⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 287313 in webkit


Ignore:
Timestamp:
Dec 21, 2021, 6:07:08 AM (5 years ago)
Author:
commit-queue@webkit.org
Message:

IPC streams should not accept 0-length stream buffers
​https://bugs.webkit.org/show_bug.cgi?id=234552
<rdar://79725420>

Patch by Kimmo Kinnunen <​kkinnunen@apple.com> on 2021-12-21
Reviewed by Antti Koivisto.

Make decoding 0-length stream buffers fail. These buffers are not useful.

No new tests, tests need additional implementation, will be added
in subsequent commits.

  • Platform/IPC/StreamConnectionBuffer.cpp:

(IPC::StreamConnectionBuffer::StreamConnectionBuffer):
(IPC::StreamConnectionBuffer::decode):

Location:
trunk/Source/WebKit
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • trunk/Source/WebKit/ChangeLog

    r287296 r287313  
     12021-12-21  Kimmo Kinnunen  <kkinnunen@apple.com>
     2
     3        IPC streams should not accept 0-length stream buffers
     4        https://bugs.webkit.org/show_bug.cgi?id=234552
     5        <rdar://79725420>
     6
     7        Reviewed by Antti Koivisto.
     8
     9        Make decoding 0-length stream buffers fail. These buffers are not useful.
     10
     11        No new tests, tests need additional implementation, will be added
     12        in subsequent commits.
     13
     14        * Platform/IPC/StreamConnectionBuffer.cpp:
     15        (IPC::StreamConnectionBuffer::StreamConnectionBuffer):
     16        (IPC::StreamConnectionBuffer::decode):
     17
    1182021-12-20  Wenson Hsieh  <wenson_hsieh@apple.com>
    219
  • trunk/Source/WebKit/Platform/IPC/StreamConnectionBuffer.cpp

    r278253 r287313  
    4343    , m_sharedMemory(createMemory(memorySize))
    4444{
     45    ASSERT(m_dataSize > 0);
    4546    ASSERT(m_dataSize <= maximumSize());
    4647}
    … …  
    5152    , m_clientWaitSemaphore(WTFMove(clientWaitSemaphore))
    5253{
     54    ASSERT(m_dataSize > 0);
    5355    ASSERT(m_dataSize <= maximumSize());
    5456}
    … …  
    8991        return std::nullopt;
    9092    size_t dataSize = static_cast<size_t>(ipcHandle->dataSize);
    91     if (dataSize < headerSize())
     93    if (dataSize <= headerSize())
    9294        return std::nullopt;
    9395    if (dataSize > headerSize() + maximumSize())
Note: See TracChangeset for help on using the changeset viewer.