GetAccessibilityMode();
1418 if (accessibility_mode
& AccessibilityModeFlagPlatform
) {
1419 BrowserAccessibilityManager
* manager
=
1420 GetOrCreateBrowserAccessibilityManager();
1422 manager
->OnLocationChanges(params
);
1424 // TODO(aboxhall): send location change events to web contents observers too
1428 void RenderFrameHostImpl::OnAccessibilityFindInPageResult(
1429 const AccessibilityHostMsg_FindInPageResultParams
& params
) {
1430 AccessibilityMode accessibility_mode
= delegate_
->GetAccessibilityMode();
1431 if (accessibility_mode
& AccessibilityModeFlagPlatform
) {
1432 BrowserAccessibilityManager
* manager
=
1433 GetOrCreateBrowserAccessibilityManager();
1435 manager
->OnFindInPageResult(
1436 params
.request_id
, params
.match_index
, params
.start_id
,
1437 params
.start_offset
, params
.end_id
, params
.end_offset
);
1442 void RenderFrameHostImpl::OnAccessibilitySnapshotResponse(
1444 const ui::AXTreeUpdate
& snapshot
) {
1445 const auto& it
= ax_tree_snapshot_callbacks_
.find(callback_id
);
1446 if (it
!= ax_tree_snapshot_callbacks_
.end()) {
1447 it
->second
.Run(snapshot
);
1448 ax_tree_snapshot_callbacks_
.erase(it
);
1450 NOTREACHED() << "Received AX tree snapshot response for unknown id";
1454 void RenderFrameHostImpl::OnToggleFullscreen(bool enter_fullscreen
) {
1455 if (enter_fullscreen
)
1456 delegate_
->EnterFullscreenMode(GetLastCommittedURL().GetOrigin());
1458 delegate_
->ExitFullscreenMode();
1460 // The previous call might change the fullscreen state. We need to make sure
1461 // the renderer is aware of that, which is done via the resize message.
1462 render_view_host_
->WasResized();
1465 void RenderFrameHostImpl::OnDidStartLoading(bool to_different_document
) {
1466 // Any main frame load to a new document should reset the load since it will
1467 // replace the current page and any frames.
1468 if (to_different_document
&& !GetParent())
1469 is_loading_
= false;
1471 // This method should never be called when the frame is loading.
1472 // Unfortunately, it can happen if a history navigation happens during a
1473 // BeforeUnload or Unload event.
1474 // TODO(fdegans): Change this to a DCHECK after LoadEventProgress has been
1475 // refactored in Blink. See crbug.com/466089
1477 LOG(WARNING
) << "OnDidStartLoading was called twice.";
1481 frame_tree_node_
->DidStartLoading(to_different_document
);
1485 void RenderFrameHostImpl::OnDidStopLoading() {
1486 // This method should never be called when the frame is not loading.
1487 // Unfortunately, it can happen if a history navigation happens during a
1488 // BeforeUnload or Unload event.
1489 // TODO(fdegans): Change this to a DCHECK after LoadEventProgress has been
1490 // refactored in Blink. See crbug.com/466089
1492 LOG(WARNING
) << "OnDidStopLoading was called twice.";
1496 is_loading_
= false;
1497 frame_tree_node_
->DidStopLoading();
1500 void RenderFrameHostImpl::OnDidChangeLoadProgress(double load_progress
) {
1501 frame_tree_node_
->DidChangeLoadProgress(load_progress
);
1504 #if defined(OS_MACOSX) || defined(OS_ANDROID)
1505 void RenderFrameHostImpl::OnShowPopup(
1506 const FrameHostMsg_ShowPopup_Params
& params
) {
1507 RenderViewHostDelegateView
* view
=
1508 render_view_host_
->delegate_
->GetDelegateView();
1510 view
->ShowPopupMenu(this,
1513 params
.item_font_size
,
1514 params
.selected_item
,
1516 params
.right_aligned
,
1517 params
.allow_multiple_selection
);
1521 void RenderFrameHostImpl::OnHidePopup() {
1522 RenderViewHostDelegateView
* view
=
1523 render_view_host_
->delegate_
->GetDelegateView();
1525 view
->HidePopupMenu();
1529 #if defined(ENABLE_MEDIA_MOJO_RENDERER)
1530 static void CreateMediaRendererService(
1531 mojo::InterfaceRequest
<mojo::MediaRenderer
> request
) {
1532 // The created object is owned by the pipe.
