Changeset 226485 in webkit
- Timestamp:
- Jan 5, 2018, 11:01:21 PM (9 years ago)
- Location:
- trunk
- Files:
-
- 14 edited
-
Source/JavaScriptCore/ChangeLog (modified) (1 diff)
-
Source/JavaScriptCore/runtime/JSCPoison.h (modified) (2 diffs)
-
Source/JavaScriptCore/wasm/js/JSToWasm.cpp (modified) (2 diffs)
-
Source/JavaScriptCore/wasm/js/JSWebAssemblyCodeBlock.h (modified) (4 diffs)
-
Source/JavaScriptCore/wasm/js/JSWebAssemblyInstance.h (modified) (5 diffs)
-
Source/JavaScriptCore/wasm/js/JSWebAssemblyMemory.h (modified) (3 diffs)
-
Source/JavaScriptCore/wasm/js/JSWebAssemblyModule.h (modified) (4 diffs)
-
Source/JavaScriptCore/wasm/js/JSWebAssemblyTable.h (modified) (4 diffs)
-
Source/WTF/ChangeLog (modified) (1 diff)
-
Source/WTF/wtf/Poisoned.h (modified) (4 diffs)
-
Tools/ChangeLog (modified) (1 diff)
-
Tools/TestWebKitAPI/Tests/WTF/ConstExprPoisoned.cpp (modified) (2 diffs)
-
Tools/TestWebKitAPI/Tests/WTF/Poisoned.cpp (modified) (2 diffs)
-
Tools/TestWebKitAPI/Tests/WTF/PoisonedRef.cpp (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/Source/JavaScriptCore/ChangeLog
r226474 r226485 1 2018-01-05 JF Bastien <jfbastien@apple.com> 2 3 WebAssembly: poison JS object's secrets 4 https://bugs.webkit.org/show_bug.cgi?id=181339 5 <rdar://problem/36325001> 6 7 Reviewed by Mark Lam. 8 9 Separating WebAssembly's JS objects from their non-JS 10 implementation means that all interesting information lives 11 outside of the JS object itself. This patch poisons each JS 12 object's pointer to non-JS implementation using the poisoning 13 mechanism and a unique key per JS object type origin. 14 15 * runtime/JSCPoison.h: 16 * wasm/js/JSToWasm.cpp: 17 (JSC::Wasm::createJSToWasmWrapper): JS -> wasm stores the JS 18 object in a stack slot when fast TLS is disabled. This requires 19 that we unpoison the Wasm::Instance. 20 * wasm/js/JSWebAssemblyCodeBlock.h: 21 * wasm/js/JSWebAssemblyInstance.h: 22 (JSC::JSWebAssemblyInstance::offsetOfPoisonedInstance): renamed to 23 be explicit that the pointer is poisoned. 24 * wasm/js/JSWebAssemblyMemory.h: 25 * wasm/js/JSWebAssemblyModule.h: 26 * wasm/js/JSWebAssemblyTable.h: 27 1 28 2018-01-05 Michael Saboff <msaboff@apple.com> 2 29 -
trunk/Source/JavaScriptCore/runtime/JSCPoison.h
r225659 r226485 1 1 /* 2 * Copyright (C) 2017 Apple Inc. All rights reserved.2 * Copyright (C) 2017-2018 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 32 32 enum Poison { 33 33 NotPoisoned = 0, 34 JSWebAssemblyCodeBlockPoison, 35 JSWebAssemblyInstancePoison, 36 JSWebAssemblyMemoryPoison, 37 JSWebAssemblyModulePoison, 38 JSWebAssemblyTablePoison, 34 39 TransitionMapPoison, 35 40 WeakImplPoison, -
trunk/Source/JavaScriptCore/wasm/js/JSToWasm.cpp
r226461 r226485 1 1 /* 2 * Copyright (C) 2016-201 7Apple Inc. All rights reserved.2 * Copyright (C) 2016-2018 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 118 118 if (!Context::useFastTLS()) { 119 119 jit.loadPtr(CCallHelpers::Address(GPRInfo::callFrameRegister, jsOffset), wasmContextInstanceGPR); 120 jit.loadPtr(CCallHelpers::Address(wasmContextInstanceGPR, JSWebAssemblyInstance::offsetOfInstance()), wasmContextInstanceGPR); 120 jit.loadPtr(CCallHelpers::Address(wasmContextInstanceGPR, JSWebAssemblyInstance::offsetOfPoisonedInstance()), wasmContextInstanceGPR); 121 jit.move(CCallHelpers::TrustedImm64(makeConstExprPoison(JSWebAssemblyInstancePoison)), scratchReg); 122 jit.xor64(scratchReg, wasmContextInstanceGPR); 121 123 jsOffset += sizeof(EncodedJSValue); 122 124 } -
