| Differences between
and this patch
- Source/JavaScriptCore/ChangeLog +47 lines
Lines 1-3 Source/JavaScriptCore/ChangeLog_sec1
1
2017-12-07  Mark Lam  <mark.lam@apple.com>
2
3
        Apply poisoning to some native code pointers.
4
        https://bugs.webkit.org/show_bug.cgi?id=180541
5
        <rdar://problem/35916875>
6
7
        Reviewed by Filip Pizlo.
8
9
        Renamed g_classInfoPoison to g_globalDataPoison.
10
        Renamed g_masmPoison to g_jitCodePoison.
11
        Introduced g_nativeCodePoison.
12
        Applied g_nativeCodePoison to poisoning some native code pointers.
13
14
        Introduced non-random Int32 poison values (in JSCPoison.h) for use with pointers
15
        to malloc allocated data structures (where needed).
16
17
        * API/JSCallbackFunction.h:
18
        (JSC::JSCallbackFunction::functionCallback):
19
        * JavaScriptCore.xcodeproj/project.pbxproj:
20
        * jit/ThunkGenerators.cpp:
21
        (JSC::nativeForGenerator):
22
        * llint/LowLevelInterpreter64.asm:
23
        * runtime/CustomGetterSetter.h:
24
        (JSC::CustomGetterSetter::getter const):
25
        (JSC::CustomGetterSetter::setter const):
26
        * runtime/InternalFunction.cpp:
27
        (JSC::InternalFunction::getCallData):
28
        (JSC::InternalFunction::getConstructData):
29
        * runtime/InternalFunction.h:
30
        (JSC::InternalFunction::nativeFunctionFor):
31
        * runtime/JSCPoison.h: Added.
32
        * runtime/JSCPoisonedPtr.cpp:
33
        (JSC::initializePoison):
34
        * runtime/JSCPoisonedPtr.h:
35
        * runtime/Lookup.h:
36
        * runtime/NativeExecutable.cpp:
37
        (JSC::NativeExecutable::hashFor const):
38
        * runtime/NativeExecutable.h:
39
        * runtime/Structure.cpp:
40
        (JSC::StructureTransitionTable::setSingleTransition):
41
        * runtime/StructureTransitionTable.h:
42
        (JSC::StructureTransitionTable::StructureTransitionTable):
43
        (JSC::StructureTransitionTable::isUsingSingleSlot const):
44
        (JSC::StructureTransitionTable::map const):
45
        (JSC::StructureTransitionTable::weakImpl const):
46
        (JSC::StructureTransitionTable::setMap):
47
1
2017-12-07  Matt Lewis  <jlewis3@apple.com>
48
2017-12-07  Matt Lewis  <jlewis3@apple.com>
2
49
3
        Unreviewed, rolling out r225634.
50
        Unreviewed, rolling out r225634.
- Source/JavaScriptCore/API/JSCallbackFunction.h -3 / +3 lines
Lines 1-5 Source/JavaScriptCore/API/JSCallbackFunction.h_sec1
1
/*
1
/*
2
 * Copyright (C) 2006, 2008 Apple Inc. All rights reserved.
2
 * Copyright (C) 2006-2017 Apple Inc. All rights reserved.
