⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 254559 in webkit


Ignore:
Timestamp:
Jan 14, 2020, 10:32:01 PM (7 years ago)
Author:
Alan Bujtas
Message:

Long continuation chain could lead to stack exhaustion
​https://bugs.webkit.org/show_bug.cgi?id=206271
<rdar://problem/41189798>

Reviewed by Simon Fraser.

Source/WebCore:

This patch replaces the recursive approach with an iterative one
to collect absolute quads across continuation.

Test: fast/inline/long-continuation-crash.html

  • rendering/RenderBlock.cpp:

(WebCore::RenderBlock::absoluteQuads const):
(WebCore::RenderBlock::absoluteQuadsIgnoringContinuation const):

  • rendering/RenderBlock.h:
  • rendering/RenderBoxModelObject.cpp:

(WebCore::RenderBoxModelObject::collectAbsoluteQuadsForContinuation const):

  • rendering/RenderBoxModelObject.h:

(WebCore::RenderBoxModelObject::absoluteQuadsIgnoringContinuation const):

  • rendering/RenderInline.cpp:

(WebCore::RenderInline::absoluteQuads const):
(WebCore::RenderInline::absoluteQuadsIgnoringContinuation const):

  • rendering/RenderInline.h:

LayoutTests:

  • fast/inline/long-continuation-crash.html: Added.
Location:
trunk
Files:
2 added
8 edited

Legend:

Unmodified
Added
Removed
  • trunk/LayoutTests/ChangeLog

    r254555 r254559  
     12020-01-14  Zalan Bujtas  <zalan@apple.com>
     2
     3        Long continuation chain could lead to stack exhaustion
     4        https://bugs.webkit.org/show_bug.cgi?id=206271
     5        <rdar://problem/41189798>
     6
     7        Reviewed by Simon Fraser.
     8
     9        * fast/inline/long-continuation-crash.html: Added.
     10
    1112020-01-14  Peng Liu  <peng.liu6@apple.com>
    212
  • trunk/Source/WebCore/ChangeLog

    r254557 r254559  
     12020-01-14  Zalan Bujtas  <zalan@apple.com>
     2
     3        Long continuation chain could lead to stack exhaustion
     4        https://bugs.webkit.org/show_bug.cgi?id=206271
     5        <rdar://problem/41189798>
     6
     7        Reviewed by Simon Fraser.
     8
     9        This patch replaces the recursive approach with an iterative one
     10        to collect absolute quads across continuation.
     11
     12        Test: fast/inline/long-continuation-crash.html
     13
     14        * rendering/RenderBlock.cpp:
     15        (WebCore::RenderBlock::absoluteQuads const):
     16        (WebCore::RenderBlock::absoluteQuadsIgnoringContinuation const):
     17        * rendering/RenderBlock.h:
     18        * rendering/RenderBoxModelObject.cpp:
     19        (WebCore::RenderBoxModelObject::collectAbsoluteQuadsForContinuation const):
     20        * rendering/RenderBoxModelObject.h:
     21        (WebCore::RenderBoxModelObject::absoluteQuadsIgnoringContinuation const):
     22        * rendering/RenderInline.cpp:
     23        (WebCore::RenderInline::absoluteQuads const):
     24        (WebCore::RenderInline::absoluteQuadsIgnoringContinuation const):
     25        * rendering/RenderInline.h:
     26
    1272020-01-14  Ryosuke Niwa  <rniwa@webkit.org>
    228
  • trunk/Source/WebCore/rendering/RenderBlock.cpp

    r254421 r254559  
    27822782void RenderBlock::absoluteQuads(Vector<FloatQuad>& quads, bool* wasFixed) const
    27832783{
     2784    if (!continuation()) {
     2785        absoluteQuadsIgnoringContinuation({ { }, size() }, quads, wasFixed);
     2786        return;
     2787    }
    27842788    // For blocks inside inlines, we include margins so that we run right up to the inline boxes
    27852789    // above and below us (thus getting merged with them to form a single irregular shape).
    2786     auto* continuation = this->continuation();
    2787     FloatRect localRect = continuation
    2788         ? FloatRect(0, -collapsedMarginBefore(), width(), height() + collapsedMarginBefore() + collapsedMarginAfter())
    2789         : FloatRect(0, 0, width(), height());
    2790    
     2790    auto logicalRect = FloatRect { 0, -collapsedMarginBefore(), width(), height() + collapsedMarginBefore() + collapsedMarginAfter() };
     2791    absoluteQuadsIgnoringContinuation(logicalRect, quads, wasFixed);
     2792    collectAbsoluteQuadsForContinuation(quads, wasFixed);
     2793}
     2794
     2795void RenderBlock::absoluteQuadsIgnoringContinuation(const FloatRect& logicalRect, Vector<FloatQuad>& quads, bool* wasFixed) const
     2796{
    27912797    // FIXME: This is wrong for block-flows that are horizontal.
    27922798    // https://bugs.webkit.org/show_bug.cgi?id=46781
    2793     RenderFragmentedFlow* fragmentedFlow = enclosingFragmentedFlow();
    2794     if (!fragmentedFlow || !fragmentedFlow->absoluteQuadsForBox(quads, wasFixed, this, localRect.y(), localRect.maxY()))
    2795         quads.append(localToAbsoluteQuad(localRect, UseTransforms, wasFixed));
    2796 
    2797     if (continuation)
    2798         continuation->absoluteQuads(quads, wasFixed);
     2799    auto* fragmentedFlow = enclosingFragmentedFlow();
     2800    if (!fragmentedFlow || !fragmentedFlow->absoluteQuadsForBox(quads, wasFixed, this, logicalRect.y(), logicalRect.maxY()))
     2801        quads.append(localToAbsoluteQuad(logicalRect, UseTransforms, wasFixed));
    27992802}
    28002803
  • trunk/Source/WebCore/rendering/RenderBlock.h