trunk/Source/JavaScriptCore/wasm/js/JSWebAssemblyCodeBlock.h
r225314 r226485 1 1 /* 2 * Copyright (C) 2017 Apple Inc. All rights reserved.2 * Copyright (C) 2017-2018 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 29 29 30 30 #include "CallLinkInfo.h" 31 #include "JSCPoison.h" 31 32 #include "JSCell.h" 32 33 #include "PromiseDeferredTimer.h" … … 37 38 #include "WasmModule.h" 38 39 #include <wtf/Bag.h> 40 #include <wtf/Ref.h> 39 41 #include <wtf/Vector.h> 40 42 … … 91 93 }; 92 94 93 Ref<Wasm::CodeBlock> m_codeBlock;95 PoisonedRef<JSWebAssemblyCodeBlockPoison, Wasm::CodeBlock> m_codeBlock; 94 96 Vector<MacroAssemblerCodeRef> m_wasmToJSExitStubs; 95 97 UnconditionalFinalizer m_unconditionalFinalizer; -
trunk/Source/JavaScriptCore/wasm/js/JSWebAssemblyInstance.h
r224810 r226485 1 1 /* 2 * Copyright (C) 2016-201 7Apple Inc. All rights reserved.2 * Copyright (C) 2016-2018 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 28 28 #if ENABLE(WEBASSEMBLY) 29 29 30 #include "JSCPoison.h" 30 31 #include "JSDestructibleObject.h" 31 32 #include "JSObject.h" … … 34 35 #include "JSWebAssemblyTable.h" 35 36 #include "WasmInstance.h" 37 #include <wtf/Ref.h> 36 38 37 39 namespace JSC { … … 75 77 } 76 78 77 static size_t offsetOf Instance() { return OBJECT_OFFSETOF(JSWebAssemblyInstance, m_instance); }79 static size_t offsetOfPoisonedInstance() { return OBJECT_OFFSETOF(JSWebAssemblyInstance, m_instance); } 78 80 static size_t offsetOfCallee() { return OBJECT_OFFSETOF(JSWebAssemblyInstance, m_callee); } 79 81 … … 87 89 JSWebAssemblyModule* module() const { return m_module.get(); } 88 90 89 Ref<Wasm::Instance> m_instance;91 PoisonedRef<JSWebAssemblyInstancePoison, Wasm::Instance> m_instance; 90 92 91 93 WriteBarrier<JSWebAssemblyModule> m_module; -
trunk/Source/JavaScriptCore/wasm/js/JSWebAssemblyMemory.h
r225314 r226485 1 1 /* 2 * Copyright (C) 2016-201 7Apple Inc. All rights reserved.2 * Copyright (C) 2016-2018 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 28 28 #if ENABLE(WEBASSEMBLY) 29 29 30 #include "JSCPoison.h" 30 31 #include "JSDestructibleObject.h" 31 32 #include "JSObject.h" 32 33 #include "WasmMemory.h" 34 #include <wtf/Ref.h> 33 35 #include <wtf/RefPtr.h> 34 36 … … 66 68 static void visitChildren(JSCell*, SlotVisitor&); 67 69 68 Ref<Wasm::Memory> m_memory;70 PoisonedRef<JSWebAssemblyMemoryPoison, Wasm::Memory> m_memory; 69 71 WriteBarrier<JSArrayBuffer> m_bufferWrapper; 70 RefPtr<ArrayBuffer> m_buffer;72 PoisonedRefPtr<JSWebAssemblyMemoryPoison, ArrayBuffer> m_buffer; 71 73 }; 72 74 -
trunk/Source/JavaScriptCore/wasm/js/JSWebAssemblyModule.h
