Changeset 225659 in webkit
- Timestamp:
- Dec 7, 2017, 5:22:06 PM (9 years ago)
- Location:
- trunk/Source
- Files:
-
- 1 added
- 21 edited
-
JavaScriptCore/API/JSCallbackFunction.h (modified) (2 diffs)
-
JavaScriptCore/ChangeLog (modified) (1 diff)
-
JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj (modified) (4 diffs)
-
JavaScriptCore/b3/B3LowerMacros.cpp (modified) (1 diff)
-
JavaScriptCore/b3/testb3.cpp (modified) (1 diff)
-
JavaScriptCore/dfg/DFGSpeculativeJIT.cpp (modified) (2 diffs)
-
JavaScriptCore/ftl/FTLLowerDFGToB3.cpp (modified) (1 diff)
-
JavaScriptCore/jit/ThunkGenerators.cpp (modified) (4 diffs)
-
JavaScriptCore/llint/LowLevelInterpreter64.asm (modified) (3 diffs)
-
JavaScriptCore/runtime/CustomGetterSetter.h (modified) (4 diffs)
-
JavaScriptCore/runtime/InternalFunction.cpp (modified) (2 diffs)
-
JavaScriptCore/runtime/InternalFunction.h (modified) (5 diffs)
-
JavaScriptCore/runtime/JSCPoison.h (added)
-
JavaScriptCore/runtime/JSCPoisonedPtr.cpp (modified) (2 diffs)
-
JavaScriptCore/runtime/JSCPoisonedPtr.h (modified) (1 diff)
-
JavaScriptCore/runtime/NativeExecutable.cpp (modified) (2 diffs)
-
JavaScriptCore/runtime/NativeExecutable.h (modified) (3 diffs)
-
JavaScriptCore/runtime/Structure.cpp (modified) (1 diff)
-
JavaScriptCore/runtime/StructureTransitionTable.h (modified) (5 diffs)
-
WTF/ChangeLog (modified) (1 diff)
-
WTF/wtf/Poisoned.cpp (modified) (1 diff)
-
WTF/wtf/Poisoned.h (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/Source/JavaScriptCore/API/JSCallbackFunction.h
r224487 r225659 1 1 /* 2 * Copyright (C) 2006 , 2008Apple Inc. All rights reserved.2 * Copyright (C) 2006-2017 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 52 52 void finishCreation(VM&, const String& name); 53 53 54 JSObjectCallAsFunctionCallback functionCallback() { return m_callback ; }54 JSObjectCallAsFunctionCallback functionCallback() { return m_callback.unpoisoned(); } 55 55 56 JSObjectCallAsFunctionCallbackm_callback;56 Poisoned<g_nativeCodePoison, JSObjectCallAsFunctionCallback> m_callback; 57 57 }; 58 58 -
trunk/Source/JavaScriptCore/ChangeLog
r225654 r225659 1 2017-12-07 Mark Lam <mark.lam@apple.com> 2 3 Apply poisoning to some native code pointers. 4 https://bugs.webkit.org/show_bug.cgi?id=180541 5 <rdar://problem/35916875> 6 7 Reviewed by Filip Pizlo. 8 9 Renamed g_classInfoPoison to g_globalDataPoison. 10 Renamed g_masmPoison to g_jitCodePoison. 11 Introduced g_nativeCodePoison. 12 Applied g_nativeCodePoison to poisoning some native code pointers. 13 14 Introduced non-random Int32 poison values (in JSCPoison.h) for use with pointers 15 to malloc allocated data structures (where needed). 16 17 * API/JSCallbackFunction.h: 18 (JSC::JSCallbackFunction::functionCallback): 19 * JavaScriptCore.xcodeproj/project.pbxproj: 20 * jit/ThunkGenerators.cpp: 21 (JSC::nativeForGenerator): 22 * llint/LowLevelInterpreter64.asm: 23 * runtime/CustomGetterSetter.h: 24 (JSC::CustomGetterSetter::getter const): 25 (JSC::CustomGetterSetter::setter const): 26 * runtime/InternalFunction.cpp: 27 (JSC::InternalFunction::getCallData): 28 (JSC::InternalFunction::getConstructData): 29 * runtime/InternalFunction.h: 30 (JSC::InternalFunction::nativeFunctionFor): 31 * runtime/JSCPoison.h: Added. 