⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 226485 in webkit


Ignore:
Timestamp:
Jan 5, 2018, 11:01:21 PM (9 years ago)
Author:
jfbastien@apple.com
Message:

WebAssembly: poison JS object's secrets
​https://bugs.webkit.org/show_bug.cgi?id=181339
<rdar://problem/36325001>

Reviewed by Mark Lam.

Source/JavaScriptCore:

Separating WebAssembly's JS objects from their non-JS
implementation means that all interesting information lives
outside of the JS object itself. This patch poisons each JS
object's pointer to non-JS implementation using the poisoning
mechanism and a unique key per JS object type origin.

  • runtime/JSCPoison.h:
  • wasm/js/JSToWasm.cpp:

(JSC::Wasm::createJSToWasmWrapper): JS -> wasm stores the JS
object in a stack slot when fast TLS is disabled. This requires
that we unpoison the Wasm::Instance.

  • wasm/js/JSWebAssemblyCodeBlock.h:
  • wasm/js/JSWebAssemblyInstance.h:

(JSC::JSWebAssemblyInstance::offsetOfPoisonedInstance): renamed to
be explicit that the pointer is poisoned.

  • wasm/js/JSWebAssemblyMemory.h:
  • wasm/js/JSWebAssemblyModule.h:
  • wasm/js/JSWebAssemblyTable.h:

Source/WTF:

swapping a poisoned pointer with a non-poisoned one (as is done in
JSWebAssembyMemory::adopt) was missing.

  • wtf/Poisoned.h:

(WTF::PoisonedImpl::swap):
(WTF::ConstExprPoisonedPtrTraits::swap):

Tools:

Update tests for swap(Poisoned<k, T>, T*)

  • TestWebKitAPI/Tests/WTF/ConstExprPoisoned.cpp:

(TestWebKitAPI::TEST):

  • TestWebKitAPI/Tests/WTF/Poisoned.cpp:

(TestWebKitAPI::TEST):

  • TestWebKitAPI/Tests/WTF/PoisonedRef.cpp:

(TestWebKitAPI::TEST):

Location:
trunk
Files:
14 edited

Legend:

Unmodified
Added
Removed
  • trunk/Source/JavaScriptCore/ChangeLog

    r226474 r226485  
     12018-01-05  JF Bastien  <jfbastien@apple.com>
     2
     3        WebAssembly: poison JS object's secrets
     4        https://bugs.webkit.org/show_bug.cgi?id=181339
     5        <rdar://problem/36325001>
     6
     7        Reviewed by Mark Lam.
     8
     9        Separating WebAssembly's JS objects from their non-JS
     10        implementation means that all interesting information lives
     11        outside of the JS object itself. This patch poisons each JS
     12        object's pointer to non-JS implementation using the poisoning
     13        mechanism and a unique key per JS object type origin.
     14
     15        * runtime/JSCPoison.h:
     16        * wasm/js/JSToWasm.cpp:
     17        (JSC::Wasm::createJSToWasmWrapper): JS -> wasm stores the JS
     18        object in a stack slot when fast TLS is disabled. This requires
     19        that we unpoison the Wasm::Instance.
     20        * wasm/js/JSWebAssemblyCodeBlock.h:
     21        * wasm/js/JSWebAssemblyInstance.h:
     22        (JSC::JSWebAssemblyInstance::offsetOfPoisonedInstance): renamed to
     23        be explicit that the pointer is poisoned.
     24        * wasm/js/JSWebAssemblyMemory.h:
     25        * wasm/js/JSWebAssemblyModule.h:
     26        * wasm/js/JSWebAssemblyTable.h:
     27
    1282018-01-05  Michael Saboff  <msaboff@apple.com>
    229
  • trunk/Source/JavaScriptCore/runtime/JSCPoison.h