1533 new media::MojoRendererService(request
.Pass());
1537 void RenderFrameHostImpl::RegisterMojoServices() {
1538 GeolocationServiceContext
* geolocation_service_context
=
1539 delegate_
? delegate_
->GetGeolocationServiceContext() : NULL
;
1540 if (geolocation_service_context
) {
1541 // TODO(creis): Bind process ID here so that GeolocationServiceImpl
1542 // can perform permissions checks once site isolation is complete.
1544 GetServiceRegistry()->AddService
<GeolocationService
>(
1545 base::Bind(&GeolocationServiceContext::CreateService
,
1546 base::Unretained(geolocation_service_context
),
1547 base::Bind(&RenderFrameHostImpl::DidUseGeolocationPermission
,
1548 base::Unretained(this))));
1551 if (!permission_service_context_
)
1552 permission_service_context_
.reset(new PermissionServiceContext(this));
1554 GetServiceRegistry()->AddService
<PermissionService
>(
1555 base::Bind(&PermissionServiceContext::CreateService
,
1556 base::Unretained(permission_service_context_
.get())));
1558 GetServiceRegistry()->AddService
<presentation::PresentationService
>(
1559 base::Bind(&PresentationServiceImpl::CreateMojoService
,
1560 base::Unretained(this)));
1562 #if defined(ENABLE_MEDIA_MOJO_RENDERER)
1563 GetServiceRegistry()->AddService
<mojo::MediaRenderer
>(
1564 base::Bind(&CreateMediaRendererService
));
1567 if (!frame_mojo_shell_
)
1568 frame_mojo_shell_
.reset(new FrameMojoShell(this));
1570 GetServiceRegistry()->AddService
<mojo::Shell
>(base::Bind(
1571 &FrameMojoShell::BindRequest
, base::Unretained(frame_mojo_shell_
.get())));
1573 GetContentClient()->browser()->OverrideRenderFrameMojoServices(
1574 GetServiceRegistry(), this);
1577 void RenderFrameHostImpl::SetState(RenderFrameHostImplState rfh_state
) {
1578 // Only main frames should be swapped out and retained inside a proxy host.
1579 if (rfh_state
== STATE_SWAPPED_OUT
)
1580 CHECK(!GetParent());
1582 // We update the number of RenderFrameHosts in a SiteInstance when the swapped
1583 // out status of a RenderFrameHost gets flipped to/from active.
1584 if (!IsRFHStateActive(rfh_state_
) && IsRFHStateActive(rfh_state
))
1585 GetSiteInstance()->increment_active_frame_count();
1586 else if (IsRFHStateActive(rfh_state_
) && !IsRFHStateActive(rfh_state
))
1587 GetSiteInstance()->decrement_active_frame_count();
1589 // The active and swapped out state of the RVH is determined by its main
1590 // frame, since subframes should have their own widgets.
1591 if (frame_tree_node_
->IsMainFrame()) {
1592 render_view_host_
->set_is_active(IsRFHStateActive(rfh_state
));
1593 render_view_host_
->set_is_swapped_out(rfh_state
== STATE_SWAPPED_OUT
);
1596 // Whenever we change the RFH state to and from active or swapped out state,
1597 // we should not be waiting for beforeunload or close acks. We clear them
1598 // here to be safe, since they can cause navigations to be ignored in
1599 // OnDidCommitProvisionalLoad.
1600 // TODO(creis): Move is_waiting_for_beforeunload_ack_ into the state machine.
1601 if (rfh_state
== STATE_DEFAULT
||
1602 rfh_state
== STATE_SWAPPED_OUT
||
1603 rfh_state_
== STATE_DEFAULT
||
1604 rfh_state_
== STATE_SWAPPED_OUT
) {
1605 if (is_waiting_for_beforeunload_ack_
) {
1606 is_waiting_for_beforeunload_ack_
= false;
1607 render_view_host_
->decrement_in_flight_event_count();
1608 render_view_host_
->StopHangMonitorTimeout();
1610 send_before_unload_start_time_
= base::TimeTicks();
1611 render_view_host_
->is_waiting_for_close_ack_
= false;
1613 rfh_state_
= rfh_state
;
1616 bool RenderFrameHostImpl::CanCommitURL(const GURL
& url
) {
1617 // TODO(creis): We should also check for WebUI pages here. Also, when the
1618 // out-of-process iframes implementation is ready, we should check for
1619 // cross-site URLs that are not allowed to commit in this process.