32 * runtime/JSCPoisonedPtr.cpp: 33 (JSC::initializePoison): 34 * runtime/JSCPoisonedPtr.h: 35 * runtime/Lookup.h: 36 * runtime/NativeExecutable.cpp: 37 (JSC::NativeExecutable::hashFor const): 38 * runtime/NativeExecutable.h: 39 * runtime/Structure.cpp: 40 (JSC::StructureTransitionTable::setSingleTransition): 41 * runtime/StructureTransitionTable.h: 42 (JSC::StructureTransitionTable::StructureTransitionTable): 43 (JSC::StructureTransitionTable::isUsingSingleSlot const): 44 (JSC::StructureTransitionTable::map const): 45 (JSC::StructureTransitionTable::weakImpl const): 46 (JSC::StructureTransitionTable::setMap): 47 1 48 2017-12-07 Joseph Pecoraro <pecoraro@apple.com> 2 49 -
trunk/Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj
r225632 r225659 1722 1722 FE2A87601F02381600EB31B2 /* MinimumReservedZoneSize.h in Headers */ = {isa = PBXBuildFile; fileRef = FE2A875F1F02381600EB31B2 /* MinimumReservedZoneSize.h */; }; 1723 1723 FE2B0B691FD227E00075DA5F /* JSCPoisonedPtr.h in Headers */ = {isa = PBXBuildFile; fileRef = FE2B0B671FD0D2960075DA5F /* JSCPoisonedPtr.h */; settings = {ATTRIBUTES = (Private, ); }; }; 1724 FE2B0B731FD9EF700075DA5F /* JSCPoison.h in Headers */ = {isa = PBXBuildFile; fileRef = FE2B0B701FD8C4630075DA5F /* JSCPoison.h */; settings = {ATTRIBUTES = (Private, ); }; }; 1724 1725 FE3022D31E3D73A500BAC493 /* SigillCrashAnalyzer.h in Headers */ = {isa = PBXBuildFile; fileRef = FE3022D11E3D739600BAC493 /* SigillCrashAnalyzer.h */; settings = {ATTRIBUTES = (Private, ); }; }; 1725 1726 FE3022D71E42857300BAC493 /* VMInspector.h in Headers */ = {isa = PBXBuildFile; fileRef = FE3022D51E42856700BAC493 /* VMInspector.h */; }; … … 4601 4602 FE2B0B671FD0D2960075DA5F /* JSCPoisonedPtr.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = JSCPoisonedPtr.h; sourceTree = "<group>"; }; 4602 4603 FE2B0B681FD0D2970075DA5F /* JSCPoisonedPtr.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = JSCPoisonedPtr.cpp; sourceTree = "<group>"; }; 4604 FE2B0B701FD8C4630075DA5F /* JSCPoison.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = JSCPoison.h; sourceTree = "<group>"; }; 4603 4605 FE2E6A7A1D6EA5FE0060F896 /* ThrowScope.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = ThrowScope.cpp; sourceTree = "<group>"; }; 4604 4606 FE3022D01E3D739600BAC493 /* SigillCrashAnalyzer.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = SigillCrashAnalyzer.cpp; sourceTree = "<group>"; }; … … 6544 6546 14ABB36E099C076400E2A24F /* JSCJSValue.h */, 6545 6547 865A30F0135007E100CDB49E /* JSCJSValueInlines.h */, 6548 FE2B0B701FD8C4630075DA5F /* JSCPoison.h */, 6546 6549 FE2B0B681FD0D2970075DA5F /* JSCPoisonedPtr.cpp */, 6547 6550 FE2B0B671FD0D2960075DA5F /* JSCPoisonedPtr.h */, … … 8102 8105 0F33FCFB1C1625BE00323F67 /* B3CFG.h in Headers */, 8103 8106 0FEC85061BDACDAC0080FF74 /* B3CheckSpecial.h in Headers */, 8107 FE2B0B731FD9EF700075DA5F /* JSCPoison.h in Headers */, 8104 8108 0FEC85081BDACDAC0080FF74 /* B3CheckValue.h in Headers */, 8105 8109 0FEC850A1BDACDAC0080FF74 /* B3Common.h in Headers */, -
trunk/Source/JavaScriptCore/b3/B3LowerMacros.cpp
r225632 r225659 508 508 GPRReg poisonScratch = params.gpScratch(1); 509 509 510 jit.move(CCallHelpers::TrustedImm64(g_ masmPoison), poisonScratch);510 jit.move(CCallHelpers::TrustedImm64(g_jitCodePoison), poisonScratch); 511 511 jit.move(CCallHelpers::TrustedImmPtr(jumpTable), scratch); 512 512 jit.load64(CCallHelpers::BaseIndex(scratch, index, CCallHelpers::timesPtr()), scratch); -
trunk/Source/JavaScriptCore/b3/testb3.cpp
r225632 r225659 13034 13034 13035 13035 jit.move(CCallHelpers::TrustedImmPtr(jumpTable), scratch); 13036 jit.move(CCallHelpers::TrustedImm64(g_ masmPoison), poisonScratch);13036 jit.move(CCallHelpers::TrustedImm64(g_jitCodePoison), poisonScratch); 13037 13037 jit.load64(CCallHelpers::BaseIndex(scratch, params[0].gpr(), CCallHelpers::timesPtr()), scratch); 13038 13038 jit.xor64(poisonScratch, scratch); -
trunk/Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp
r225632 r225659 8707 8707 m_jit.loadPtr(CCallHelpers::Address(otherGPR, Structure::classInfoOffset()), otherGPR); 8708 8708 #if USE(JSVALUE64) 8709 m_jit.move(CCallHelpers::TrustedImm64(g_ classInfoPoison), specifiedGPR);8709 m_jit.move(CCallHelpers::TrustedImm64(g_globalDataPoison), specifiedGPR); 8710 8710 m_jit.xor64(specifiedGPR, otherGPR); 8711 8711 #endif … … 9785 9785 UNUSED_PARAM(poisonScratch); // Placate the 32-bit build. 9786 9786 #if USE(JSVALUE64) 9787 m_jit.move(TrustedImm64(g_ masmPoison), poisonScratch);9787 m_jit.move(TrustedImm64(g_jitCodePoison), poisonScratch); 9788 9788 #endif 9789 9789 m_jit.move(TrustedImmPtr(table.ctiOffsets.begin()), scratch); -
trunk/Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp
r225632 r225659 11172 11172 LValue structure = loadStructure(cell); 11173 11173 LValue poisonedClassInfo = m_out.loadPtr(structure, m_heaps.Structure_classInfo); 11174 LValue classInfo = m_out.bitXor(poisonedClassInfo, m_out.constInt64(g_ classInfoPoison));11174 LValue classInfo = m_out.bitXor(poisonedClassInfo, m_out.constInt64(g_globalDataPoison)); 11175 11175 ValueFromBlock otherAtStart = m_out.anchor(classInfo); 11176 11176 m_out.jump(loop); -
trunk/Source/JavaScriptCore/jit/ThunkGenerators.cpp
r225632 r225659 215 215 // call. 216 216 #if USE(JSVALUE64) 217 jit.move(CCallHelpers::TrustedImm64(g_ masmPoison), GPRInfo::regT1);217 jit.move(CCallHelpers::TrustedImm64(g_jitCodePoison), GPRInfo::regT1); 218 218 jit.xor64(GPRInfo::regT1, GPRInfo::regT4); 219 219 #endif … … 308 308 if (thunkFunctionType == ThunkFunctionType::JSFunction) { 309 309 jit.loadPtr(JSInterfaceJIT::Address(X86Registers::esi, JSFunction::offsetOfExecutable()), X86Registers::r9); 310 jit. call(JSInterfaceJIT::Address(X86Registers::r9, executableOffsetToFunction));310 jit.loadPtr(JSInterfaceJIT::Address(X86Registers::r9, executableOffsetToFunction), X86Registers::r9); 311 311 } else 312 jit.call(JSInterfaceJIT::Address(X86Registers::esi, InternalFunction::offsetOfNativeFunctionFor(kind))); 312 jit.loadPtr(JSInterfaceJIT::Address(X86Registers::esi, InternalFunction::offsetOfNativeFunctionFor(kind)), X86Registers::r9); 313 jit.move(JSInterfaceJIT::TrustedImm64(g_nativeCodePoison), X86Registers::esi); 314 jit.xor64(X86Registers::esi, X86Registers::r9); 315 jit.call(X86Registers::r9); 313 316 314 317 #else … … 342 345 if (thunkFunctionType == ThunkFunctionType::JSFunction) { 343 346 jit.loadPtr(JSInterfaceJIT::Address(ARM64Registers::x1, JSFunction::offsetOfExecutable()), ARM64Registers::x2); 344 jit. call(JSInterfaceJIT::Address(ARM64Registers::x2, executableOffsetToFunction));347 jit.loadPtr(JSInterfaceJIT::Address(ARM64Registers::x2, executableOffsetToFunction), ARM64Registers::x2); 345 348 } else 346 jit.call(JSInterfaceJIT::Address(ARM64Registers::x1, InternalFunction::offsetOfNativeFunctionFor(kind))); 349 jit.loadPtr(JSInterfaceJIT::Address(ARM64Registers::x1, InternalFunction::offsetOfNativeFunctionFor(kind)), ARM64Registers::x2); 350 jit.move(JSInterfaceJIT::TrustedImm64(g_nativeCodePoison), ARM64Registers::x1); 351 jit.xor64(ARM64Registers::x1, ARM64Registers::x2); 352 jit.call(ARM64Registers::x2); 353 347 354 #elif CPU(ARM) || CPU(MIPS) 348 355 #if CPU(MIPS) … … 1164 1171 1165 1172 #if USE(JSVALUE64) 1166 jit.move(CCallHelpers::TrustedImm64(g_ masmPoison), GPRInfo::regT1);1173 jit.move(CCallHelpers::TrustedImm64(g_jitCodePoison), GPRInfo::regT1); 1167 1174 jit.xor64(GPRInfo::regT1, GPRInfo::regT0); 1168 1175 #endif -
trunk/Source/JavaScriptCore/llint/LowLevelInterpreter64.asm
r225632 r225659 1951 1951 callTargetFunction(LLIntCallLinkInfo::machineCodeTarget[t1]) 1952 1952 else 1953 loadp _g_ masmPoison, t21953 loadp _g_jitCodePoison, t2 1954 1954 xorp LLIntCallLinkInfo::machineCodeTarget[t1], t2 1955 1955 prepareCall(t2, t1, t3, t4) … … 2081 2081 if X86_64_WIN 2082 2082 subp 32, sp 2083 end 2084 call executableOffsetToFunction[t1] 2085 if X86_64_WIN 2083 call executableOffsetToFunction[t1] 2086 2084 addp 32, sp 2085 else 2086 loadp _g_nativeCodePoison, t2 2087 xorp executableOffsetToFunction[t1], t2 2088 call t2 2087 2089 end 2088 2090 end … … 2120 2122 if X86_64_WIN 2121 2123 subp 32, sp 2122 end 2123 call offsetOfFunction[t1] 2124 if X86_64_WIN 2124 call offsetOfFunction[t1] 2125 2125 addp 32, sp 2126 else 2127 loadp _g_nativeCodePoison, t2 2128 xorp offsetOfFunction[t1], t2 2129 call t2 2126 2130 end 2127 2131 end -
trunk/Source/JavaScriptCore/runtime/CustomGetterSetter.h
r219981 r225659 1 1 /* 2 * Copyright (C) 2014 Apple Inc. All rights reserved.2 * Copyright (C) 2014-2017 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 26 26 #pragma once 27 27 28 #include "JSCPoisonedPtr.h" 28 29 #include "JSCell.h" 29 30 #include "PropertySlot.h" … … 48 49 } 49 50 50 CustomGetterSetter::CustomGetter getter() const { return m_getter ; }51 CustomGetterSetter::CustomSetter setter() const { return m_setter ; }51 CustomGetterSetter::CustomGetter getter() const { return m_getter.unpoisoned(); } 52 CustomGetterSetter::CustomSetter setter() const { return m_setter.unpoisoned(); } 52 53 53 54 static Structure* createStructure(VM& vm, JSGlobalObject* globalObject, JSValue prototype) … … 67 68 68 69 private: 69 CustomGetter m_getter; 70 CustomSetter m_setter; 70 template<typename T> 71 using PoisonedAccessor = Poisoned<g_nativeCodePoison, T>; 72 73 PoisonedAccessor<CustomGetter> m_getter; 74 PoisonedAccessor<CustomSetter> m_setter; 71 75 }; 72 76 -
trunk/Source/JavaScriptCore/runtime/InternalFunction.cpp
r224487 r225659 89 89 auto* function = jsCast<InternalFunction*>(cell); 90 90 ASSERT(function->m_functionForCall); 91 callData.native.function = function->m_functionForCall ;91 callData.native.function = function->m_functionForCall.unpoisoned(); 92 92 return CallType::Host; 93 93 } … … 98 98 if (function->m_functionForConstruct == callHostFunctionAsConstructor) 99 99 return ConstructType::None; 100 constructData.native.function = function->m_functionForConstruct ;100 constructData.native.function = function->m_functionForConstruct.unpoisoned(); 101 101 return ConstructType::Host; 102 102 } -
trunk/Source/JavaScriptCore/runtime/InternalFunction.h
r224487 r225659 1 1 /* 2 2 * Copyright (C) 1999-2000 Harri Porten (porten@kde.org) 3 * Copyright (C) 2003 , 2006, 2007, 2008, 2016Apple Inc. All rights reserved.3 * Copyright (C) 2003-2017 Apple Inc. All rights reserved. 4 4 * Copyright (C) 2007 Cameron Zwarich (cwzwarich@uwaterloo.ca) 5 5 * Copyright (C) 2007 Maks Orlovich … … 25 25 26 26 #include "CodeSpecializationKind.h" 27 #include "JSCPoisonedPtr.h" 27 28 #include "JSDestructibleObject.h" 28 29 … … 56 57 { 57 58 if (kind == CodeForCall) 58 return m_functionForCall ;59 return m_functionForCall.unpoisoned(); 59 60 ASSERT(kind == CodeForConstruct); 60 return m_functionForConstruct ;61 return m_functionForConstruct.unpoisoned(); 61 62 } 62 63 … … 70 71 71 72 protected: 73 using PoisonedNativeFunction = Poisoned<g_nativeCodePoison, NativeFunction>; 74 72 75 JS_EXPORT_PRIVATE InternalFunction(VM&, Structure*, NativeFunction functionForCall, NativeFunction functionForConstruct); 73 76 … … 80 83 JS_EXPORT_PRIVATE static CallType getCallData(JSCell*, CallData&); 81 84 82 NativeFunction m_functionForCall;83 NativeFunction m_functionForConstruct;85 PoisonedNativeFunction m_functionForCall; 86 PoisonedNativeFunction m_functionForConstruct; 84 87 WriteBarrier<JSString> m_originalName; 85 88 }; -
trunk/Source/JavaScriptCore/runtime/JSCPoisonedPtr.cpp
r225632 r225659 29 29 namespace JSC { 30 30 31 uintptr_t g_classInfoPoison; 32 uintptr_t g_masmPoison; 31 uintptr_t g_globalDataPoison; 32 uintptr_t g_jitCodePoison; 33 uintptr_t g_nativeCodePoison; 33 34 34 35 void initializePoison() … … 36 37 static std::once_flag initializeOnceFlag; 37 38 std::call_once(initializeOnceFlag, [] { 38 g_classInfoPoison = makePoison(); 39 g_masmPoison = makePoison(); 39 g_globalDataPoison = makePoison(); 40 g_jitCodePoison = makePoison(); 41 g_nativeCodePoison = makePoison(); 40 42 }); 41 43 } -
trunk/Source/JavaScriptCore/runtime/JSCPoisonedPtr.h
r225632 r225659 30 30 namespace JSC { 31 31 32 extern "C" JS_EXPORTDATA uintptr_t g_classInfoPoison; 33 extern "C" JS_EXPORTDATA uintptr_t g_masmPoison; 32 extern "C" JS_EXPORTDATA uintptr_t g_globalDataPoison; 33 extern "C" JS_EXPORTDATA uintptr_t g_jitCodePoison; 34 extern "C" JS_EXPORTDATA uintptr_t g_nativeCodePoison; 34 35 35 36 struct ClassInfo; 36 37 37 using PoisonedClassInfoPtr = Poisoned<g_ classInfoPoison, const ClassInfo*>;38 using PoisonedMasmPtr = Poisoned<g_ masmPoison, void*>;38 using PoisonedClassInfoPtr = Poisoned<g_globalDataPoison, const ClassInfo*>; 39 using PoisonedMasmPtr = Poisoned<g_jitCodePoison, void*>; 39 40 40 41 void initializePoison(); -
trunk/Source/JavaScriptCore/runtime/NativeExecutable.cpp
r217108 r225659 1 1 /* 2 * Copyright (C) 2009 , 2010, 2013, 2015-2016Apple Inc. All rights reserved.2 * Copyright (C) 2009-2017 Apple Inc. All rights reserved. 3 3 * 4 4 * Redistribution and use in source and binary forms, with or without … … 80 80 { 81 81 if (kind == CodeForCall) 82 return CodeBlockHash( static_cast<unsigned>(bitwise_cast<size_t>(m_function)));83 82 return CodeBlockHash(m_function.bits()); 83 84 84 RELEASE_ASSERT(kind == CodeForConstruct); 85 return CodeBlockHash( static_cast<unsigned>(bitwise_cast<size_t>(m_constructor)));85 return CodeBlockHash(m_constructor.bits()); 86 86 } 87 87 -
trunk/Source/JavaScriptCore/runtime/NativeExecutable.h
r225314 r225659 27 27 28 28 #include "ExecutableBase.h" 29 #include "JSCPoisonedPtr.h" 29 30 30 31 namespace JSC { … … 52 53 CodeBlockHash hashFor(CodeSpecializationKind) const; 53 54 54 NativeFunction function() { return m_function ; }55 NativeFunction constructor() { return m_constructor ; }55 NativeFunction function() { return m_function.unpoisoned(); } 56 NativeFunction constructor() { return m_constructor.unpoisoned(); } 56 57 57 58 NativeFunction nativeFunctionFor(CodeSpecializationKind kind) … … 90 91 private: 91 92 friend class ExecutableBase; 93 using PoisonedNativeFunction = Poisoned<g_nativeCodePoison, NativeFunction>; 92 94 93 95 NativeExecutable(VM&, NativeFunction function, NativeFunction constructor, Intrinsic, const DOMJIT::Signature*); 94 96 95 NativeFunction m_function;96 NativeFunction m_constructor;97 PoisonedNativeFunction m_function; 98 PoisonedNativeFunction m_constructor; 97 99 const DOMJIT::Signature* m_signature; 98 100 -
trunk/Source/JavaScriptCore/runtime/Structure.cpp
r225524 r225659 87 87 WeakSet::deallocate(impl); 88 88 WeakImpl* impl = WeakSet::allocate(structure, &singleSlotTransitionWeakOwner(), this); 89 m_data = reinterpret_cast<intptr_t>(impl) | UsingSingleSlotFlag;89 m_data = PoisonedWeakImplPtr(impl).bits() | UsingSingleSlotFlag; 90 90 } 91 91 -
trunk/Source/JavaScriptCore/runtime/StructureTransitionTable.h
r206525 r225659 27 27 28 28 #include "IndexingType.h" 29 #include "JSCPoison.h" 29 30 #include "WeakGCMap.h" 30 31 #include <wtf/HashFunctions.h> … … 187 188 private: 188 189 friend class SingleSlotTransitionWeakOwner; 190 using PoisonedTransitionMapPtr = Int32Poisoned<TransitionMapPoison, TransitionMap*>; 191 using PoisonedWeakImplPtr = Int32Poisoned<WeakImplPoison, WeakImpl*>; 189 192 190 193 bool isUsingSingleSlot() const … … 196 199 { 197 200 ASSERT(!isUsingSingleSlot()); 198 return reinterpret_cast<TransitionMap*>(m_data);201 return PoisonedTransitionMapPtr(m_data).unpoisoned(); 199 202 } 200 203 … … 202 205 { 203 206 ASSERT(isUsingSingleSlot()); 204 return reinterpret_cast<WeakImpl*>(m_data & ~UsingSingleSlotFlag);207 return PoisonedWeakImplPtr(m_data & ~UsingSingleSlotFlag).unpoisoned(); 205 208 } 206 209 … … 213 216 214 217 // This implicitly clears the flag that indicates we're using a single transition 215 m_data = reinterpret_cast<intptr_t>(map);218 m_data = PoisonedTransitionMapPtr(map).bits(); 216 219 217 220 ASSERT(!isUsingSingleSlot()); -
trunk/Source/WTF/ChangeLog
r225632 r225659 1 2017-12-07 Mark Lam <mark.lam@apple.com> 2 3 Apply poisoning to some native code pointers. 4 https://bugs.webkit.org/show_bug.cgi?id=180541 5 <rdar://problem/35916875> 6 7 Reviewed by Filip Pizlo. 8 9 Ensure that the resultant poisoned bits still looks like a pointer in that its 10 bottom bits are 0, just like the alignment bits of a pointer. This allows the 11 client to use the bottom bits of the poisoned bits as flag bits just like the 12 client was previously able to do with pointer values. 13 14 Note: we only ensure that the bottom alignment bits of the generated poison 15 value is 0. We're not masking out the poisoned bits. This means that the bottom 16 bits of the poisoned bits will only be null if the original pointer is aligned. 17 Hence, if the client applies the poison to an unaligned pointer, we do not lose 18 any information on the low bits. 19 20 Also removed 2 wrong assertions in PoisonedImpl's constructors. We were 21 asserting that Poisoned will never be used with a null value, but that's invalid. 22 We do want to allow a null value so that we don't have to constantly do null 23 checks in the clients. This was uncovered by some layout tests. 24 25 * wtf/Poisoned.cpp: 26 (WTF::makePoison): 27 * wtf/Poisoned.h: 28 (WTF::PoisonedImpl::PoisonedImpl): 29 1 30 2017-12-07 Mark Lam <mark.lam@apple.com> 2 31 -
trunk/Source/WTF/wtf/Poisoned.cpp
r225632 r225659 40 40 // used for a notmal zero check without needing to decoded first. 41 41 key |= (static_cast<uintptr_t>(0x1) << 63); 42 // Ensure that the bottom alignment bits are still 0 so that the poisoned bits will 43 // still preserve the properties of a pointer where these bits are expected to be 0. 44 // This allows the poisoned bits to be used in place of the pointer by clients that 45 // rely on this property of pointers and sets flags in the low bits. 46 key &= ~static_cast<uintptr_t>(0x7); 42 47 #else 43 48 key = 0; // Poisoning is not supported on 32-bit or non-darwin platforms yet. -
trunk/Source/WTF/wtf/Poisoned.h
r225632 r225659 48 48 explicit PoisonedImpl(T ptr) 49 49 : m_poisonedBits(poison(ptr)) 50 { 51 ASSERT(ptr && m_poisonedBits); 52 } 50 { } 53 51 54 52 PoisonedImpl(const PoisonedImpl&) = default; … … 56 54 explicit PoisonedImpl(PoisonedBits poisonedBits) 57 55 : m_poisonedBits(poisonedBits) 58 { 59 ASSERT(m_poisonedBits); 60 } 56 { } 61 57 62 58 #if ENABLE(POISON_ASSERTS)
Note:
See TracChangeset
for help on using the changeset viewer.