Browser Process Model — Site Isolation, Blink, Network Stack & V8 Pipeline
Chromium splits browser, renderer, GPU, network, and utility processes. Site isolation, Blink, and the V8 Ignition-to-TurboFan path are the systems interview, not a JS language lecture.
- 1Gist
- 2Maps
- 3Q&A
- 4Sandbox
Voice readout needs Web Speech Synthesis in this browser.
Question ladder
L1
Why can one tab crash without killing the browser?
Answer
That site's renderer is a separate process. The browser process drops it and keeps the UI.
L2
What does site isolation buy?
Answer
Cross-site pages and iframes get different renderer processes, so a compromise is harder to turn into cross-site memory reads.
L3
Origin versus site?
Answer
An origin is scheme, host, and port. A site is coarser, usually the scheme plus the registrable domain. Isolation and some cookie rules use site, not origin.
L4
Which process owns the DOM, and which coordinates cookies?
Answer
The renderer owns the DOM, style, and layout. The network service performs HTTP and is the usual home for cookie coordination.
L5
Blink versus Chromium versus V8?
Answer
Chromium is the browser project. Blink is the rendering engine. V8 is the JS engine inside the renderer. Chrome adds Google services on top of Chromium.
L6
Ignition versus TurboFan?
Answer
Ignition runs bytecode for a fast start. TurboFan compiles hot functions using type feedback. Failed assumptions deoptimize back to Ignition.
L7
Where does a Service Worker sit, and what is it not?
Answer
An origin-scoped worker, often with its own lifetime, that may intercept fetch before the network. It is not a privilege escalation and not the page's main thread. Task order on that thread is the event-loop lesson.
Failure modes
Privileged token in renderer JS
XSS in that origin reads the token. The sandbox does not save you from script you executed.
Site isolation misunderstood as same-origin policy
Isolation is a process boundary. The same-origin policy is an API boundary. You need both.
HTTP cache confused with Cache Storage
The network stack has an HTTP cache. The Service Worker Cache API is origin storage the worker controls.
Deopt spiral blamed on the network
A hot function keeps changing object shape, so TurboFan bails to Ignition. The trace is compiler tiers, not DNS.
Worker treated as a privilege hatch
The worker is still the origin. A page that can message it can ask it to do origin-scoped work.
Misconceptions
The GPU process runs your JS.
V8 runs in the renderer. The GPU process composites and talks to the graphics driver.
One renderer per tab, always.
Site isolation keys processes by site. A tab can host more than one renderer when it embeds another site.
TurboFan means the function stays fast.
Speculative optimizations deoptimize when a hidden assumption, often object shape, stops holding.
Interviewer traps
Explaining closures, this, or microtasks in detail.
Name the process and the compiler tier. Send task ordering to the event-loop lesson.
Saying Blink is Chrome.
Blink renders. Chromium is the project. Chrome is the branded product. Gecko and WebKit are the other engines.
A bank iframe sits inside a news page
Prefer
Site isolation
The bank site gets its own renderer. A bug in the news renderer does not share that address space.
- Cross-site iframes are different processes.
- A hung news renderer does not have to take the bank document with it.
- You pay memory for the extra process.
Alternative
One renderer for the tab
Every frame in the tab shares a process and a heap.
- Less RAM.
- A speculative-execution read has more cross-site data nearby.
- One crash or hang mixes unrelated sites.
Who owns the work
- 1
Browser process
UI, tab strip, navigation coordination, permission prompts. Highest privilege. - 2
Network service
DNS, TLS, HTTP. Cookie coordination lives over here, not in the page heap. - 3
Renderer per site
Blink and V8. Sandboxed. Untrusted HTML and JS. - 4
GPU process
Compositing and WebGL. A GPU crash is not the whole browser. - 5
Service Worker
Origin-scoped, separate lifetime, may see fetch before the network. Still that origin.