    r225659 r226485  
    11/*
    2  * Copyright (C) 2017 Apple Inc. All rights reserved.
     2 * Copyright (C) 2017-2018 Apple Inc. All rights reserved.
    33 *
    44 * Redistribution and use in source and binary forms, with or without
    … …  
    3232enum Poison {
    3333    NotPoisoned = 0,
     34    JSWebAssemblyCodeBlockPoison,
     35    JSWebAssemblyInstancePoison,
     36    JSWebAssemblyMemoryPoison,
     37    JSWebAssemblyModulePoison,
     38    JSWebAssemblyTablePoison,
    3439    TransitionMapPoison,
    3540    WeakImplPoison,
  • trunk/Source/JavaScriptCore/wasm/js/JSToWasm.cpp

    r226461 r226485  
    11/*
    2  * Copyright (C) 2016-2017 Apple Inc. All rights reserved.
     2 * Copyright (C) 2016-2018 Apple Inc. All rights reserved.
    33 *
    44 * Redistribution and use in source and binary forms, with or without
    … …  
    118118        if (!Context::useFastTLS()) {
    119119            jit.loadPtr(CCallHelpers::Address(GPRInfo::callFrameRegister, jsOffset), wasmContextInstanceGPR);
    120             jit.loadPtr(CCallHelpers::Address(wasmContextInstanceGPR, JSWebAssemblyInstance::offsetOfInstance()), wasmContextInstanceGPR);
     120            jit.loadPtr(CCallHelpers::Address(wasmContextInstanceGPR, JSWebAssemblyInstance::offsetOfPoisonedInstance()), wasmContextInstanceGPR);
     121            jit.move(CCallHelpers::TrustedImm64(makeConstExprPoison(JSWebAssemblyInstancePoison)), scratchReg);
     122            jit.xor64(scratchReg, wasmContextInstanceGPR);
    121123            jsOffset += sizeof(EncodedJSValue);
    122124        }
  • trunk/Source/JavaScriptCore/wasm/js/JSWebAssemblyCodeBlock.h

    r225314 r226485  
    11/*
    2  * Copyright (C) 2017 Apple Inc. All rights reserved.
     2 * Copyright (C) 2017-2018 Apple Inc. All rights reserved.
    33 *
    44 * Redistribution and use in source and binary forms, with or without
    … …  
    2929
    3030#include "CallLinkInfo.h"
     31#include "JSCPoison.h"
    3132#include "JSCell.h"
    3233#include "PromiseDeferredTimer.h"
    … …  
    3738#include "WasmModule.h"
    3839#include <wtf/Bag.h>
     40#include <wtf/Ref.h>
    3941#include <wtf/Vector.h>
    4042
    … …  
    9193    };
    9294
    93     Ref<Wasm::CodeBlock> m_codeBlock;
     95    PoisonedRef<JSWebAssemblyCodeBlockPoison, Wasm::CodeBlock> m_codeBlock;
    9496    Vector<MacroAssemblerCodeRef> m_wasmToJSExitStubs;
    9597    UnconditionalFinalizer m_unconditionalFinalizer;
  • trunk/Source/JavaScriptCore/wasm/js/JSWebAssemblyInstance.h

    r224810 r226485  
    11/*
    2  * Copyright (C) 2016-2017 Apple Inc. All rights reserved.
     2 * Copyright (C) 2016-2018 Apple Inc. All rights reserved.
    33 *
    44 * Redistribution and use in source and binary forms, with or without
    … …  
    2828#if ENABLE(WEBASSEMBLY)
    2929
     30#include "JSCPoison.h"
    3031#include "JSDestructibleObject.h"
    3132#include "JSObject.h"
    … …  
    3435#include "JSWebAssemblyTable.h"
    3536#include "WasmInstance.h"
     37#include <wtf/Ref.h>
    3638
    3739namespace JSC {
    … …  
    7577    }
    7678
    77     static size_t offsetOfInstance() { return OBJECT_OFFSETOF(JSWebAssemblyInstance, m_instance); }
     79    static size_t offsetOfPoisonedInstance() { return OBJECT_OFFSETOF(JSWebAssemblyInstance, m_instance); }
    7880    static size_t offsetOfCallee() { return OBJECT_OFFSETOF(JSWebAssemblyInstance, m_callee); }
    7981
    … …  
    8789    JSWebAssemblyModule* module() const { return m_module.get(); }
    8890
    89     Ref<Wasm::Instance> m_instance;
     91    PoisonedRef<JSWebAssemblyInstancePoison, Wasm::Instance> m_instance;
    9092
    9193    WriteBarrier<JSWebAssemblyModule> m_module;
  • trunk/Source/JavaScriptCore/wasm/js/JSWebAssemblyMemory.h

