⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 294837 in webkit


Ignore:
Timestamp:
May 25, 2022, 4:49:29 PM (4 years ago)
Author:
Alan Coon
Message:

Cherry-pick r293643. rdar://problem/92445366

[Mac] VTVideoDecoderClass object pointers can become unaligned on x86
​https://bugs.webkit.org/show_bug.cgi?id=239916
<rdar://92445366>

Reviewed by Eric Carlson.

Both the base class and the derived class must be 4-byte aligned on x86, or there
is a chance that a pointer member of that struct will cross a page boundary, and
dereferencing that pointer will fail.

  • Source/webrtc/sdk/WebKit/WebKitVP8Decoder.cpp:
  • Source/webrtc/sdk/WebKit/WebKitVP9Decoder.cpp:

Canonical link: ​https://commits.webkit.org/250147@main
git-svn-id: ​https://svn.webkit.org/repository/webkit/trunk@293643 268f45cc-cd09-0410-ab3c-d52691b4dbfc

Location:
branches/safari-613-branch/Source/ThirdParty/libwebrtc
Files:
3 edited

Legend:

Unmodified
Added
Removed
  • branches/safari-613-branch/Source/ThirdParty/libwebrtc/ChangeLog

    r289296 r294837  
     12022-05-19  Alan Coon  <alancoon@apple.com>
     2
     3        Cherry-pick r293643. rdar://problem/92445366
     4
     5    [Mac] VTVideoDecoderClass object pointers can become unaligned on x86
     6    https://bugs.webkit.org/show_bug.cgi?id=239916
     7    <rdar://92445366>
     8   
     9    Reviewed by Eric Carlson.
     10   
     11    Both the base class and the derived class must be 4-byte aligned on x86, or there
     12    is a chance that a pointer member of that struct will cross a page boundary, and
     13    dereferencing that pointer will fail.
     14   
     15    * Source/webrtc/sdk/WebKit/WebKitVP8Decoder.cpp:
     16    * Source/webrtc/sdk/WebKit/WebKitVP9Decoder.cpp:
     17   
     18    Canonical link: https://commits.webkit.org/250147@main
     19    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@293643 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     20
     21    2022-04-30  Jer Noble  <jer.noble@apple.com>
     22
     23            [Mac] VTVideoDecoderClass object pointers can become unaligned on x86
     24            https://bugs.webkit.org/show_bug.cgi?id=239916
     25            <rdar://92445366>
     26
     27            Reviewed by Eric Carlson.
     28
     29            Both the base class and the derived class must be 4-byte aligned on x86, or there
     30            is a chance that a pointer member of that struct will cross a page boundary, and
     31            dereferencing that pointer will fail.
     32
     33            * Source/webrtc/sdk/WebKit/WebKitVP8Decoder.cpp:
     34            * Source/webrtc/sdk/WebKit/WebKitVP9Decoder.cpp:
     35
    1362022-02-07  Russell Epstein  <repstein@apple.com>
    237
  • branches/safari-613-branch/Source/ThirdParty/libwebrtc/Source/webrtc/sdk/WebKit/WebKitVP8Decoder.cpp