Overview
Chromium is a multi-process OS for the web. The browser process orchestrates. Renderer processes run Blink and V8 under site-isolation rules. GPU, network, and utility processes shrink privilege and keep crashes local.
Know the security boundaries and the Ignition to TurboFan path at systems level. Closures, this, and the microtask queue are not this page. Task ordering is JS event loop, microtasks, and macrotasks. This page says which process and which compiler tier execute those tasks.
Process model
Flow
- 1
1. Browser process coordinates
- next2. Network service does HTTP
- 2
2. Network service does HTTP
- next3. GPU process composites
- 3
3. GPU process composites
- next4. One renderer per site
- 4
4. One renderer per site
- next5. Blink and V8 live there
- 5
5. Blink and V8 live there
- next6. Utility processes stay narrow
- 6
6. Utility processes stay narrow
Lesson map
Browser Process Model — Site Isolation, Blink, Network Stack & V8 Pipeline
Chromium splits browser, renderer, GPU, network, and utility processes. Site isolation, Blink, and the V8 Ignition-to-TurboFan path are the systems interview, not a JS language lecture.
Architecture. Architecture
Select a node to see why it exists, or an edge to see the protocol, direction, effect, and consequence.
Mermaid export
flowchart TB a["1. Browser process coordinates"] b["2. Network service does HTTP"] c["3. GPU process composites"] d["4. One renderer per site"] a -->|1. Browser process coordinates| b b -->|2. Network service does HTTP| c c -->|3. GPU process composites| d
The boxes are siblings coordinated by the browser process, drawn as a column so the card does not spread sideways. The network service feeds renderers. The GPU process composites for them. A Service Worker for an origin is another worker lifetime, often its own process, not a second copy of the page.
| Process | Role | Privilege |
|---|---|---|
| Browser | Tab UI, navigation coordination, permission prompts | Highest. Talks to the OS |
| Renderer | DOM, style, layout, JS for a site | Sandboxed. Untrusted HTML and JS |
| GPU | Compositing, WebGL | Separate. A crash here is not the browser UI |
| Network | HTTP stack, cookie and cache coordination | Isolated I/O |
| Utility | Audio, storage, decode helpers | Least privilege for that job |
| Service Worker | Origin worker that can intercept fetch | Separate lifetime from the page. Same origin rules |
Site isolation
Site isolation puts different sites in different renderer processes so a compromised renderer cannot easily read another site's DOM or cookies out of its own memory.
| Without isolation | With isolation |
|---|---|
| Many iframes can share a process | A cross-site iframe gets another process |
| Speculative reads have more cross-site data nearby | Higher memory cost, stronger boundary |
| One hang can stall mixed content | Failures stay closer to that site |
Origin is scheme + host + port. Site is coarser: typically the scheme and the registrable domain, so app.example.com and docs.example.com can share a site while evil.test cannot. Isolation and some cookie rules use that coarser key. Say both terms. The public-suffix list is what makes "registrable" real. The sandbox below is a toy that only keeps the last two labels.
Blink
Blink is Chromium's rendering engine: HTML and CSS parsing, DOM, style, layout, paint, the bindings that expose Web APIs to V8, and much of the Web platform surface inside the renderer.
| Layer | Responsibility |
|---|---|
| Bindings | Web APIs visible to V8 |
| DOM and CSS | Document and style |
| Layout and paint | Geometry and display lists. The previous lesson |
| Compositor handoff | Layers toward the GPU process |
| Loader | Document and resource loading, coordinated with the network service |
Blink is not Chromium, and Chromium is not Chrome. Chromium is the open-source browser. Blink is the rendering engine inside it. Chrome adds Google services and branding. Other engines: Gecko (Firefox), WebKit (Safari).
Network stack
- Navigation starts in the browser process.
- The network service does DNS, TLS, and HTTP.
- Bytes stream to the renderer that owns the document.
