⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 293736 in webkit


Ignore:
Timestamp:
May 3, 2022, 1:18:02 PM (4 years ago)
Author:
sihui_liu@apple.com
Message:

StorageMap::removeItem may fail to remove item from map
​https://bugs.webkit.org/show_bug.cgi?id=239982
rdar://80891555

Reviewed by Chris Dumez.

Source/WebCore:

We may have updated m_impl, but we don't update iterator for removal. In this case, item is not removed from
map, but currentSize is updated. The mismatch between currentSize and actual size of the map may lead to
underflow and overflow in currentSize when item is added or removed later.

Test: storage/domstorage/sessionstorage/window-open-remove-item.html

  • storage/StorageMap.cpp:

(WebCore::StorageMap::removeItem):

LayoutTests:

  • storage/domstorage/sessionstorage/resources/window-open-remove-item.html: Added.
  • storage/domstorage/sessionstorage/window-open-remove-item-expected.txt: Added.
  • storage/domstorage/sessionstorage/window-open-remove-item.html: Added.
Location:
trunk
Files:
3 added
3 edited

Legend:

Unmodified
Added
Removed
  • trunk/LayoutTests/ChangeLog

    r293731 r293736  
     12022-05-03  Sihui Liu  <sihui_liu@apple.com>
     2
     3        StorageMap::removeItem may fail to remove item from map
     4        https://bugs.webkit.org/show_bug.cgi?id=239982
     5        rdar://80891555
     6
     7        Reviewed by Chris Dumez.
     8
     9        * storage/domstorage/sessionstorage/resources/window-open-remove-item.html: Added.
     10        * storage/domstorage/sessionstorage/window-open-remove-item-expected.txt: Added.
     11        * storage/domstorage/sessionstorage/window-open-remove-item.html: Added.
     12
    1132022-05-03  Robert Jenner  <Jenner@apple.com>
    214
  • trunk/Source/WebCore/ChangeLog

    r293735 r293736  
     12022-05-03  Sihui Liu  <sihui_liu@apple.com>
     2
     3        StorageMap::removeItem may fail to remove item from map
     4        https://bugs.webkit.org/show_bug.cgi?id=239982
     5        rdar://80891555
     6
     7        Reviewed by Chris Dumez.
     8
     9        We may have updated m_impl, but we don't update iterator for removal. In this case, item is not removed from
     10        map, but currentSize is updated. The mismatch between currentSize and actual size of the map may lead to
     11        underflow and overflow in currentSize when item is added or removed later.
     12
     13        Test: storage/domstorage/sessionstorage/window-open-remove-item.html
     14
     15        * storage/StorageMap.cpp:
     16        (WebCore::StorageMap::removeItem):
     17
    1182022-05-03  Chris Dumez  <cdumez@apple.com>
    219
  • trunk/Source/WebCore/storage/StorageMap.cpp

    r292836 r293736  
    139139        m_impl = m_impl->copy();
    140140
    141     m_impl->map.remove(iter);
     141    m_impl->map.remove(key);
    142142    m_impl->currentSize = newSize;
    143143    invalidateIterator();
Note: See TracChangeset for help on using the changeset viewer.