← All reports

Enable `SiteIsolationSharedProcessEnabled` by default

Component: WebKit UIProcess Site Isolation | 5fa37cf

Site Isolation puts different sites in separate OS processes so that a compromised renderer — reached, typically, through a JS engine memory-corruption bug — cannot read cross-site data or credentials, and so that Spectre-style side channels cannot cross an origin boundary in-process. BrowsingContextGroup is the UIProcess-side component that decides which WebProcess a given site's frames are assigned to. "Shared process mode" is the resource-saving alternative to strict per-site isolation: instead of spinning up a process per site, multiple cross-site frames are routed into one shared process through sharedProcessForSite and ensureProcessForSite, tracked in m_sharedProcessSites.

This commit flips the SiteIsolationSharedProcessEnabled preference from false to true, making that mode the default rather than an opt-in. It also adds release logging around BrowsingContextGroup::sharedProcessForSite and ensureProcessForSite, recording when a site joins a shared process and how many sites that process now hosts.

Groups of cross-site frames now cohabit one WebContent process by default, narrowing the process boundary that Site Isolation exists to provide. Until this commit the shared-process path was off for most users; flipping the flag means this code path — and the reduced isolation it implies — is what most users actually get, which also makes the new logging the primary observability into which sites ended up sharing a process.

The forward-facing question is what elsewhere in the UIProcess assumes a process hosts one site. Narrow: trace the consumers of m_sharedProcessSites and the sharedProcessForSite/ensureProcessForSite assignment results, looking for policy decisions that derive a single site or origin from a process identity. Wider: any code that answers "which site is this process?" rather than "which frame sent this?" now has a many-to-one relationship where it previously had one-to-one — the audit set is every place a WebProcessProxy is used as a proxy for an origin in a permission, storage or cookie decision. Widest: the pattern is a resource-sharing optimization that merges previously-disjoint isolation domains, and every invariant that was upheld incidentally by the partition now needs to be an explicit check. Code-review tell: a lookup that goes from process to site rather than from message to frame to site.