3
 *
3
 *
4
 * Redistribution and use in source and binary forms, with or without
4
 * Redistribution and use in source and binary forms, with or without
5
 * modification, are permitted provided that the following conditions
5
 * modification, are permitted provided that the following conditions
Lines 51-59 private: Source/JavaScriptCore/API/JSCallbackFunction.h_sec2
51
    JSCallbackFunction(VM&, Structure*, JSObjectCallAsFunctionCallback);
51
    JSCallbackFunction(VM&, Structure*, JSObjectCallAsFunctionCallback);
52
    void finishCreation(VM&, const String& name);
52
    void finishCreation(VM&, const String& name);
53
53
54
    JSObjectCallAsFunctionCallback functionCallback() { return m_callback; }
54
    JSObjectCallAsFunctionCallback functionCallback() { return m_callback.unpoisoned(); }
55
55
56
    JSObjectCallAsFunctionCallback m_callback;
56
    Poisoned<g_nativeCodePoison, JSObjectCallAsFunctionCallback> m_callback;
57
};
57
};
58
58
59
} // namespace JSC
59
} // namespace JSC
- Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj +4 lines
Lines 1721-1726 Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj_sec1
1721
		FE20CE9E15F04A9500DF3430 /* LLIntCLoop.h in Headers */ = {isa = PBXBuildFile; fileRef = FE20CE9C15F04A9500DF3430 /* LLIntCLoop.h */; settings = {ATTRIBUTES = (Private, ); }; };
1721
		FE20CE9E15F04A9500DF3430 /* LLIntCLoop.h in Headers */ = {isa = PBXBuildFile; fileRef = FE20CE9C15F04A9500DF3430 /* LLIntCLoop.h */; settings = {ATTRIBUTES = (Private, ); }; };
1722
		FE2A87601F02381600EB31B2 /* MinimumReservedZoneSize.h in Headers */ = {isa = PBXBuildFile; fileRef = FE2A875F1F02381600EB31B2 /* MinimumReservedZoneSize.h */; };
1722
		FE2A87601F02381600EB31B2 /* MinimumReservedZoneSize.h in Headers */ = {isa = PBXBuildFile; fileRef = FE2A875F1F02381600EB31B2 /* MinimumReservedZoneSize.h */; };
1723
		FE2B0B691FD227E00075DA5F /* JSCPoisonedPtr.h in Headers */ = {isa = PBXBuildFile; fileRef = FE2B0B671FD0D2960075DA5F /* JSCPoisonedPtr.h */; settings = {ATTRIBUTES = (Private, ); }; };
1723
		FE2B0B691FD227E00075DA5F /* JSCPoisonedPtr.h in Headers */ = {isa = PBXBuildFile; fileRef = FE2B0B671FD0D2960075DA5F /* JSCPoisonedPtr.h */; settings = {ATTRIBUTES = (Private, ); }; };
1724
		FE2B0B731FD9EF700075DA5F /* JSCPoison.h in Headers */ = {isa = PBXBuildFile; fileRef = FE2B0B701FD8C4630075DA5F /* JSCPoison.h */; settings = {ATTRIBUTES = (Private, ); }; };
1724
		FE3022D31E3D73A500BAC493 /* SigillCrashAnalyzer.h in Headers */ = {isa = PBXBuildFile; fileRef = FE3022D11E3D739600BAC493 /* SigillCrashAnalyzer.h */; settings = {ATTRIBUTES = (Private, ); }; };
1725
		FE3022D31E3D73A500BAC493 /* SigillCrashAnalyzer.h in Headers */ = {isa = PBXBuildFile; fileRef = FE3022D11E3D739600BAC493 /* SigillCrashAnalyzer.h */; settings = {ATTRIBUTES = (Private, ); }; };
1725
		FE3022D71E42857300BAC493 /* VMInspector.h in Headers */ = {isa = PBXBuildFile; fileRef = FE3022D51E42856700BAC493 /* VMInspector.h */; };
1726
		FE3022D71E42857300BAC493 /* VMInspector.h in Headers */ = {isa = PBXBuildFile; fileRef = FE3022D51E42856700BAC493 /* VMInspector.h */; };
1726
		FE318FE01CAC982F00DFCC54 /* ECMAScriptSpecInternalFunctions.h in Headers */ = {isa = PBXBuildFile; fileRef = FE318FDE1CAC8C5300DFCC54 /* ECMAScriptSpecInternalFunctions.h */; };
1727
		FE318FE01CAC982F00DFCC54 /* ECMAScriptSpecInternalFunctions.h in Headers */ = {isa = PBXBuildFile; fileRef = FE318FDE1CAC8C5300DFCC54 /* ECMAScriptSpecInternalFunctions.h */; };
Lines 4600-4605 Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj_sec2
4600
