content/browser/direct_sockets)This directory implements the browser-process service and security checks for the Direct Sockets API, allowing Isolated Web Apps (IWAs) and isolated contexts to establish raw TCP (TCPSocket, TCPServerSocket) and UDP (UDPSocket) connections.
//components/webapps/isolated_web_appsDirectSocketsServiceImpl supports connections initiated from a RenderFrameHost, SharedWorkerHost, or ServiceWorkerVersion (Context std::variant) and enforces:
CreateForFrame), verifies either (HasIsolatedContextCapability(render_frame_host) and PermissionsPolicyFeature::kDirectSockets) or DirectSocketsDelegate::AreDirectSocketsAllowed().CreateForSharedWorker, CreateForServiceWorker), verifies IsIsolatedContext(RenderProcessHost*).kTcp, kConnectedUdp, kBoundUdp, kTcpServer) via content::DirectSocketsDelegate::ValidateRequest*().PermissionsPolicyFeature::kDirectSockets and PermissionsPolicyFeature::kMulticastInDirectSockets, and requests blink::PermissionType::LOCAL_NETWORK or blink::PermissionType::LOOPBACK_NETWORK via PermissionController when connecting or binding to non-public IP addresses.FirewallHoleDelegate): Opens and manages scoped OS firewall holes for listening TCP/UDP server sockets on ChromeOS.When requests pass these security checks, DirectSocketsServiceImpl forwards socket creation to the sandboxed Network Service (network::mojom::NetworkContext).