1621 // Give the client a chance to disallow URLs from committing.
1622 return GetContentClient()->browser()->CanCommitURL(GetProcess(), url
);
1625 void RenderFrameHostImpl::Navigate(
1626 const CommonNavigationParams
& common_params
,
1627 const StartNavigationParams
& start_params
,
1628 const RequestNavigationParams
& request_params
) {
1629 TRACE_EVENT0("navigation", "RenderFrameHostImpl::Navigate");
1631 UpdatePermissionsForNavigation(common_params
, request_params
);
1633 // Only send the message if we aren't suspended at the start of a cross-site
1635 if (navigations_suspended_
) {
1636 // Shouldn't be possible to have a second navigation while suspended, since
1637 // navigations will only be suspended during a cross-site request. If a
1638 // second navigation occurs, RenderFrameHostManager will cancel this pending
1639 // RFH and create a new pending RFH.
1640 DCHECK(!suspended_nav_params_
.get());
1641 suspended_nav_params_
.reset(
1642 new NavigationParams(common_params
, start_params
, request_params
));
1644 // Get back to a clean state, in case we start a new navigation without
1645 // completing a RFH swap or unload handler.
1646 SetState(RenderFrameHostImpl::STATE_DEFAULT
);
1648 Send(new FrameMsg_Navigate(routing_id_
, common_params
, start_params
,
1652 // Force the throbber to start. This is done because Blink's "started loading"
1653 // message will be received asynchronously from the UI of the browser. But the
1654 // throbber needs to be kept in sync with what's happening in the UI. For
1655 // example, the throbber will start immediately when the user navigates even
1656 // if the renderer is delayed. There is also an issue with the throbber
1657 // starting because the WebUI (which controls whether the favicon is
1658 // displayed) happens synchronously. If the start loading messages was
1659 // asynchronous, then the default favicon would flash in.
1661 // Blink doesn't send throb notifications for JavaScript URLs, so it is not
1662 // done here either.
1663 if (!common_params
.url
.SchemeIs(url::kJavaScriptScheme
))
1664 frame_tree_node_
->DidStartLoading(true);
1667 void RenderFrameHostImpl::NavigateToURL(const GURL
& url
) {
1668 CommonNavigationParams
common_params(
1669 url
, Referrer(), ui::PAGE_TRANSITION_LINK
, FrameMsg_Navigate_Type::NORMAL
,
1670 true, base::TimeTicks::Now(), FrameMsg_UILoadMetricsReportType::NO_REPORT
,
1672 Navigate(common_params
, StartNavigationParams(), RequestNavigationParams());
1675 void RenderFrameHostImpl::OpenURL(const FrameHostMsg_OpenURL_Params
& params
,
1676 SiteInstance
* source_site_instance
) {
1677 GURL
validated_url(params
.url
);
1678 GetProcess()->FilterURL(false, &validated_url
);
1680 TRACE_EVENT1("navigation", "RenderFrameHostImpl::OpenURL", "url",
1681 validated_url
.possibly_invalid_spec());
1682 frame_tree_node_
->navigator()->RequestOpenURL(
1683 this, validated_url
, source_site_instance
, params
.referrer
,
1684 params
.disposition
, params
.should_replace_current_entry
,
1685 params
.user_gesture
);
1688 void RenderFrameHostImpl::Stop() {
1689 Send(new FrameMsg_Stop(routing_id_
));
1692 void RenderFrameHostImpl::DispatchBeforeUnload(bool for_navigation
) {
1693 // TODO(creis): Support beforeunload on subframes. For now just pretend that
1694 // the handler ran and allowed the navigation to proceed.
1695 if (GetParent() || !IsRenderFrameLive()) {
1696 // We don't have a live renderer, so just skip running beforeunload.
1697 if (base::CommandLine::ForCurrentProcess()->HasSwitch(
1698 switches::kEnableBrowserSideNavigation
)) {
1699 frame_tree_node_
->navigator()->OnBeforeUnloadACK(
1700 frame_tree_node_
, true);
1702 frame_tree_node_
->render_manager()->OnBeforeUnloadACK(
1703 for_navigation
, true, base::TimeTicks::Now());
1707 TRACE_EVENT_ASYNC_BEGIN0(
1708 "navigation", "RenderFrameHostImpl::BeforeUnload", this);
1710 // This may be called more than once (if the user clicks the tab close button
1711 // several times, or if she clicks the tab close button then the browser close
1712 // button), and we only send the message once.