    r254087 r254559  
    494494    void removePositionedObjectsIfNeeded(const RenderStyle& oldStyle, const RenderStyle& newStyle);
    495495
     496    void absoluteQuadsIgnoringContinuation(const FloatRect&, Vector<FloatQuad>&, bool* wasFixed) const override;
     497
    496498private:
    497499    bool hasRareData() const;
  • trunk/Source/WebCore/rendering/RenderBoxModelObject.cpp

    r254087 r254559  
    26962696}
    26972697
     2698void RenderBoxModelObject::collectAbsoluteQuadsForContinuation(Vector<FloatQuad>& quads, bool* wasFixed) const
     2699{
     2700    ASSERT(continuation());
     2701    for (auto* nextInContinuation = this->continuation(); nextInContinuation; nextInContinuation = nextInContinuation->continuation()) {
     2702        if (is<RenderBlock>(*nextInContinuation)) {
     2703            auto& blockBox = downcast<RenderBlock>(*nextInContinuation);
     2704            // For blocks inside inlines, we include margins so that we run right up to the inline boxes
     2705            // above and below us (thus getting merged with them to form a single irregular shape).
     2706            auto logicalRect = FloatRect { 0, -blockBox.collapsedMarginBefore(), blockBox.width(),
     2707                blockBox.height() + blockBox.collapsedMarginBefore() + blockBox.collapsedMarginAfter() };
     2708            nextInContinuation->absoluteQuadsIgnoringContinuation(logicalRect, quads, wasFixed);
     2709            continue;
     2710        }
     2711        nextInContinuation->absoluteQuadsIgnoringContinuation({ }, quads, wasFixed);
     2712    }
     2713}
     2714
    26982715} // namespace WebCore
  • trunk/Source/WebCore/rendering/RenderBoxModelObject.h

    r252965 r254559  
    295295protected:
    296296    LayoutUnit computedCSSPadding(const Length&) const;
     297    virtual void absoluteQuadsIgnoringContinuation(const FloatRect&, Vector<FloatQuad>&, bool* /*wasFixed*/) const { ASSERT_NOT_REACHED(); }
     298    void collectAbsoluteQuadsForContinuation(Vector<FloatQuad>& quads, bool* wasFixed) const;
    297299
    298300private:
  • trunk/Source/WebCore/rendering/RenderInline.cpp

    r254087 r254559  
    413413void RenderInline::absoluteQuads(Vector<FloatQuad>& quads, bool* wasFixed) const
    414414{
     415    absoluteQuadsIgnoringContinuation({ }, quads, wasFixed);
     416    if (continuation())
     417        collectAbsoluteQuadsForContinuation(quads, wasFixed);
     418}
     419
     420void RenderInline::absoluteQuadsIgnoringContinuation(const FloatRect&, Vector<FloatQuad>& quads, bool*) const
     421{
    415422    AbsoluteQuadsGeneratorContext context(this, quads);
    416423    generateLineBoxRects(context);
    417 
    418     if (RenderBoxModelObject* continuation = this->continuation())
    419         continuation->absoluteQuads(quads, wasFixed);
    420424}
    421425
  • trunk/Source/WebCore/rendering/RenderInline.h

    r246285 r254559  
    110110    InlineBox* culledInlineLastLineBox() const;
    111111
     112    void absoluteQuadsIgnoringContinuation(const FloatRect&, Vector<FloatQuad>&, bool* wasFixed) const override;
     113
    112114    template<typename GeneratorContext>
    113115    void generateLineBoxRects(GeneratorContext& yield) const;
Note: See TracChangeset for help on using the changeset viewer.