		FE2A875F1F02381600EB31B2 /* MinimumReservedZoneSize.h */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.c.h; path = MinimumReservedZoneSize.h; sourceTree = "<group>"; };
4601
		FE2A875F1F02381600EB31B2 /* MinimumReservedZoneSize.h */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.c.h; path = MinimumReservedZoneSize.h; sourceTree = "<group>"; };
4601
		FE2B0B671FD0D2960075DA5F /* JSCPoisonedPtr.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = JSCPoisonedPtr.h; sourceTree = "<group>"; };
4602
		FE2B0B671FD0D2960075DA5F /* JSCPoisonedPtr.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = JSCPoisonedPtr.h; sourceTree = "<group>"; };
4602
		FE2B0B681FD0D2970075DA5F /* JSCPoisonedPtr.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = JSCPoisonedPtr.cpp; sourceTree = "<group>"; };
4603
		FE2B0B681FD0D2970075DA5F /* JSCPoisonedPtr.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = JSCPoisonedPtr.cpp; sourceTree = "<group>"; };
4604
		FE2B0B701FD8C4630075DA5F /* JSCPoison.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = JSCPoison.h; sourceTree = "<group>"; };
4603
		FE2E6A7A1D6EA5FE0060F896 /* ThrowScope.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = ThrowScope.cpp; sourceTree = "<group>"; };
4605
		FE2E6A7A1D6EA5FE0060F896 /* ThrowScope.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = ThrowScope.cpp; sourceTree = "<group>"; };
4604
		FE3022D01E3D739600BAC493 /* SigillCrashAnalyzer.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = SigillCrashAnalyzer.cpp; sourceTree = "<group>"; };
4606
		FE3022D01E3D739600BAC493 /* SigillCrashAnalyzer.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = SigillCrashAnalyzer.cpp; sourceTree = "<group>"; };
4605
		FE3022D11E3D739600BAC493 /* SigillCrashAnalyzer.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = SigillCrashAnalyzer.h; sourceTree = "<group>"; };
4607
		FE3022D11E3D739600BAC493 /* SigillCrashAnalyzer.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = SigillCrashAnalyzer.h; sourceTree = "<group>"; };
Lines 6543-6548 Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj_sec3
6543
				F692A8870255597D01FF60F7 /* JSCJSValue.cpp */,
6545
				F692A8870255597D01FF60F7 /* JSCJSValue.cpp */,
6544
				14ABB36E099C076400E2A24F /* JSCJSValue.h */,
6546
				14ABB36E099C076400E2A24F /* JSCJSValue.h */,
6545
				865A30F0135007E100CDB49E /* JSCJSValueInlines.h */,
6547
				865A30F0135007E100CDB49E /* JSCJSValueInlines.h */,
6548
				FE2B0B701FD8C4630075DA5F /* JSCPoison.h */,
6546
				FE2B0B681FD0D2970075DA5F /* JSCPoisonedPtr.cpp */,
6549
				FE2B0B681FD0D2970075DA5F /* JSCPoisonedPtr.cpp */,
6547
				FE2B0B671FD0D2960075DA5F /* JSCPoisonedPtr.h */,
6550
				FE2B0B671FD0D2960075DA5F /* JSCPoisonedPtr.h */,
6548
				72AAF7CB1D0D318B005E60BE /* JSCustomGetterSetterFunction.cpp */,
6551
				72AAF7CB1D0D318B005E60BE /* JSCustomGetterSetterFunction.cpp */,
Lines 8101-8106 Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj_sec4
8101
				0F338DFA1BE96AA80013C88F /* B3CCallValue.h in Headers */,
8104
				0F338DFA1BE96AA80013C88F /* B3CCallValue.h in Headers */,
8102
				0F33FCFB1C1625BE00323F67 /* B3CFG.h in Headers */,
8105
				0F33FCFB1C1625BE00323F67 /* B3CFG.h in Headers */,
8103
				0FEC85061BDACDAC0080FF74 /* B3CheckSpecial.h in Headers */,
8106
				0FEC85061BDACDAC0080FF74 /* B3CheckSpecial.h in Headers */,
8107
				FE2B0B731FD9EF700075DA5F /* JSCPoison.h in Headers */,
8104
				0FEC85081BDACDAC0080FF74 /* B3CheckValue.h in Headers */,
8108
				0FEC85081BDACDAC0080FF74 /* B3CheckValue.h in Headers */,
8105
				0FEC850A1BDACDAC0080FF74 /* B3Common.h in Headers */,
8109
				0FEC850A1BDACDAC0080FF74 /* B3Common.h in Headers */,
8106
				0FDCE12D1FAFB4E5006F3901 /* IsoSubspace.h in Headers */,
