Changeset 287313 in webkit
- Timestamp:
- Dec 21, 2021, 6:07:08 AM (5 years ago)
- Location:
- trunk/Source/WebKit
- Files:
-
- 2 edited
-
ChangeLog (modified) (1 diff)
-
Platform/IPC/StreamConnectionBuffer.cpp (modified) (3 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/Source/WebKit/ChangeLog
r287296 r287313 1 2021-12-21 Kimmo Kinnunen <kkinnunen@apple.com> 2 3 IPC streams should not accept 0-length stream buffers 4 https://bugs.webkit.org/show_bug.cgi?id=234552 5 <rdar://79725420> 6 7 Reviewed by Antti Koivisto. 8 9 Make decoding 0-length stream buffers fail. These buffers are not useful. 10 11 No new tests, tests need additional implementation, will be added 12 in subsequent commits. 13 14 * Platform/IPC/StreamConnectionBuffer.cpp: 15 (IPC::StreamConnectionBuffer::StreamConnectionBuffer): 16 (IPC::StreamConnectionBuffer::decode): 17 1 18 2021-12-20 Wenson Hsieh <wenson_hsieh@apple.com> 2 19 -
trunk/Source/WebKit/Platform/IPC/StreamConnectionBuffer.cpp
r278253 r287313 43 43 , m_sharedMemory(createMemory(memorySize)) 44 44 { 45 ASSERT(m_dataSize > 0); 45 46 ASSERT(m_dataSize <= maximumSize()); 46 47 } … … 51 52 , m_clientWaitSemaphore(WTFMove(clientWaitSemaphore)) 52 53 { 54 ASSERT(m_dataSize > 0); 53 55 ASSERT(m_dataSize <= maximumSize()); 54 56 } … … 89 91 return std::nullopt; 90 92 size_t dataSize = static_cast<size_t>(ipcHandle->dataSize); 91 if (dataSize < headerSize())93 if (dataSize <= headerSize()) 92 94 return std::nullopt; 93 95 if (dataSize > headerSize() + maximumSize())
Note:
See TracChangeset
for help on using the changeset viewer.