    r225314 r226485  
    11/*
    2  * Copyright (C) 2016-2017 Apple Inc. All rights reserved.
     2 * Copyright (C) 2016-2018 Apple Inc. All rights reserved.
    33 *
    44 * Redistribution and use in source and binary forms, with or without
    … …  
    2828#if ENABLE(WEBASSEMBLY)
    2929
     30#include "JSCPoison.h"
    3031#include "JSDestructibleObject.h"
    3132#include "JSObject.h"
    3233#include "WasmMemory.h"
     34#include <wtf/Ref.h>
    3335#include <wtf/RefPtr.h>
    3436
    … …  
    6668    static void visitChildren(JSCell*, SlotVisitor&);
    6769
    68     Ref<Wasm::Memory> m_memory;
     70    PoisonedRef<JSWebAssemblyMemoryPoison, Wasm::Memory> m_memory;
    6971    WriteBarrier<JSArrayBuffer> m_bufferWrapper;
    70     RefPtr<ArrayBuffer> m_buffer;
     72    PoisonedRefPtr<JSWebAssemblyMemoryPoison, ArrayBuffer> m_buffer;
    7173};
    7274
  • trunk/Source/JavaScriptCore/wasm/js/JSWebAssemblyModule.h

    r225499 r226485  
    11/*
    2  * Copyright (C) 2016-2017 Apple Inc. All rights reserved.
     2 * Copyright (C) 2016-2018 Apple Inc. All rights reserved.
    33 *
    44 * Redistribution and use in source and binary forms, with or without
    … …  
    2828#if ENABLE(WEBASSEMBLY)
    2929
     30#include "JSCPoison.h"
    3031#include "JSDestructibleObject.h"
    3132#include "JSObject.h"
    … …  
    3536#include <wtf/Expected.h>
    3637#include <wtf/Forward.h>
     38#include <wtf/Ref.h>
    3739#include <wtf/text/WTFString.h>
    3840
    … …  
    8082    static void visitChildren(JSCell*, SlotVisitor&);
    8183
    82     Ref<Wasm::Module> m_module;
     84    PoisonedRef<JSWebAssemblyModulePoison, Wasm::Module> m_module;
    8385    WriteBarrier<SymbolTable> m_exportSymbolTable;
    8486    WriteBarrier<JSWebAssemblyCodeBlock> m_codeBlocks[Wasm::NumberOfMemoryModes];
  • trunk/Source/JavaScriptCore/wasm/js/JSWebAssemblyTable.h

    r223738 r226485  
    11/*
    2  * Copyright (C) 2016-2017 Apple Inc. All rights reserved.
     2 * Copyright (C) 2016-2018 Apple Inc. All rights reserved.
    33 *
    44 * Redistribution and use in source and binary forms, with or without
    … …  
    2828#if ENABLE(WEBASSEMBLY)
    2929
     30#include "JSCPoison.h"
    3031#include "JSDestructibleObject.h"
    3132#include "JSObject.h"
    … …  
    3536#include "WebAssemblyFunction.h"
    3637#include <wtf/MallocPtr.h>
     38#include <wtf/Ref.h>
    3739
    3840namespace JSC {
    … …  
    6466    static void visitChildren(JSCell*, SlotVisitor&);
    6567
    66     Ref<Wasm::Table> m_table;
     68    PoisonedRef<JSWebAssemblyTablePoison, Wasm::Table> m_table;
    6769    MallocPtr<WriteBarrier<JSObject>> m_jsFunctions;
    6870};
  • trunk/Source/WTF/ChangeLog