r225499 r226485 1 1 /* 2 * Copyright (C) 2016-201 7Apple Inc. All rights reserved.2 * Copyright (C) 2016-2018 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 28 28 #if ENABLE(WEBASSEMBLY) 29 29 30 #include "JSCPoison.h" 30 31 #include "JSDestructibleObject.h" 31 32 #include "JSObject.h" … … 35 36 #include <wtf/Expected.h> 36 37 #include <wtf/Forward.h> 38 #include <wtf/Ref.h> 37 39 #include <wtf/text/WTFString.h> 38 40 … … 80 82 static void visitChildren(JSCell*, SlotVisitor&); 81 83 82 Ref<Wasm::Module> m_module;84 PoisonedRef<JSWebAssemblyModulePoison, Wasm::Module> m_module; 83 85 WriteBarrier<SymbolTable> m_exportSymbolTable; 84 86 WriteBarrier<JSWebAssemblyCodeBlock> m_codeBlocks[Wasm::NumberOfMemoryModes]; -
trunk/Source/JavaScriptCore/wasm/js/JSWebAssemblyTable.h
r223738 r226485 1 1 /* 2 * Copyright (C) 2016-201 7Apple Inc. All rights reserved.2 * Copyright (C) 2016-2018 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 28 28 #if ENABLE(WEBASSEMBLY) 29 29 30 #include "JSCPoison.h" 30 31 #include "JSDestructibleObject.h" 31 32 #include "JSObject.h" … … 35 36 #include "WebAssemblyFunction.h" 36 37 #include <wtf/MallocPtr.h> 38 #include <wtf/Ref.h> 37 39 38 40 namespace JSC { … … 64 66 static void visitChildren(JSCell*, SlotVisitor&); 65 67 66 Ref<Wasm::Table> m_table;68 PoisonedRef<JSWebAssemblyTablePoison, Wasm::Table> m_table; 67 69 MallocPtr<WriteBarrier<JSObject>> m_jsFunctions; 68 70 }; -
trunk/Source/WTF/ChangeLog
r226483 r226485 1 2018-01-05 JF Bastien <jfbastien@apple.com> 2 3 WebAssembly: poison JS object's secrets 4 https://bugs.webkit.org/show_bug.cgi?id=181339 5 <rdar://problem/36325001> 6 7 Reviewed by Mark Lam. 8 9 swapping a poisoned pointer with a non-poisoned one (as is done in 10 JSWebAssembyMemory::adopt) was missing. 11 12 * wtf/Poisoned.h: 13 (WTF::PoisonedImpl::swap): 14 (WTF::ConstExprPoisonedPtrTraits::swap): 15 1 16 2018-01-05 David Kilzer <ddkilzer@apple.com> 2 17 -
trunk/Source/WTF/wtf/Poisoned.h
r226344 r226485 183 183 } 184 184 185 void swap(T& t2) 186 { 187 T t1 = this->unpoisoned(); 188 std::swap(t1, t2); 189 m_poisonedBits = poison(t1); 190 } 191 185 192 template<class U> 186 193 T exchange(U&& newValue) … … 209 216 template<typename K1, K1 k1, typename T1, typename K2, K2 k2, typename T2> 210 217 inline void swap(PoisonedImpl<K1, k1, T1>& a, PoisonedImpl<K2, k2, T2>& b) 218 { 219 a.swap(b); 220 } 221 222 template<typename K1, K1 k1, typename T1> 223 inline void swap(PoisonedImpl<K1, k1, T1>& a, T1& b) 211 224 { 212 225 a.swap(b); … … 242 255 template<class U> static ALWAYS_INLINE T* exchange(StorageType& ptr, U&& newValue) { return ptr.exchange(newValue); } 243 256 257 template<typename K1, K1 k1, typename T1> 258 static ALWAYS_INLINE void swap(PoisonedImpl<K1, k1, T1>& a, T1& b) { a.swap(b); } 259 244 260 template<typename K1, K1 k1, typename T1, typename K2, K2 k2, typename T2> 245 261 static ALWAYS_INLINE void swap(PoisonedImpl<K1, k1, T1>& a, PoisonedImpl<K2, k2, T2>& b) { a.swap(b); } … … 253 269 using WTF::Poisoned; 254 270 using WTF::PoisonedBits; 271 using WTF::makeConstExprPoison; 255 272 using WTF::makePoison; 256 -
trunk/Tools/ChangeLog