8110
				0FDCE12D1FAFB4E5006F3901 /* IsoSubspace.h in Headers */,
- Source/JavaScriptCore/b3/B3LowerMacros.cpp -1 / +1 lines
Lines 507-513 private: Source/JavaScriptCore/b3/B3LowerMacros.cpp_sec1
507
                        GPRReg scratch = params.gpScratch(0);
507
                        GPRReg scratch = params.gpScratch(0);
508
                        GPRReg poisonScratch = params.gpScratch(1);
508
                        GPRReg poisonScratch = params.gpScratch(1);
509
509
510
                        jit.move(CCallHelpers::TrustedImm64(g_masmPoison), poisonScratch);
510
                        jit.move(CCallHelpers::TrustedImm64(g_jitCodePoison), poisonScratch);
511
                        jit.move(CCallHelpers::TrustedImmPtr(jumpTable), scratch);
511
                        jit.move(CCallHelpers::TrustedImmPtr(jumpTable), scratch);
512
                        jit.load64(CCallHelpers::BaseIndex(scratch, index, CCallHelpers::timesPtr()), scratch);
512
                        jit.load64(CCallHelpers::BaseIndex(scratch, index, CCallHelpers::timesPtr()), scratch);
513
                        jit.xor64(poisonScratch, scratch);
513
                        jit.xor64(poisonScratch, scratch);
- Source/JavaScriptCore/b3/testb3.cpp -1 / +1 lines
Lines 13033-13039 void testInterpreter() Source/JavaScriptCore/b3/testb3.cpp_sec1
13033
            GPRReg poisonScratch = params.gpScratch(1);
13033
            GPRReg poisonScratch = params.gpScratch(1);
13034
13034
13035
            jit.move(CCallHelpers::TrustedImmPtr(jumpTable), scratch);
13035
            jit.move(CCallHelpers::TrustedImmPtr(jumpTable), scratch);
13036
            jit.move(CCallHelpers::TrustedImm64(g_masmPoison), poisonScratch);
13036
            jit.move(CCallHelpers::TrustedImm64(g_jitCodePoison), poisonScratch);
13037
            jit.load64(CCallHelpers::BaseIndex(scratch, params[0].gpr(), CCallHelpers::timesPtr()), scratch);
13037
            jit.load64(CCallHelpers::BaseIndex(scratch, params[0].gpr(), CCallHelpers::timesPtr()), scratch);
13038
            jit.xor64(poisonScratch, scratch);
13038
            jit.xor64(poisonScratch, scratch);
13039
            jit.jump(scratch);
13039
            jit.jump(scratch);
- Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp -2 / +2 lines
Lines 8706-8712 void SpeculativeJIT::compileCheckSubClas Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp_sec1
8706
        m_jit.emitLoadStructure(*m_jit.vm(), baseGPR, otherGPR, specifiedGPR);
8706
        m_jit.emitLoadStructure(*m_jit.vm(), baseGPR, otherGPR, specifiedGPR);
8707
        m_jit.loadPtr(CCallHelpers::Address(otherGPR, Structure::classInfoOffset()), otherGPR);
8707
        m_jit.loadPtr(CCallHelpers::Address(otherGPR, Structure::classInfoOffset()), otherGPR);
8708
#if USE(JSVALUE64)
8708
#if USE(JSVALUE64)
8709
        m_jit.move(CCallHelpers::TrustedImm64(g_classInfoPoison), specifiedGPR);
8709
        m_jit.move(CCallHelpers::TrustedImm64(g_globalDataPoison), specifiedGPR);
8710
        m_jit.xor64(specifiedGPR, otherGPR);
8710
        m_jit.xor64(specifiedGPR, otherGPR);
8711
#endif
8711
#endif
8712
        m_jit.move(CCallHelpers::TrustedImmPtr(node->classInfo()), specifiedGPR);
8712
        m_jit.move(CCallHelpers::TrustedImmPtr(node->classInfo()), specifiedGPR);
Lines 9784-9790 void SpeculativeJIT::emitSwitchIntJump( Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp_sec2
9784
        data->fallThrough.block);
9784
        data->fallThrough.block);
9785
    UNUSED_PARAM(poisonScratch); // Placate the 32-bit build.
9785
    UNUSED_PARAM(poisonScratch); // Placate the 32-bit build.