    r285577 r294837  
    5656
    5757#pragma pack(push, 4)
    58 struct DecoderClass {
     58struct DecoderBaseClass {
    5959    uint8_t pad[padSize];
    6060    CMBaseClass alignedClass;
    6161};
    6262
    63 static const DecoderClass WebKitVP8Decoder_BaseClass {
     63static const DecoderBaseClass WebKitVP8Decoder_BaseClass {
    6464    { },
    6565    {
    … …  
    8383    static_assert(sizeof(WebKitVP8Decoder_BaseClass.alignedClass.version) == sizeof(uintptr_t), "CMBaseClass fixup is not required!");
    8484#endif
     85static_assert(offsetof(DecoderBaseClass, alignedClass) == padSize, "CMBaseClass offset is incorrect!");
     86static_assert(alignof(DecoderBaseClass) == 4, "CMBaseClass must have 4 byte alignment");
     87
     88static OSStatus startVP8DecoderSession(VTVideoDecoderRef, VTVideoDecoderSession, CMVideoFormatDescriptionRef);
     89static OSStatus decodeVP8DecoderFrame(VTVideoDecoderRef, VTVideoDecoderFrame, CMSampleBufferRef, VTDecodeFrameFlags, VTDecodeInfoFlags*);
     90
     91#pragma pack(push, 4)
     92struct DecoderClass {
     93    uint8_t pad[padSize];
     94    VTVideoDecoderClass alignedClass;
     95};
     96
     97static const DecoderClass WebKitVP8Decoder_VideoDecoderClass =
     98{
     99    { },
     100    {
     101        kVTVideoDecoder_ClassVersion_1,
     102        startVP8DecoderSession,
     103        decodeVP8DecoderFrame,
     104        nullptr, // VTVideoDecoderFunction_CopySupportedPropertyDictionary,
     105        nullptr, // VTVideoDecoderFunction_SetProperties
     106        nullptr, // VTVideoDecoderFunction_CopySerializableProperties
     107        nullptr, // VTVideoDecoderFunction_CanAcceptFormatDescription
     108        nullptr, // VTVideoDecoderFunction_FinishDelayedFrames
     109        nullptr, // VTVideoDecoderFunction_StartTileSession
     110        nullptr, // VTVideoDecoderFunction_DecodeTile
     111        nullptr // VTVideoDecoderFunction_FinishDelayedTiles
     112    }
     113};
     114#pragma pack(pop)
     115
     116#if defined(CMBASE_OBJECT_NEEDS_ALIGNMENT) && CMBASE_OBJECT_NEEDS_ALIGNMENT
     117    static_assert(sizeof(WebKitVP8Decoder_VideoDecoderClass.alignedClass.version) == sizeof(uint32_t), "CMBaseClass fixup is required!");
     118#else
     119    static_assert(sizeof(WebKitVP8Decoder_VideoDecoderClass.alignedClass.version) == sizeof(uintptr_t), "CMBaseClass fixup is not required!");
     120#endif
    85121static_assert(offsetof(DecoderClass, alignedClass) == padSize, "CMBaseClass offset is incorrect!");
    86122static_assert(alignof(DecoderClass) == 4, "CMBaseClass must have 4 byte alignment");
    87123
    88 static OSStatus startVP8DecoderSession(VTVideoDecoderRef, VTVideoDecoderSession, CMVideoFormatDescriptionRef);
    89 static OSStatus decodeVP8DecoderFrame(VTVideoDecoderRef, VTVideoDecoderFrame, CMSampleBufferRef, VTDecodeFrameFlags, VTDecodeInfoFlags*);
    90 
    91 static const VTVideoDecoderClass WebKitVP8Decoder_VideoDecoderClass =
    92 {
    93     kVTVideoDecoder_ClassVersion_1,
    94     startVP8DecoderSession,
    95     decodeVP8DecoderFrame,
    96     nullptr, // VTVideoDecoderFunction_CopySupportedPropertyDictionary,
    97     nullptr, // VTVideoDecoderFunction_SetProperties
    98     nullptr, // VTVideoDecoderFunction_CopySerializableProperties
    99     nullptr, // VTVideoDecoderFunction_CanAcceptFormatDescription
    100     nullptr, // VTVideoDecoderFunction_FinishDelayedFrames
    101     nullptr, // VTVideoDecoderFunction_StartTileSession
    102     nullptr, // VTVideoDecoderFunction_DecodeTile
    103     nullptr // VTVideoDecoderFunction_FinishDelayedTiles
    104 };
    105 
    106124static const VTVideoDecoderVTable WebKitVP8DecoderVTable =
    107125{
    108126    { nullptr, &WebKitVP8Decoder_BaseClass.alignedClass },
    109     &WebKitVP8Decoder_VideoDecoderClass
     127    &WebKitVP8Decoder_VideoDecoderClass.alignedClass
    110128};
    111129
  • branches/safari-613-branch/Source/ThirdParty/libwebrtc/Source/webrtc/sdk/WebKit/WebKitVP9Decoder.cpp