1713 if (is_waiting_for_beforeunload_ack_
) {
1714 // Some of our close messages could be for the tab, others for cross-site
1715 // transitions. We always want to think it's for closing the tab if any
1716 // of the messages were, since otherwise it might be impossible to close
1717 // (if there was a cross-site "close" request pending when the user clicked
1718 // the close button). We want to keep the "for cross site" flag only if
1719 // both the old and the new ones are also for cross site.
1720 unload_ack_is_for_navigation_
=
1721 unload_ack_is_for_navigation_
&& for_navigation
;
1723 // Start the hang monitor in case the renderer hangs in the beforeunload
1725 is_waiting_for_beforeunload_ack_
= true;
1726 unload_ack_is_for_navigation_
= for_navigation
;
1727 // Increment the in-flight event count, to ensure that input events won't
1728 // cancel the timeout timer.
1729 render_view_host_
->increment_in_flight_event_count();
1730 render_view_host_
->StartHangMonitorTimeout(
1731 TimeDelta::FromMilliseconds(RenderViewHostImpl::kUnloadTimeoutMS
));
1732 send_before_unload_start_time_
= base::TimeTicks::Now();
1733 Send(new FrameMsg_BeforeUnload(routing_id_
));
1737 void RenderFrameHostImpl::DisownOpener() {
1738 Send(new FrameMsg_DisownOpener(GetRoutingID()));
1741 void RenderFrameHostImpl::ExtendSelectionAndDelete(size_t before
,
1743 Send(new InputMsg_ExtendSelectionAndDelete(routing_id_
, before
, after
));
1746 void RenderFrameHostImpl::JavaScriptDialogClosed(
1747 IPC::Message
* reply_msg
,
1749 const base::string16
& user_input
,
1750 bool dialog_was_suppressed
) {
1751 GetProcess()->SetIgnoreInputEvents(false);
1752 bool is_waiting
= is_waiting_for_beforeunload_ack_
|| IsWaitingForUnloadACK();
1754 // If we are executing as part of (before)unload event handling, we don't
1755 // want to use the regular hung_renderer_delay_ms_ if the user has agreed to
1756 // leave the current page. In this case, use the regular timeout value used
1757 // during the (before)unload handling.
1759 render_view_host_
->StartHangMonitorTimeout(
1761 ? TimeDelta::FromMilliseconds(RenderViewHostImpl::kUnloadTimeoutMS
)
1762 : render_view_host_
->hung_renderer_delay_
);
1765 FrameHostMsg_RunJavaScriptMessage::WriteReplyParams(reply_msg
,
1766 success
, user_input
);
1769 // If we are waiting for an unload or beforeunload ack and the user has
1770 // suppressed messages, kill the tab immediately; a page that's spamming
1771 // alerts in onbeforeunload is presumably malicious, so there's no point in
1772 // continuing to run its script and dragging out the process.
1773 // This must be done after sending the reply since RenderView can't close
1774 // correctly while waiting for a response.
1775 if (is_waiting
&& dialog_was_suppressed
)
1776 render_view_host_
->delegate_
->RendererUnresponsive(render_view_host_
);
1780 void RenderFrameHostImpl::CommitNavigation(
1781 ResourceResponse
* response
,
1782 scoped_ptr
<StreamHandle
> body
,
1783 const CommonNavigationParams
& common_params
,
1784 const RequestNavigationParams
& request_params
) {
1785 DCHECK((response
&& body
.get()) ||
1786 !NavigationRequest::ShouldMakeNetworkRequest(common_params
.url
));
1787 UpdatePermissionsForNavigation(common_params
, request_params
);
1789 // Get back to a clean state, in case we start a new navigation without
1790 // completing a RFH swap or unload handler.
1791 SetState(RenderFrameHostImpl::STATE_DEFAULT
);
1793 const GURL body_url
= body
.get() ? body
->GetURL() : GURL();
1794 const ResourceResponseHead head
= response
?