9786
#if USE(JSVALUE64)
9786
#if USE(JSVALUE64)
9787
    m_jit.move(TrustedImm64(g_masmPoison), poisonScratch);
9787
    m_jit.move(TrustedImm64(g_jitCodePoison), poisonScratch);
9788
#endif
9788
#endif
9789
    m_jit.move(TrustedImmPtr(table.ctiOffsets.begin()), scratch);
9789
    m_jit.move(TrustedImmPtr(table.ctiOffsets.begin()), scratch);
9790
    m_jit.loadPtr(JITCompiler::BaseIndex(scratch, value, JITCompiler::timesPtr()), scratch);
9790
    m_jit.loadPtr(JITCompiler::BaseIndex(scratch, value, JITCompiler::timesPtr()), scratch);
- Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp -1 / +1 lines
Lines 11171-11177 private: Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp_sec1
11171
11171
11172
            LValue structure = loadStructure(cell);
11172
            LValue structure = loadStructure(cell);
11173
            LValue poisonedClassInfo = m_out.loadPtr(structure, m_heaps.Structure_classInfo);
11173
            LValue poisonedClassInfo = m_out.loadPtr(structure, m_heaps.Structure_classInfo);
11174
            LValue classInfo = m_out.bitXor(poisonedClassInfo, m_out.constInt64(g_classInfoPoison));
11174
            LValue classInfo = m_out.bitXor(poisonedClassInfo, m_out.constInt64(g_globalDataPoison));
11175
            ValueFromBlock otherAtStart = m_out.anchor(classInfo);
11175
            ValueFromBlock otherAtStart = m_out.anchor(classInfo);
11176
            m_out.jump(loop);
11176
            m_out.jump(loop);
11177
11177
- Source/JavaScriptCore/jit/ThunkGenerators.cpp -6 / +13 lines
Lines 214-220 MacroAssemblerCodeRef virtualThunkFor(VM Source/JavaScriptCore/jit/ThunkGenerators.cpp_sec1
214
    // Now we know that we have a CodeBlock, and we're committed to making a fast
214
    // Now we know that we have a CodeBlock, and we're committed to making a fast
215
    // call.
215
    // call.
216
#if USE(JSVALUE64)
216
#if USE(JSVALUE64)
217
    jit.move(CCallHelpers::TrustedImm64(g_masmPoison), GPRInfo::regT1);
217
    jit.move(CCallHelpers::TrustedImm64(g_jitCodePoison), GPRInfo::regT1);
218
    jit.xor64(GPRInfo::regT1, GPRInfo::regT4);
218
    jit.xor64(GPRInfo::regT1, GPRInfo::regT4);
219
#endif
219
#endif
220
220
Lines 307-315 static MacroAssemblerCodeRef nativeForGe Source/JavaScriptCore/jit/ThunkGenerators.cpp_sec2
307
    jit.emitGetFromCallFrameHeaderPtr(CallFrameSlot::callee, X86Registers::esi);
307
    jit.emitGetFromCallFrameHeaderPtr(CallFrameSlot::callee, X86Registers::esi);
308
    if (thunkFunctionType == ThunkFunctionType::JSFunction) {
308
    if (thunkFunctionType == ThunkFunctionType::JSFunction) {
309
        jit.loadPtr(JSInterfaceJIT::Address(X86Registers::esi, JSFunction::offsetOfExecutable()), X86Registers::r9);
309
        jit.loadPtr(JSInterfaceJIT::Address(X86Registers::esi, JSFunction::offsetOfExecutable()), X86Registers::r9);
310
        jit.call(JSInterfaceJIT::Address(X86Registers::r9, executableOffsetToFunction));
310
        jit.loadPtr(JSInterfaceJIT::Address(X86Registers::r9, executableOffsetToFunction), X86Registers::r9);
311
    } else
311
    } else
312
        jit.call(JSInterfaceJIT::Address(X86Registers::esi, InternalFunction::offsetOfNativeFunctionFor(kind)));
312
        jit.loadPtr(JSInterfaceJIT::Address(X86Registers::esi, InternalFunction::offsetOfNativeFunctionFor(kind)), X86Registers::r9);
313
    jit.move(JSInterfaceJIT::TrustedImm64(g_nativeCodePoison), X86Registers::esi);
314
    jit.xor64(X86Registers::esi, X86Registers::r9);
315
    jit.call(X86Registers::r9);
313
316
314
#else
317
#else
315