    r285577 r294837  
    5656
    5757#pragma pack(push, 4)
    58 struct DecoderClass {
     58struct DecoderBaseClass {
    5959    uint8_t pad[padSize];
    6060    CMBaseClass alignedClass;
    6161};
    6262
    63 static const DecoderClass WebKitVP9Decoder_BaseClass {
     63static const DecoderBaseClass WebKitVP9Decoder_BaseClass {
    6464    { },
    6565    {
    … …  
    8383    static_assert(sizeof(WebKitVP9Decoder_BaseClass.alignedClass.version) == sizeof(uintptr_t), "CMBaseClass fixup is not required!");
    8484#endif
    85 static_assert(offsetof(DecoderClass, alignedClass) == padSize, "CMBaseClass offset is incorrect!");
    86 static_assert(alignof(DecoderClass) == 4, "CMBaseClass must have 4 byte alignment");
     85static_assert(offsetof(DecoderBaseClass, alignedClass) == padSize, "CMBaseClass offset is incorrect!");
     86static_assert(alignof(DecoderBaseClass) == 4, "CMBaseClass must have 4 byte alignment");
    8787
    8888static OSStatus startVP9DecoderSession(VTVideoDecoderRef, VTVideoDecoderSession, CMVideoFormatDescriptionRef);
    8989static OSStatus decodeVP9DecoderFrame(VTVideoDecoderRef, VTVideoDecoderFrame, CMSampleBufferRef, VTDecodeFrameFlags, VTDecodeInfoFlags*);
    9090
    91 static const VTVideoDecoderClass WebKitVP9Decoder_VideoDecoderClass =
    92 {
    93     kVTVideoDecoder_ClassVersion_1,
    94     startVP9DecoderSession,
    95     decodeVP9DecoderFrame,
    96     nullptr, // VTVideoDecoderFunction_CopySupportedPropertyDictionary,
    97     nullptr, // VTVideoDecoderFunction_SetProperties
    98     nullptr, // VTVideoDecoderFunction_CopySerializableProperties
    99     nullptr, // VTVideoDecoderFunction_CanAcceptFormatDescription
    100     nullptr, // VTVideoDecoderFunction_FinishDelayedFrames
    101     nullptr, // VTVideoDecoderFunction_StartTileSession
    102     nullptr, // VTVideoDecoderFunction_DecodeTile
    103     nullptr // VTVideoDecoderFunction_FinishDelayedTiles
    104 };
     91#pragma pack(push, 4)
     92struct DecoderClass {
     93    uint8_t pad[padSize];
     94    VTVideoDecoderClass alignedClass;
     95};
     96
     97static const DecoderClass WebKitVP9Decoder_VideoDecoderClass =
     98{
     99    { },
     100    {
     101        kVTVideoDecoder_ClassVersion_1,
     102        startVP9DecoderSession,
     103        decodeVP9DecoderFrame,
     104        nullptr, // VTVideoDecoderFunction_CopySupportedPropertyDictionary,
     105        nullptr, // VTVideoDecoderFunction_SetProperties
     106        nullptr, // VTVideoDecoderFunction_CopySerializableProperties
     107        nullptr, // VTVideoDecoderFunction_CanAcceptFormatDescription
     108        nullptr, // VTVideoDecoderFunction_FinishDelayedFrames
     109        nullptr, // VTVideoDecoderFunction_StartTileSession
     110        nullptr, // VTVideoDecoderFunction_DecodeTile
     111        nullptr // VTVideoDecoderFunction_FinishDelayedTiles
     112    }
     113};
     114#pragma pack(pop)
    105115
    106116static const VTVideoDecoderVTable WebKitVP9DecoderVTable =
    107117{
    108118    { nullptr, &WebKitVP9Decoder_BaseClass.alignedClass },
    109     &WebKitVP9Decoder_VideoDecoderClass
     119    &WebKitVP9Decoder_VideoDecoderClass.alignedClass
    110120};
    111121
Note: See TracChangeset for help on using the changeset viewer.