Changeset 179702 in webkit
- Timestamp:
- Feb 5, 2015, 1:29:19 PM (12 years ago)
- Location:
- trunk
- Files:
-
- 2 added
- 7 edited
-
LayoutTests/http/tests/cache/memory-cache-pruning-expected.txt (added)
-
LayoutTests/http/tests/cache/memory-cache-pruning.html (added)
-
Source/WebCore/ChangeLog (modified) (1 diff)
-
Source/WebCore/WebCore.exp.in (modified) (1 diff)
-
Source/WebCore/loader/cache/MemoryCache.cpp (modified) (2 diffs)
-
Source/WebCore/loader/cache/MemoryCache.h (modified) (2 diffs)
-
Source/WebCore/testing/Internals.cpp (modified) (1 diff)
-
Source/WebCore/testing/Internals.h (modified) (1 diff)
-
Source/WebCore/testing/Internals.idl (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
trunk/Source/WebCore/ChangeLog
r179699 r179702 1 2015-02-05 Chris Dumez <cdumez@apple.com> 2 3 Free memory read under MemoryCache::pruneLiveResourcesToSize() 4 https://bugs.webkit.org/show_bug.cgi?id=141292 5 <rdar://problem/19725522> 6 7 Reviewed by Antti Koivisto. 8 9 In MemoryCache::pruneLiveResourcesToSize(), we were iterating over the 10 m_liveDecodedResources ListHashSet and possibly calling 11 CachedResource::destroyDecodedData() on the current value. Doing so 12 would cause a call to ListHashSet::remove() to remove the value pointed 13 by the current iterator, thus invalidating our iterator. 14 15 In this patch, we increment the ListHashSet iterator *before* calling 16 CachedResource::destroyDecodedData(), while the current iterator is 17 still valid. Note that this is safe because unlike iteration of most 18 WTF Hash data structures, iteration is guaranteed safe against mutation 19 of the ListHashSet, except for removal of the item currently pointed to 20 by a given iterator. 21 22 Test: http/tests/cache/memory-cache-pruning.html 23 24 * loader/cache/MemoryCache.cpp: 25 (WebCore::MemoryCache::pruneLiveResourcesToSize): 26 1 27 2015-02-05 Jer Noble <jer.noble@apple.com> 2 28 -
trunk/Source/WebCore/WebCore.exp.in
r179604 r179702 198 198 __ZN7WebCore11MemoryCache19getOriginsWithCacheERN3WTF7HashSetINS1_6RefPtrINS_14SecurityOriginEEENS_18SecurityOriginHashENS1_10HashTraitsIS5_EEEE 199 199 __ZN7WebCore11MemoryCache20removeImageFromCacheERKNS_3URLERKN3WTF6StringE 200 __ZN7WebCore11MemoryCache24pruneDeadResourcesToSizeEj 201 __ZN7WebCore11MemoryCache24pruneLiveResourcesToSizeEjb 200 202 __ZN7WebCore11MemoryCache25removeResourcesWithOriginERNS_14SecurityOriginE 201 203 __ZN7WebCore11MemoryCache9singletonEv -
trunk/Source/WebCore/loader/cache/MemoryCache.cpp
r179489 r179702 301 301 // greater than the current->m_lastDecodedAccessTime. 302 302 // For more details see: https://bugs.webkit.org/show_bug.cgi?id=30209 303 for (auto* current : m_liveDecodedResources) { 303 auto it = m_liveDecodedResources.begin(); 304 while (it != m_liveDecodedResources.end()) { 305 auto* current = *it; 306 307 // Increment the iterator now because the call to destroyDecodedData() below 308 // may cause a call to ListHashSet::remove() and invalidate the current 309 // iterator. Note that this is safe because unlike iteration of most 310 // WTF Hash data structures, iteration is guaranteed safe against mutation 311 // of the ListHashSet, except for removal of the item currently pointed to 312 // by a given iterator. 313 ++it; 314 304 315 ASSERT(current->hasClients()); 305 316 if (current->isLoaded() && current->decodedSize()) { … … 312 323 continue; 313 324 314 // Destroy our decoded data. This will remove us from 315 // m_liveDecodedResources, and possibly move us to a different LRU 316 // list in m_allResources. 325 // Destroy our decoded data. This will remove us from m_liveDecodedResources, and possibly move us 326 // to a different LRU list in m_allResources. 317 327 current->destroyDecodedData(); 318 328 -
trunk/Source/WebCore/loader/cache/MemoryCache.h
r179489 r179702 63 63 WTF_MAKE_NONCOPYABLE(MemoryCache); WTF_MAKE_FAST_ALLOCATED; 64 64 friend NeverDestroyed<MemoryCache>; 65 65 friend class Internals; 66 66 public: 67 67 struct TypeStatistic { … … 118 118 119 119 void prune(); 120 unsigned size() const { return m_liveSize + m_deadSize; } 120 121 121 122 void setDeadDecodedDataDeletionInterval(std::chrono::milliseconds interval) { m_deadDecodedDataDeletionInterval = interval; } -
trunk/Source/WebCore/testing/Internals.cpp
r179489 r179702 410 410 } 411 411 412 void Internals::pruneMemoryCacheToSize(unsigned size) 413 { 414 MemoryCache::singleton().pruneDeadResourcesToSize(size); 415 MemoryCache::singleton().pruneLiveResourcesToSize(size, true); 416 } 417 418 unsigned Internals::memoryCacheSize() const 419 { 420 return MemoryCache::singleton().size(); 421 } 422 412 423 Node* Internals::treeScopeRootNode(Node* node, ExceptionCode& ec) 413 424 { -
trunk/Source/WebCore/testing/Internals.h
r178820 r179702 85 85 bool isLoadingFromMemoryCache(const String& url); 86 86 String xhrResponseSource(XMLHttpRequest*); 87 87 88 void clearMemoryCache(); 89 void pruneMemoryCacheToSize(unsigned size); 90 unsigned memoryCacheSize() const; 88 91 89 92 PassRefPtr<CSSComputedStyleDeclaration> computedStyleIncludingVisitedInfo(Node*, ExceptionCode&) const; -
trunk/Source/WebCore/testing/Internals.idl
r178820 r179702 45 45 DOMString xhrResponseSource(XMLHttpRequest xhr); 46 46 void clearMemoryCache(); 47 void pruneMemoryCacheToSize(long size); 48 long memoryCacheSize(); 47 49 48 50 [RaisesException] CSSStyleDeclaration computedStyleIncludingVisitedInfo(Node node);
Note:
See TracChangeset
for help on using the changeset viewer.