⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 278782 in webkit


Ignore:
Timestamp:
Jun 11, 2021, 2:21:31 PM (5 years ago)
Author:
ysuzuki@apple.com
Message:

Add fast-path for binding security check of DOMWindow
​https://bugs.webkit.org/show_bug.cgi?id=226930

Reviewed by Geoffrey Garen.

The security check[1] must pass if the current JSDOMGlobalObject is the same to the accessed JSDOMWindow.
This clarification paves the way to emit JIT code which removes this security check when the lexical and
accessed JSGlobalObjects are the same.

[1]: ​https://html.spec.whatwg.org/multipage/browsers.html#integration-with-idl

  • bindings/js/JSDOMBindingSecurity.cpp:

(WebCore::BindingSecurity::shouldAllowAccessToDOMWindow):

  • bindings/js/JSDOMBindingSecurity.h:
  • bindings/scripts/CodeGeneratorJS.pm:

(GenerateAttributeGetterBodyDefinition):
(GenerateAttributeSetterBodyDefinition):
(GenerateOperationBodyDefinition):

Location:
trunk/Source/WebCore
Files:
1 added
3 edited

Legend:

Unmodified
Added
Removed
  • trunk/Source/WebCore/ChangeLog

    r278780 r278782  
     12021-06-11  Yusuke Suzuki  <ysuzuki@apple.com>
     2
     3        Add fast-path for binding security check of DOMWindow
     4        https://bugs.webkit.org/show_bug.cgi?id=226930
     5
     6        Reviewed by Geoffrey Garen.
     7
     8        The security check[1] must pass if the current JSDOMGlobalObject is the same to the accessed JSDOMWindow.
     9        This clarification paves the way to emit JIT code which removes this security check when the lexical and
     10        accessed JSGlobalObjects are the same.
     11
     12        [1]: https://html.spec.whatwg.org/multipage/browsers.html#integration-with-idl
     13
     14        * bindings/js/JSDOMBindingSecurity.cpp:
     15        (WebCore::BindingSecurity::shouldAllowAccessToDOMWindow):
     16        * bindings/js/JSDOMBindingSecurity.h:
     17        * bindings/scripts/CodeGeneratorJS.pm:
     18        (GenerateAttributeGetterBodyDefinition):
     19        (GenerateAttributeSetterBodyDefinition):
     20        (GenerateOperationBodyDefinition):
     21
    1222021-06-11  Jonathan Bedard  <jbedard@apple.com>
    223
  • trunk/Source/WebCore/WebCore.xcodeproj/project.pbxproj

    r278738 r278782  
    51845184                E3C99A091DC3D41C00794AD3 /* DOMJITCheckDOM.h in Headers */ = {isa = PBXBuildFile; fileRef = E3C99A081DC3D41700794AD3 /* DOMJITCheckDOM.h */; };
    51855185                E3C9AECB2113149900419B92 /* JSMicrotaskCallback.h in Headers */ = {isa = PBXBuildFile; fileRef = E3C9AEC92113147400419B92 /* JSMicrotaskCallback.h */; };
     5186                E3CA0BFC2673F47C009FDD67 /* JSDOMBindingSecurityInlines.h in Headers */ = {isa = PBXBuildFile; fileRef = E3CA0BFA2673F478009FDD67 /* JSDOMBindingSecurityInlines.h */; settings = {ATTRIBUTES = (Private, ); }; };
    51865187                E3E4E2A81E3B17100023BB8A /* ScriptElementCachedScriptFetcher.h in Headers */ = {isa = PBXBuildFile; fileRef = E3E4E2A61E3B16FC0023BB8A /* ScriptElementCachedScriptFetcher.h */; settings = {ATTRIBUTES = (Private, ); }; };
    51875188                E3FA38641D71812D00AA5950 /* PendingScriptClient.h in Headers */ = {isa = PBXBuildFile; fileRef = E3FA38611D716E7600AA5950 /* PendingScriptClient.h */; };
    … …  
    1653016531                E3C99A081DC3D41700794AD3 /* DOMJITCheckDOM.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = DOMJITCheckDOM.h; sourceTree = "<group>"; };
    1653116532                E3C9AEC92113147400419B92 /* JSMicrotaskCallback.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = JSMicrotaskCallback.h; sourceTree = "<group>"; };
     16533                E3CA0BFA2673F478009FDD67 /* JSDOMBindingSecurityInlines.h */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.c.h; path = JSDOMBindingSecurityInlines.h; sourceTree = "<group>"; };
    1653216534                E3D049931DADC04500718F3C /* NodeConstants.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = NodeConstants.h; sourceTree = "<group>"; };
    1653316535                E3E4E2A51E3B16FC0023BB8A /* ScriptElementCachedScriptFetcher.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = ScriptElementCachedScriptFetcher.cpp; sourceTree = "<group>"; };
    … …  
    2749227494                                7C45C9CA1E3E8D2E00AAB558 /* JSDOMBindingSecurity.cpp */,
    2749327495                                7C45C9C91E3E8CD700AAB558 /* JSDOMBindingSecurity.h */,
     27496                                E3CA0BFA2673F478009FDD67 /* JSDOMBindingSecurityInlines.h */,
    2749427497                                841C4414260C38BA00FF6673 /* JSDOMCastThisValue.h */,
    2749527498                                7C45C9CC1E3E8F0800AAB558 /* JSDOMExceptionHandling.cpp */,
    … …  
    3264132644                                E0FEF372B17C53EAC1C1FBEE /* EventSource.h in Headers */,
    3264232645                                E12EDB7B0B308A78002704B6 /* EventTarget.h in Headers */,
     32646                                E3CA0BFC2673F47C009FDD67 /* JSDOMBindingSecurityInlines.h in Headers */,
    3264332647                                84B349A222F86E7500D47BCF /* EventTargetConcrete.h in Headers */,
    3264432648                                97AA3CA5145237CC003E1DA6 /* EventTargetHeaders.h in Headers */,
  • trunk/Source/WebCore/bindings/scripts/CodeGeneratorJS.pm