    r226483 r226485  
     12018-01-05  JF Bastien  <jfbastien@apple.com>
     2
     3        WebAssembly: poison JS object's secrets
     4        https://bugs.webkit.org/show_bug.cgi?id=181339
     5        <rdar://problem/36325001>
     6
     7        Reviewed by Mark Lam.
     8
     9        swapping a poisoned pointer with a non-poisoned one (as is done in
     10        JSWebAssembyMemory::adopt) was missing.
     11
     12        * wtf/Poisoned.h:
     13        (WTF::PoisonedImpl::swap):
     14        (WTF::ConstExprPoisonedPtrTraits::swap):
     15
    1162018-01-05  David Kilzer  <ddkilzer@apple.com>
    217
  • trunk/Source/WTF/wtf/Poisoned.h

    r226344 r226485  
    183183    }
    184184
     185    void swap(T& t2)
     186    {
     187        T t1 = this->unpoisoned();
     188        std::swap(t1, t2);
     189        m_poisonedBits = poison(t1);
     190    }
     191
    185192    template<class U>
    186193    T exchange(U&& newValue)
    … …  
    209216template<typename K1, K1 k1, typename T1, typename K2, K2 k2, typename T2>
    210217inline void swap(PoisonedImpl<K1, k1, T1>& a, PoisonedImpl<K2, k2, T2>& b)
     218{
     219    a.swap(b);
     220}
     221
     222template<typename K1, K1 k1, typename T1>
     223inline void swap(PoisonedImpl<K1, k1, T1>& a, T1& b)
    211224{
    212225    a.swap(b);
    … …  
    242255    template<class U> static ALWAYS_INLINE T* exchange(StorageType& ptr, U&& newValue) { return ptr.exchange(newValue); }
    243256
     257    template<typename K1, K1 k1, typename T1>
     258    static ALWAYS_INLINE void swap(PoisonedImpl<K1, k1, T1>& a, T1& b) { a.swap(b); }
     259
    244260    template<typename K1, K1 k1, typename T1, typename K2, K2 k2, typename T2>
    245261    static ALWAYS_INLINE void swap(PoisonedImpl<K1, k1, T1>& a, PoisonedImpl<K2, k2, T2>& b) { a.swap(b); }
    … …  
    253269using WTF::Poisoned;
    254270using WTF::PoisonedBits;
     271using WTF::makeConstExprPoison;
    255272using WTF::makePoison;
    256 
  • trunk/Tools/ChangeLog

    r226484 r226485  
     12018-01-05  JF Bastien  <jfbastien@apple.com>
     2
     3        WebAssembly: poison JS object's secrets
     4        https://bugs.webkit.org/show_bug.cgi?id=181339
     5        <rdar://problem/36325001>
     6
     7        Reviewed by Mark Lam.
     8
     9        Update tests for swap(Poisoned<k, T>, T*)
     10
     11        * TestWebKitAPI/Tests/WTF/ConstExprPoisoned.cpp:
     12        (TestWebKitAPI::TEST):
     13        * TestWebKitAPI/Tests/WTF/Poisoned.cpp:
     14        (TestWebKitAPI::TEST):
     15        * TestWebKitAPI/Tests/WTF/PoisonedRef.cpp:
     16        (TestWebKitAPI::TEST):
     17
    1182018-01-05  Wenson Hsieh  <wenson_hsieh@apple.com>
    219
  • trunk/Tools/TestWebKitAPI/Tests/WTF/ConstExprPoisoned.cpp