1795 response
->head
: ResourceResponseHead();
1796 Send(new FrameMsg_CommitNavigation(routing_id_
, head
, body_url
, common_params
,
1798 // TODO(clamy): Check if we should start the throbber for non javascript urls
1801 // TODO(clamy): Release the stream handle once the renderer has finished
1803 stream_handle_
= body
.Pass();
1804 pending_commit_
= true;
1807 void RenderFrameHostImpl::FailedNavigation(
1808 const CommonNavigationParams
& common_params
,
1809 const RequestNavigationParams
& request_params
,
1810 bool has_stale_copy_in_cache
,
1812 // Get back to a clean state, in case a new navigation started without
1813 // completing a RFH swap or unload handler.
1814 SetState(RenderFrameHostImpl::STATE_DEFAULT
);
1816 Send(new FrameMsg_FailedNavigation(routing_id_
, common_params
, request_params
,
1817 has_stale_copy_in_cache
, error_code
));
1820 void RenderFrameHostImpl::SetUpMojoIfNeeded() {
1821 if (service_registry_
.get())
1824 service_registry_
.reset(new ServiceRegistryImpl());
1825 if (!GetProcess()->GetServiceRegistry())
1828 RegisterMojoServices();
1829 RenderFrameSetupPtr setup
;
1830 GetProcess()->GetServiceRegistry()->ConnectToRemoteService(
1831 mojo::GetProxy(&setup
));
1833 mojo::ServiceProviderPtr exposed_services
;
1834 service_registry_
->Bind(GetProxy(&exposed_services
));
1836 mojo::ServiceProviderPtr services
;
1837 setup
->ExchangeServiceProviders(routing_id_
, GetProxy(&services
),
1838 exposed_services
.Pass());
1839 service_registry_
->BindRemoteServiceProvider(services
.Pass());
1841 #if defined(OS_ANDROID)
1842 service_registry_android_
.reset(
1843 new ServiceRegistryAndroid(service_registry_
.get()));
1844 ServiceRegistrarAndroid::RegisterFrameHostServices(
1845 service_registry_android_
.get());
1849 void RenderFrameHostImpl::InvalidateMojoConnection() {
1850 #if defined(OS_ANDROID)
1851 // The Android-specific service registry has a reference to
1852 // |service_registry_| and thus must be torn down first.
1853 service_registry_android_
.reset();
1856 service_registry_
.reset();
1859 bool RenderFrameHostImpl::IsFocused() {
1860 // TODO(mlamouri,kenrb): call GetRenderWidgetHost() directly when it stops
1861 // returning nullptr in some cases. See https://crbug.com/455245.
1862 return RenderWidgetHostImpl::From(
1863 GetView()->GetRenderWidgetHost())->is_focused() &&
1864 frame_tree_
->GetFocusedFrame() &&
1865 (frame_tree_
->GetFocusedFrame() == frame_tree_node() ||
1866 frame_tree_
->GetFocusedFrame()->IsDescendantOf(frame_tree_node()));
1869 void RenderFrameHostImpl::UpdateCrossProcessIframeAccessibility(
1870 const std::map
<int32
, int>& node_to_frame_routing_id_map
) {
1871 for (const auto& iter
: node_to_frame_routing_id_map
) {
1872 // This is the id of the accessibility node that has a child frame.
1873 int32 node_id
= iter
.first
;
1874 // The routing id from either a RenderFrame or a RenderFrameProxy.
1875 int frame_routing_id
= iter
.second
;
1877 FrameTree
* frame_tree
= frame_tree_node()->frame_tree();
1878 FrameTreeNode
* child_frame_tree_node
= frame_tree
->FindByRoutingID(
1879 GetProcess()->GetID(), frame_routing_id
);
1881 if (child_frame_tree_node
) {
1882 FrameAccessibility::GetInstance()->AddChildFrame(
1883 this, node_id
, child_frame_tree_node
->frame_tree_node_id());
1888 void RenderFrameHostImpl::UpdateGuestFrameAccessibility(
1889 const std::map
<int32
, int>& node_to_browser_plugin_instance_id_map
) {
1890 for (const auto& iter
: node_to_browser_plugin_instance_id_map
) {
1891 // This is the id of the accessibility node that hosts a plugin.
1892 int32 node_id
= iter
.first
;
1893 // The id of the browser plugin.