- A Service Worker can intercept in its own context before the network. The lifecycle page owns that handler.
- The HTTP cache and Cache Storage are different layers. Do not treat a worker
caches.matchas the HTTP cache.
V8, at systems level
Flow
- 1
1. Parse JS source
- next2. Ignition runs bytecode
- 2
2. Ignition runs bytecode
- next3. Collect type feedback
- 3
3. Collect type feedback
- next4. TurboFan optimizes hot code
- 4
4. TurboFan optimizes hot code
- next5. Deopt returns to Ignition
- 5
5. Deopt returns to Ignition
| Stage | Role | Interview takeaway |
|---|---|---|
| Ignition | Fast startup via bytecode | Cold code runs interpreted |
| TurboFan | Optimize hot functions | Speculative opts use type feedback |
| Deoptimization | Bail back when checks fail | A shape change can make a hot function slow again |
| Generational GC | Reclaim the heap | Retention roots still dominate leaks |
Do not expand this into a language lesson. The renderer hosts V8. The event-loop page explains task ordering. This page explains the process and the compiler tier.
Security boundaries
| Boundary | Protects against | Broken by |
|---|---|---|
| Process sandbox | A renderer escape into native code | Sandbox bugs, unsafe IPC |
| Site isolation | Cross-site data theft via memory | A mis-assigned process. The exploit still owns that site |
| Same-origin policy | Cross-origin DOM and API access | XSS in the victim origin |
| CORS | Cross-origin reads from script | A loose Access-Control-Allow-Origin |
| Content Security Policy | XSS blast radius | A weak policy or unsafe-inline |
What if you choose the other? A privileged token in renderer JS trusts XSS. Checking a secret only inside a Service Worker still trusts any page of that origin that can message the worker.
Processes and tiers, in memory
Press Run. Snippets must be self-contained — no network, files, or native modules.
app.example.com and docs.example.com share a toy site and therefore one renderer id. evil.test gets another. Real Chromium uses the public suffix list, not "last two labels."
Interview Q&A
Why can one tab crash without killing the whole browser?
Answer
Renderers are separate processes. The browser process can discard a dead renderer and keep the UI alive.
What does site isolation buy?
Answer
Cross-site pages and iframes get separate renderers, so a compromise is harder to turn into cross-site data theft through memory.
Ignition versus TurboFan, in one line?
Answer
Ignition interprets bytecode for a quick start. TurboFan compiles hot code with speculative optimizations that may deoptimize.
Where do Service Workers fit?
Answer
They are origin-scoped workers, often with their own process lifetime, and they can intercept fetch. They stay inside origin security. They are not a privilege hatch.
Who owns cookies if the renderer is compromised?
Answer
Cookie jars are coordinated outside the renderer, in the network service. Isolation is what keeps another site's renderer from simply reading them out of a shared heap. XSS in the victim origin is a different hole.
Is a same-site iframe a same-origin iframe?
Answer
Not always. https://app.example.com and https://docs.example.com can be the same site and different origins. APIs still enforce origin. Isolation keys off site.
Why did a hot function get slow after a refactor?
Answer
TurboFan speculated on object shape or types. The new shape failed a check, deoptimized to Ignition, and may keep failing if the shapes stay polymorphic.
What is the event loop doing on this page?
Answer
Nothing beyond the pointer. Ordering of tasks and microtasks is JS event loop, microtasks, and macrotasks. Here the question is which process runs that loop and which tier runs the function.
Pitfalls
- Drawing one box labeled "Chrome" for UI, DOM, GPU, and the network.
- Calling V8 the renderer, or Blink the JS engine.
- Storing a session secret in a renderer global and calling the sandbox enough.
- Explaining a deopt as "the event loop is blocked" without a trace. Different questions.
A tab loads https://news.example, which iframes https://bank.example and https://cdn.example. Say which documents can share a renderer under site isolation, which process owns the cookie jar, and which process runs the bank page's JS.