    // Calling convention:      f(ecx, edx, r8, r9, ...);
318
    // Calling convention:      f(ecx, edx, r8, r9, ...);
Lines 341-349 static MacroAssemblerCodeRef nativeForGe Source/JavaScriptCore/jit/ThunkGenerators.cpp_sec3
341
    jit.emitGetFromCallFrameHeaderPtr(CallFrameSlot::callee, ARM64Registers::x1);
344
    jit.emitGetFromCallFrameHeaderPtr(CallFrameSlot::callee, ARM64Registers::x1);
342
    if (thunkFunctionType == ThunkFunctionType::JSFunction) {
345
    if (thunkFunctionType == ThunkFunctionType::JSFunction) {
343
        jit.loadPtr(JSInterfaceJIT::Address(ARM64Registers::x1, JSFunction::offsetOfExecutable()), ARM64Registers::x2);
346
        jit.loadPtr(JSInterfaceJIT::Address(ARM64Registers::x1, JSFunction::offsetOfExecutable()), ARM64Registers::x2);
344
        jit.call(JSInterfaceJIT::Address(ARM64Registers::x2, executableOffsetToFunction));
347
        jit.loadPtr(JSInterfaceJIT::Address(ARM64Registers::x2, executableOffsetToFunction), ARM64Registers::x2);
345
    } else
348
    } else
346
        jit.call(JSInterfaceJIT::Address(ARM64Registers::x1, InternalFunction::offsetOfNativeFunctionFor(kind)));
349
        jit.loadPtr(JSInterfaceJIT::Address(ARM64Registers::x1, InternalFunction::offsetOfNativeFunctionFor(kind)), ARM64Registers::x2);
350
    jit.move(JSInterfaceJIT::TrustedImm64(g_nativeCodePoison), ARM64Registers::x1);
351
    jit.xor64(ARM64Registers::x1, ARM64Registers::x2);
352
    jit.call(ARM64Registers::x2);
353
347
#elif CPU(ARM) || CPU(MIPS)
354
#elif CPU(ARM) || CPU(MIPS)
348
#if CPU(MIPS)
355
#if CPU(MIPS)
349
    // Allocate stack space for (unused) 16 bytes (8-byte aligned) for 4 arguments.
356
    // Allocate stack space for (unused) 16 bytes (8-byte aligned) for 4 arguments.
Lines 1163-1169 MacroAssemblerCodeRef boundThisNoArgsFun Source/JavaScriptCore/jit/ThunkGenerators.cpp_sec4
1163
    CCallHelpers::Jump noCode = jit.branchTestPtr(CCallHelpers::Zero, GPRInfo::regT0);
1170
    CCallHelpers::Jump noCode = jit.branchTestPtr(CCallHelpers::Zero, GPRInfo::regT0);
1164
    
1171
    
1165
#if USE(JSVALUE64)
1172
#if USE(JSVALUE64)
1166
    jit.move(CCallHelpers::TrustedImm64(g_masmPoison), GPRInfo::regT1);
1173
    jit.move(CCallHelpers::TrustedImm64(g_jitCodePoison), GPRInfo::regT1);
1167
    jit.xor64(GPRInfo::regT1, GPRInfo::regT0);
1174
    jit.xor64(GPRInfo::regT1, GPRInfo::regT0);
1168
#endif
1175
#endif
1169
    emitPointerValidation(jit, GPRInfo::regT0);
1176
    emitPointerValidation(jit, GPRInfo::regT0);
- Source/JavaScriptCore/llint/LowLevelInterpreter64.asm -7 / +11 lines
Lines 1950-1956 macro doCall(slowPath, prepareCall) Source/JavaScriptCore/llint/LowLevelInterpreter64.asm_sec1
1950
        prepareCall(LLIntCallLinkInfo::machineCodeTarget[t1], t2, t3, t4)
1950
        prepareCall(LLIntCallLinkInfo::machineCodeTarget[t1], t2, t3, t4)
1951
        callTargetFunction(LLIntCallLinkInfo::machineCodeTarget[t1])
1951
        callTargetFunction(LLIntCallLinkInfo::machineCodeTarget[t1])
1952
    else
1952
    else
1953
        loadp _g_masmPoison, t2
1953
        loadp _g_jitCodePoison, t2
1954
        xorp LLIntCallLinkInfo::machineCodeTarget[t1], t2
1954
        xorp LLIntCallLinkInfo::machineCodeTarget[t1], t2
1955
        prepareCall(t2, t1, t3, t4)
1955
        prepareCall(t2, t1, t3, t4)
1956
        callTargetFunction(t2)
1956
        callTargetFunction(t2)
Lines 2080-2089 macro nativeCallTrampoline(executableOff Source/JavaScriptCore/llint/LowLevelInterpreter64.asm_sec2
2080
    else
2080
    else
2081
        if X86_64_WIN
2081
        if X86_64_WIN
2082
            subp 32, sp
2082
            subp 32, sp
2083
        end
2083
            call executableOffsetToFunction[t1]
2084
        call executableOffsetToFunction[t1]
2085
        if X86_64_WIN
2086
            addp 32, sp
2084
            addp 32, sp
2085
        else
2086
            loadp _g_nativeCodePoison, t2
2087
            xorp executableOffsetToFunction[t1], t2
2088
            call t2
2087
        end
2089
        end
2088
    end
2090
    end
2089
2091
Lines 2119-2128 macro internalFunctionCallTrampoline(off Source/JavaScriptCore/llint/LowLevelInterpreter64.asm_sec3
2119
    else
2121
    else
2120
        if X86_64_WIN
2122
        if X86_64_WIN
2121
            subp 32, sp
2123
            subp 32, sp
2122
        end
2124
            call offsetOfFunction[t1]
2123
        call offsetOfFunction[t1]
2124
        if X86_64_WIN
2125
            addp 32, sp
2125
            addp 32, sp
2126
        else
2127
            loadp _g_nativeCodePoison, t2
2128
            xorp offsetOfFunction[t1], t2
2129
            call t2
2126
        end
2130
        end
2127
    end
2131
    end
2128
2132
- Source/JavaScriptCore/runtime/CustomGetterSetter.h -5 / +9 lines
Lines 1-5 Source/JavaScriptCore/runtime/CustomGetterSetter.h_sec1
1
/*
1
/*
2
 * Copyright (C) 2014 Apple Inc. All rights reserved.
2
 * Copyright (C) 2014-2017 Apple Inc. All rights reserved.
3
 *
3
 *
4
 * Redistribution and use in source and binary forms, with or without
4
 * Redistribution and use in source and binary forms, with or without
5
 * modification, are permitted provided that the following conditions
5
 * modification, are permitted provided that the following conditions
Lines 25-30 Source/JavaScriptCore/runtime/CustomGetterSetter.h_sec2
25
25
26
#pragma once
26
#pragma once
27
27
28
#include "JSCPoisonedPtr.h"
28
#include "JSCell.h"
29
#include "JSCell.h"
29
#include "PropertySlot.h"
30
#include "PropertySlot.h"
30
#include "PutPropertySlot.h"
31
#include "PutPropertySlot.h"
Lines 47-54 public: Source/JavaScriptCore/runtime/CustomGetterSetter.h_sec3
47
        return customGetterSetter;
48
        return customGetterSetter;
48
    }
49
    }
49
50
50
    CustomGetterSetter::CustomGetter getter() const { return m_getter; }
51
    CustomGetterSetter::CustomGetter getter() const { return m_getter.unpoisoned(); }
51
    CustomGetterSetter::CustomSetter setter() const { return m_setter; }
52
    CustomGetterSetter::CustomSetter setter() const { return m_setter.unpoisoned(); }
52
53
53
    static Structure* createStructure(VM& vm, JSGlobalObject* globalObject, JSValue prototype)
54
    static Structure* createStructure(VM& vm, JSGlobalObject* globalObject, JSValue prototype)
54
    {
55
    {
Lines 66-73 protected: Source/JavaScriptCore/runtime/CustomGetterSetter.h_sec4
66
    }
67
    }
67
68
68
private:
69
private:
69
    CustomGetter m_getter;
70
    template<typename T>
70
    CustomSetter m_setter;
71
    using PoisonedAccessor = Poisoned<g_nativeCodePoison, T>;
72
73
    PoisonedAccessor<CustomGetter> m_getter;
74
    PoisonedAccessor<CustomSetter> m_setter;
71
};
75
};
72
76
73
JS_EXPORT_PRIVATE bool callCustomSetter(ExecState*, CustomGetterSetter::CustomSetter, bool isAccessor, JSValue thisValue, JSValue);
77
JS_EXPORT_PRIVATE bool callCustomSetter(ExecState*, CustomGetterSetter::CustomSetter, bool isAccessor, JSValue thisValue, JSValue);
- Source/JavaScriptCore/runtime/InternalFunction.cpp -2 / +2 lines
Lines 88-94 CallType InternalFunction::getCallData(J Source/JavaScriptCore/runtime/InternalFunction.cpp_sec1