r226484 r226485 1 2018-01-05 JF Bastien <jfbastien@apple.com> 2 3 WebAssembly: poison JS object's secrets 4 https://bugs.webkit.org/show_bug.cgi?id=181339 5 <rdar://problem/36325001> 6 7 Reviewed by Mark Lam. 8 9 Update tests for swap(Poisoned<k, T>, T*) 10 11 * TestWebKitAPI/Tests/WTF/ConstExprPoisoned.cpp: 12 (TestWebKitAPI::TEST): 13 * TestWebKitAPI/Tests/WTF/Poisoned.cpp: 14 (TestWebKitAPI::TEST): 15 * TestWebKitAPI/Tests/WTF/PoisonedRef.cpp: 16 (TestWebKitAPI::TEST): 17 1 18 2018-01-05 Wenson Hsieh <wenson_hsieh@apple.com> 2 19 -
trunk/Tools/TestWebKitAPI/Tests/WTF/ConstExprPoisoned.cpp
r226247 r226485 1 1 /* 2 * Copyright (C) 2017 Apple Inc. All rights reserved.2 * Copyright (C) 2017-2018 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 338 338 ASSERT_TRUE(p2.bits() != p4.bits()); 339 339 } 340 341 { 342 ConstExprPoisoned<PoisonA, RefLogger*> p1(&a); 343 RefLogger* p2(&b); 344 ASSERT_EQ(&a, p1.unpoisoned()); 345 ASSERT_EQ(&b, p2); 346 swap(p1, p2); 347 ASSERT_EQ(&b, p1.unpoisoned()); 348 ASSERT_EQ(&a, p2); 349 350 ASSERT_TRUE(p1.bits() != bitwise_cast<uintptr_t>(p2)); 351 } 352 353 { 354 ConstExprPoisoned<PoisonA, RefLogger*> p1(&a); 355 RefLogger* p2(&b); 356 ASSERT_EQ(&a, p1.unpoisoned()); 357 ASSERT_EQ(&b, p2); 358 p1.swap(p2); 359 ASSERT_EQ(&b, p1.unpoisoned()); 360 ASSERT_EQ(&a, p2); 361 362 ASSERT_TRUE(p1.bits() != bitwise_cast<uintptr_t>(p2)); 363 } 340 364 } 341 365 -
trunk/Tools/TestWebKitAPI/Tests/WTF/Poisoned.cpp
r226015 r226485 1 1 /* 2 * Copyright (C) 2017 Apple Inc. All rights reserved.2 * Copyright (C) 2017-2018 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 377 377 #endif 378 378 } 379 380 #if ENABLE(MIXED_POISON) 381 { 382 Poisoned<g_testPoisonA, RefLogger*> p1(&a); 383 RefLogger* p2(&b); 384 ASSERT_EQ(&a, p1.unpoisoned()); 385 ASSERT_EQ(&b, p2); 386 swap(p1, p2); 387 ASSERT_EQ(&b, p1.unpoisoned()); 388 ASSERT_EQ(&a, p2); 389 390 ASSERT_TRUE(p1.bits() != bitwise_cast<uintptr_t>(p2)); 391 } 392 393 { 394 Poisoned<g_testPoisonA, RefLogger*> p1(&a); 395 RefLogger* p2(&b); 396 ASSERT_EQ(&a, p1.unpoisoned()); 397 ASSERT_EQ(&b, p2); 398 p1.swap(p2); 399 ASSERT_EQ(&b, p1.unpoisoned()); 400 ASSERT_EQ(&a, p2); 401 402 ASSERT_TRUE(p1.bits() != bitwise_cast<uintptr_t>(p2)); 403 } 404 #endif 379 405 } 380 406 -
trunk/Tools/TestWebKitAPI/Tests/WTF/PoisonedRef.cpp
r226015 r226485 1 1 /* 2 * Copyright (C) 2017 Apple Inc. All rights reserved.2 * Copyright (C) 2017-2018 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 195 195 } 196 196 EXPECT_STREQ("ref(a) ref(b) | | deref(a) deref(b) ", takeLogStr().c_str()); 197 198 { 199 PoisonedRef<PoisonF, RefLogger> p1(a); 200 Ref<RefLogger> p2(b); 201 log() << "| "; 202 EXPECT_EQ(&a, p1.ptr()); 203 EXPECT_EQ(&b, p2.ptr()); 204 swap(p1, p2); 205 EXPECT_EQ(&b, p1.ptr()); 206 EXPECT_EQ(&a, p2.ptr()); 207 log() << "| "; 208 } 209 EXPECT_STREQ("ref(a) ref(b) | | deref(a) deref(b) ", takeLogStr().c_str()); 210 211 { 212 PoisonedRef<PoisonF, RefLogger> p1(a); 213 Ref<RefLogger> p2(b); 214 log() << "| "; 215 EXPECT_EQ(&a, p1.ptr()); 216 EXPECT_EQ(&b, p2.ptr()); 217 p1.swap(p2); 218 EXPECT_EQ(&b, p1.ptr()); 219 EXPECT_EQ(&a, p2.ptr()); 220 log() << "| "; 221 } 222 EXPECT_STREQ("ref(a) ref(b) | | deref(a) deref(b) ", takeLogStr().c_str()); 197 223 } 198 224
Note:
See TracChangeset
for help on using the changeset viewer.