Skip to content

Honor CSP sha256 source expressions for inline iframe scripts #864

Description

@wieslawsoltes

Parents: #267, #81
Release owner: SceneTech/AppScene#130

Reproduction

The exact Code OSS package at WebScene 5b97aac fetches webWorkerExtensionHostIframe.html successfully, but its inline bootstrap never posts vscode.bootstrap.nls. The file declares:

script-src ... 'sha256-daEgfo2VIXpx2Np71KqCCbkeQwv+68vPrx54XRcbdcs=' ...

The declared digest exactly matches the 5,588-byte inline script. WebScene's nested-document CSP parser recognizes that a hash source exists and consequently disables unsafe-inline, but frame_script_policy_allows never calculates or compares the script hash. It therefore rejects every hash-authorized inline script. The frame is fetched again after VS Code retries, with the same result, and #81 fails before MessagePort transfer.

Fix

  • Compute SHA-256 over the exact inline script bytes parsed from the document.
  • Encode the digest as standard padded Base64 and compare the source expression case-sensitively.
  • Preserve nonce and external-source behavior; keep unsafe-inline suppressed when any nonce/hash expression is present.
  • Reject malformed and nonmatching hashes without executing script.

SHA-384/SHA-512 expressions remain fail-closed until matching digest providers are implemented; they must not accidentally enable inline execution.

Gates

  • Browser/WPT-derived positive SHA-256, wrong digest, whitespace-sensitive source, mixed nonce/hash, unsafe-inline suppression, malformed value, and meta-policy-order contracts.
  • Native Code OSS-shaped iframe fixture using the exact published digest and the real bootstrap message structure.
  • Repeat bootstrap/teardown with bounded nodes, wrappers, heap/RSS, task queues, and zero extra idle frames.
  • Exact packaged Code OSS evidence: one iframe bootstrap, transferred MessagePort, Ready/Initialized handshake, and no application source change.

Performance

Hash each parser-discovered inline script at most once during policy admission. Do not add DOM scans, retained visual nodes, timers, or frame publications.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingvscode-oss/plannedPlanned for the AppScene/WebScene VS Code OSS integration

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions