| Summary: | [JSC] Introduce JITOperationList to validate JIT-caged pointers | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Product: | WebKit | Reporter: | Yusuke Suzuki <ysuzuki> | ||||||||||||||
| Component: | New Bugs | Assignee: | Yusuke Suzuki <ysuzuki> | ||||||||||||||
| Status: | RESOLVED FIXED | ||||||||||||||||
| Severity: | Normal | CC: | annulen, benjamin, cdumez, cmarcelo, ews-watchlist, gyuyoung.kim, keith_miller, mark.lam, msaboff, ryuan.choi, saam, sergio, tzagallo, webkit-bug-importer | ||||||||||||||
| Priority: | P2 | Keywords: | InRadar | ||||||||||||||
| Version: | WebKit Nightly Build | ||||||||||||||||
| Hardware: | Unspecified | ||||||||||||||||
| OS: | Unspecified | ||||||||||||||||
| Attachments: |
|
||||||||||||||||
|
Description
Yusuke Suzuki
2020-10-02 17:50:28 PDT
Created attachment 410393 [details]
Patch
Created attachment 410394 [details]
Patch
Created attachment 410396 [details]
Patch
Created attachment 410398 [details]
Patch
Comment on attachment 410398 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=410398&action=review r=me > Source/JavaScriptCore/assembler/JITOperationList.h:50 > + JS_EXPORT_PRIVATE static void populatePointersInEmbedder1(const uintptr_t* beginHost, const uintptr_t* endHost, const uintptr_t* beginOperations, const uintptr_t* endOperations); > + JS_EXPORT_PRIVATE static void populatePointersInEmbedder2(const uintptr_t* beginHost, const uintptr_t* endHost, const uintptr_t* beginOperations, const uintptr_t* endOperations); let's do what we talked about on slack of just a single function > Source/WebKitLegacy/mac/WebView/WebPreferences.mm:380 > + WebCore::populateJITOperations(); could we have a version of "initialize" per library that calls the necessary initialize functions blow it? e.g, JSC::initialize, WebCore::initilziae, that calls JSC::initialize and calls WebCore::populateJITOperations WebKit::initialize, that calls WebCore::initialize, and WebKit::populateJITOperations Created attachment 410404 [details]
Patch
Created attachment 410405 [details]
Patch
Committed r267938: <https://trac.webkit.org/changeset/267938> All reviewed patches have been landed. Closing bug and clearing flags on attachment 410405 [details]. Committed r268013: <https://trac.webkit.org/changeset/268013> |