    r278645 r278782  
    52115211
    52125212    if ($needSecurityCheck) {
    5213         AddToImplIncludes("JSDOMBindingSecurity.h", $conditional);
    52145213        if ($interface->type->name eq "DOMWindow") {
    5215             push(@$outputArray, "    bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(&lexicalGlobalObject, thisObject.wrapped(), ThrowSecurityError);\n");
     5214            AddToImplIncludes("JSDOMBindingSecurityInlines.h", $conditional);
     5215            push(@$outputArray, "    bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(&lexicalGlobalObject, thisObject, ThrowSecurityError);\n");
    52165216        } else {
     5217            AddToImplIncludes("JSDOMBindingSecurity.h", $conditional);
    52175218            push(@$outputArray, "    bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(&lexicalGlobalObject, thisObject.wrapped().window(), ThrowSecurityError);\n");
    52185219        }
    … …  
    53685369
    53695370    if ($needSecurityCheck) {
    5370         AddToImplIncludes("JSDOMBindingSecurity.h", $conditional);
    53715371        if ($interface->type->name eq "DOMWindow") {
    5372             push(@$outputArray, "    bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(&lexicalGlobalObject, thisObject.wrapped(), ThrowSecurityError);\n");
     5372            AddToImplIncludes("JSDOMBindingSecurityInlines.h", $conditional);
     5373            push(@$outputArray, "    bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(&lexicalGlobalObject, thisObject, ThrowSecurityError);\n");
    53735374        } else {
     5375            AddToImplIncludes("JSDOMBindingSecurity.h", $conditional);
    53745376            push(@$outputArray, "    bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(&lexicalGlobalObject, thisObject.wrapped().window(), ThrowSecurityError);\n");
    53755377        }
    … …  
    55805582            assert("Security checks are not supported for static operations.") if $operation->isStatic;
    55815583           
    5582             AddToImplIncludes("JSDOMBindingSecurity.h", $conditional);
    55835584            if ($interface->type->name eq "DOMWindow") {
    5584                 push(@$outputArray, "    bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(lexicalGlobalObject, castedThis->wrapped(), ThrowSecurityError);\n");
     5585                AddToImplIncludes("JSDOMBindingSecurityInlines.h", $conditional);
     5586                push(@$outputArray, "    bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(lexicalGlobalObject, *castedThis, ThrowSecurityError);\n");
    55855587            } else {
     5588                AddToImplIncludes("JSDOMBindingSecurity.h", $conditional);
    55865589                push(@$outputArray, "    bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(lexicalGlobalObject, castedThis->wrapped().window(), ThrowSecurityError);\n");
    55875590            }
Note: See TracChangeset for help on using the changeset viewer.