1894 int browser_plugin_instance_id
= iter
.second
;
1895 FrameAccessibility::GetInstance()->AddGuestWebContents(
1896 this, node_id
, browser_plugin_instance_id
);
1900 bool RenderFrameHostImpl::IsSameSiteInstance(
1901 RenderFrameHostImpl
* other_render_frame_host
) {
1902 // As a sanity check, make sure the frame belongs to the same BrowserContext.
1903 CHECK_EQ(GetSiteInstance()->GetBrowserContext(),
1904 other_render_frame_host
->GetSiteInstance()->GetBrowserContext());
1905 return GetSiteInstance() == other_render_frame_host
->GetSiteInstance();
1908 void RenderFrameHostImpl::SetAccessibilityMode(AccessibilityMode mode
) {
1909 Send(new FrameMsg_SetAccessibilityMode(routing_id_
, mode
));
1912 void RenderFrameHostImpl::RequestAXTreeSnapshot(
1913 AXTreeSnapshotCallback callback
) {
1914 static int next_id
= 1;
1915 int callback_id
= next_id
++;
1916 Send(new AccessibilityMsg_SnapshotTree(routing_id_
, callback_id
));
1917 ax_tree_snapshot_callbacks_
.insert(std::make_pair(callback_id
, callback
));
1920 void RenderFrameHostImpl::SetAccessibilityCallbackForTesting(
1921 const base::Callback
<void(ui::AXEvent
, int)>& callback
) {
1922 accessibility_testing_callback_
= callback
;
1925 void RenderFrameHostImpl::SetTextTrackSettings(
1926 const FrameMsg_TextTrackSettings_Params
& params
) {
1927 DCHECK(!GetParent());
1928 Send(new FrameMsg_SetTextTrackSettings(routing_id_
, params
));
1931 const ui::AXTree
* RenderFrameHostImpl::GetAXTreeForTesting() {
1932 return ax_tree_for_testing_
.get();
1935 BrowserAccessibilityManager
*
1936 RenderFrameHostImpl::GetOrCreateBrowserAccessibilityManager() {
1937 RenderWidgetHostViewBase
* view
= static_cast<RenderWidgetHostViewBase
*>(
1938 render_view_host_
->GetView());
1940 !browser_accessibility_manager_
&&
1941 !no_create_browser_accessibility_manager_for_testing_
) {
1942 browser_accessibility_manager_
.reset(
1943 view
->CreateBrowserAccessibilityManager(this));
1944 if (browser_accessibility_manager_
)
1945 UMA_HISTOGRAM_COUNTS("Accessibility.FrameEnabledCount", 1);
1947 UMA_HISTOGRAM_COUNTS("Accessibility.FrameDidNotEnableCount", 1);
1949 return browser_accessibility_manager_
.get();
1952 void RenderFrameHostImpl::ActivateFindInPageResultForAccessibility(
1954 AccessibilityMode accessibility_mode
= delegate_
->GetAccessibilityMode();
1955 if (accessibility_mode
& AccessibilityModeFlagPlatform
) {
1956 BrowserAccessibilityManager
* manager
=
1957 GetOrCreateBrowserAccessibilityManager();
1959 manager
->ActivateFindInPageResult(request_id
);
1963 void RenderFrameHostImpl::InsertVisualStateCallback(
1964 const VisualStateCallback
& callback
) {
1965 static uint64 next_id
= 1;
1966 uint64 key
= next_id
++;
1967 Send(new FrameMsg_VisualStateRequest(routing_id_
, key
));
1968 visual_state_callbacks_
.insert(std::make_pair(key
, callback
));
1973 void RenderFrameHostImpl::SetParentNativeViewAccessible(
1974 gfx::NativeViewAccessible accessible_parent
) {
1975 RenderWidgetHostViewBase
* view
= static_cast<RenderWidgetHostViewBase
*>(
1976 render_view_host_
->GetView());
1978 view
->SetParentNativeViewAccessible(accessible_parent
);
1981 gfx::NativeViewAccessible
1982 RenderFrameHostImpl::GetParentNativeViewAccessible() const {
1983 return delegate_
->GetParentNativeViewAccessible();
1986 #elif defined(OS_MACOSX)
1988 void RenderFrameHostImpl::DidSelectPopupMenuItem(int selected_index
) {
1989 Send(new FrameMsg_SelectPopupMenuItem(routing_id_
, selected_index
));
1992 void RenderFrameHostImpl::DidCancelPopupMenu() {
1993 Send(new FrameMsg_SelectPopupMenuItem(routing_id_
, -1));
1996 #elif defined(OS_ANDROID)
1998 void RenderFrameHostImpl::DidSelectPopupMenuItems(
1999 const std::vector
<int>& selected_indices
) {
2000 Send(new FrameMsg_SelectPopupMenuItems(routing_id_
, false, selected_indices
));
2003 void RenderFrameHostImpl::DidCancelPopupMenu() {
2004 Send(new FrameMsg_SelectPopupMenuItems(
2005 routing_id_
, true, std::vector
<int>()));
2010 void RenderFrameHostImpl::SetNavigationsSuspended(
2012 const base::TimeTicks
& proceed_time
) {
2013 // This should only be called to toggle the state.