    r226247 r226485  
    11/*
    2  * Copyright (C) 2017 Apple Inc. All rights reserved.
     2 * Copyright (C) 2017-2018 Apple Inc. All rights reserved.
    33 *
    44 * Redistribution and use in source and binary forms, with or without
    … …  
    338338        ASSERT_TRUE(p2.bits() != p4.bits());
    339339    }
     340
     341    {
     342        ConstExprPoisoned<PoisonA, RefLogger*> p1(&a);
     343        RefLogger* p2(&b);
     344        ASSERT_EQ(&a, p1.unpoisoned());
     345        ASSERT_EQ(&b, p2);
     346        swap(p1, p2);
     347        ASSERT_EQ(&b, p1.unpoisoned());
     348        ASSERT_EQ(&a, p2);
     349
     350        ASSERT_TRUE(p1.bits() != bitwise_cast<uintptr_t>(p2));
     351    }
     352
     353    {
     354        ConstExprPoisoned<PoisonA, RefLogger*> p1(&a);
     355        RefLogger* p2(&b);
     356        ASSERT_EQ(&a, p1.unpoisoned());
     357        ASSERT_EQ(&b, p2);
     358        p1.swap(p2);
     359        ASSERT_EQ(&b, p1.unpoisoned());
     360        ASSERT_EQ(&a, p2);
     361
     362        ASSERT_TRUE(p1.bits() != bitwise_cast<uintptr_t>(p2));
     363    }
    340364}
    341365
  • trunk/Tools/TestWebKitAPI/Tests/WTF/Poisoned.cpp

    r226015 r226485  
    11/*
    2  * Copyright (C) 2017 Apple Inc. All rights reserved.
     2 * Copyright (C) 2017-2018 Apple Inc. All rights reserved.
    33 *
    44 * Redistribution and use in source and binary forms, with or without
    … …  
    377377#endif
    378378    }
     379
     380#if ENABLE(MIXED_POISON)
     381    {
     382        Poisoned<g_testPoisonA, RefLogger*> p1(&a);
     383        RefLogger* p2(&b);
     384        ASSERT_EQ(&a, p1.unpoisoned());
     385        ASSERT_EQ(&b, p2);
     386        swap(p1, p2);
     387        ASSERT_EQ(&b, p1.unpoisoned());
     388        ASSERT_EQ(&a, p2);
     389
     390        ASSERT_TRUE(p1.bits() != bitwise_cast<uintptr_t>(p2));
     391    }
     392
     393    {
     394        Poisoned<g_testPoisonA, RefLogger*> p1(&a);
     395        RefLogger* p2(&b);
     396        ASSERT_EQ(&a, p1.unpoisoned());
     397        ASSERT_EQ(&b, p2);
     398        p1.swap(p2);
     399        ASSERT_EQ(&b, p1.unpoisoned());
     400        ASSERT_EQ(&a, p2);
     401
     402        ASSERT_TRUE(p1.bits() != bitwise_cast<uintptr_t>(p2));
     403    }
     404#endif
    379405}
    380406
  • trunk/Tools/TestWebKitAPI/Tests/WTF/PoisonedRef.cpp

    r226015 r226485  
    11/*
    2  * Copyright (C) 2017 Apple Inc. All rights reserved.
     2 * Copyright (C) 2017-2018 Apple Inc. All rights reserved.
    33 *
    44 * Redistribution and use in source and binary forms, with or without
    … …  
    195195    }
    196196    EXPECT_STREQ("ref(a) ref(b) | | deref(a) deref(b) ", takeLogStr().c_str());
     197
     198    {
     199        PoisonedRef<PoisonF, RefLogger> p1(a);
     200        Ref<RefLogger> p2(b);
     201        log() << "| ";
     202        EXPECT_EQ(&a, p1.ptr());
     203        EXPECT_EQ(&b, p2.ptr());
     204        swap(p1, p2);
     205        EXPECT_EQ(&b, p1.ptr());
     206        EXPECT_EQ(&a, p2.ptr());
     207        log() << "| ";
     208    }
     209    EXPECT_STREQ("ref(a) ref(b) | | deref(a) deref(b) ", takeLogStr().c_str());
     210
     211    {
     212        PoisonedRef<PoisonF, RefLogger> p1(a);
     213        Ref<RefLogger> p2(b);
     214        log() << "| ";
     215        EXPECT_EQ(&a, p1.ptr());
     216        EXPECT_EQ(&b, p2.ptr());
     217        p1.swap(p2);
     218        EXPECT_EQ(&b, p1.ptr());
     219        EXPECT_EQ(&a, p2.ptr());
     220        log() << "| ";
     221    }
     222    EXPECT_STREQ("ref(a) ref(b) | | deref(a) deref(b) ", takeLogStr().c_str());
    197223}
    198224
Note: See TracChangeset for help on using the changeset viewer.