2014 DCHECK(navigations_suspended_
!= suspend
);
2016 navigations_suspended_
= suspend
;
2017 if (navigations_suspended_
) {
2018 TRACE_EVENT_ASYNC_BEGIN0("navigation",
2019 "RenderFrameHostImpl navigation suspended", this);
2021 TRACE_EVENT_ASYNC_END0("navigation",
2022 "RenderFrameHostImpl navigation suspended", this);
2025 if (!suspend
&& suspended_nav_params_
) {
2026 // There's navigation message params waiting to be sent. Now that we're not
2027 // suspended anymore, resume navigation by sending them. If we were swapped
2028 // out, we should also stop filtering out the IPC messages now.
2029 SetState(RenderFrameHostImpl::STATE_DEFAULT
);
2031 DCHECK(!proceed_time
.is_null());
2032 suspended_nav_params_
->request_params
.browser_navigation_start
=
2034 Send(new FrameMsg_Navigate(routing_id_
,
2035 suspended_nav_params_
->common_params
,
2036 suspended_nav_params_
->start_params
,
2037 suspended_nav_params_
->request_params
));
2038 suspended_nav_params_
.reset();
2042 void RenderFrameHostImpl::CancelSuspendedNavigations() {
2043 // Clear any state if a pending navigation is canceled or preempted.
2044 if (suspended_nav_params_
)
2045 suspended_nav_params_
.reset();
2047 TRACE_EVENT_ASYNC_END0("navigation",
2048 "RenderFrameHostImpl navigation suspended", this);
2049 navigations_suspended_
= false;
2052 void RenderFrameHostImpl::DidUseGeolocationPermission() {
2053 PermissionManager
* permission_manager
=
2054 GetSiteInstance()->GetBrowserContext()->GetPermissionManager();
2055 if (!permission_manager
)
2058 permission_manager
->RegisterPermissionUsage(
2059 PermissionType::GEOLOCATION
,
2060 GetLastCommittedURL().GetOrigin(),
2061 frame_tree_node()->frame_tree()->GetMainFrame()
2062 ->GetLastCommittedURL().GetOrigin());
2065 void RenderFrameHostImpl::UpdatePermissionsForNavigation(
2066 const CommonNavigationParams
& common_params
,
2067 const RequestNavigationParams
& request_params
) {
2068 // Browser plugin guests are not allowed to navigate outside web-safe schemes,
2069 // so do not grant them the ability to request additional URLs.
2070 if (!GetProcess()->IsIsolatedGuest()) {
2071 ChildProcessSecurityPolicyImpl::GetInstance()->GrantRequestURL(
2072 GetProcess()->GetID(), common_params
.url
);
2073 if (common_params
.url
.SchemeIs(url::kDataScheme
) &&
2074 common_params
.base_url_for_data_url
.SchemeIs(url::kFileScheme
)) {
2075 // If 'data:' is used, and we have a 'file:' base url, grant access to
2077 ChildProcessSecurityPolicyImpl::GetInstance()->GrantRequestURL(
2078 GetProcess()->GetID(), common_params
.base_url_for_data_url
);
2082 // We may be returning to an existing NavigationEntry that had been granted
2083 // file access. If this is a different process, we will need to grant the
2084 // access again. The files listed in the page state are validated when they
2085 // are received from the renderer to prevent abuse.
2086 if (request_params
.page_state
.IsValid()) {
2087 render_view_host_
->GrantFileAccessFromPageState(request_params
.page_state
);
2091 } // namespace content