88
{
88
{
89
    auto* function = jsCast<InternalFunction*>(cell);
89
    auto* function = jsCast<InternalFunction*>(cell);
90
    ASSERT(function->m_functionForCall);
90
    ASSERT(function->m_functionForCall);
91
    callData.native.function = function->m_functionForCall;
91
    callData.native.function = function->m_functionForCall.unpoisoned();
92
    return CallType::Host;
92
    return CallType::Host;
93
}
93
}
94
94
Lines 97-103 ConstructType InternalFunction::getConst Source/JavaScriptCore/runtime/InternalFunction.cpp_sec2
97
    auto* function = jsCast<InternalFunction*>(cell);
97
    auto* function = jsCast<InternalFunction*>(cell);
98
    if (function->m_functionForConstruct == callHostFunctionAsConstructor)
98
    if (function->m_functionForConstruct == callHostFunctionAsConstructor)
99
        return ConstructType::None;
99
        return ConstructType::None;
100
    constructData.native.function = function->m_functionForConstruct;
100
    constructData.native.function = function->m_functionForConstruct.unpoisoned();
101
    return ConstructType::Host;
101
    return ConstructType::Host;
102
}
102
}
103
103
- Source/JavaScriptCore/runtime/InternalFunction.h -5 / +8 lines
Lines 1-6 Source/JavaScriptCore/runtime/InternalFunction.h_sec1
1
/*
1
/*
2
 *  Copyright (C) 1999-2000 Harri Porten (porten@kde.org)
2
 *  Copyright (C) 1999-2000 Harri Porten (porten@kde.org)
3
 *  Copyright (C) 2003, 2006, 2007, 2008, 2016 Apple Inc. All rights reserved.
3
 *  Copyright (C) 2003-2017 Apple Inc. All rights reserved.
4
 *  Copyright (C) 2007 Cameron Zwarich (cwzwarich@uwaterloo.ca)
4
 *  Copyright (C) 2007 Cameron Zwarich (cwzwarich@uwaterloo.ca)
5
 *  Copyright (C) 2007 Maks Orlovich
5
 *  Copyright (C) 2007 Maks Orlovich
6
 *
6
 *
Lines 24-29 Source/JavaScriptCore/runtime/InternalFunction.h_sec2
24
#pragma once
24
#pragma once
25
25
26
#include "CodeSpecializationKind.h"
26
#include "CodeSpecializationKind.h"
27
#include "JSCPoisonedPtr.h"
27
#include "JSDestructibleObject.h"
28
#include "JSDestructibleObject.h"
28
29
29
namespace JSC {
30
namespace JSC {
Lines 55-63 public: Source/JavaScriptCore/runtime/InternalFunction.h_sec3
55
    NativeFunction nativeFunctionFor(CodeSpecializationKind kind)
56
    NativeFunction nativeFunctionFor(CodeSpecializationKind kind)
56
    {
57
    {
57
        if (kind == CodeForCall)
58
        if (kind == CodeForCall)
58
            return m_functionForCall;
59
            return m_functionForCall.unpoisoned();
59
        ASSERT(kind == CodeForConstruct);
60
        ASSERT(kind == CodeForConstruct);
60
        return m_functionForConstruct;
61
        return m_functionForConstruct.unpoisoned();
61
    }
62
    }
62
63
63
    static ptrdiff_t offsetOfNativeFunctionFor(CodeSpecializationKind kind)
64
    static ptrdiff_t offsetOfNativeFunctionFor(CodeSpecializationKind kind)
Lines 69-74 public: Source/JavaScriptCore/runtime/InternalFunction.h_sec4
69
    }
70
    }
70
71
71
protected:
72
protected:
73
    using PoisonedNativeFunction = Poisoned<g_nativeCodePoison, NativeFunction>;
74
72
    JS_EXPORT_PRIVATE InternalFunction(VM&, Structure*, NativeFunction functionForCall, NativeFunction functionForConstruct);
75
    JS_EXPORT_PRIVATE InternalFunction(VM&, Structure*, NativeFunction functionForCall, NativeFunction functionForConstruct);
73
76
74
    enum class NameVisibility { Visible, Anonymous };
77
    enum class NameVisibility { Visible, Anonymous };
Lines 79-86 protected: Source/JavaScriptCore/runtime/InternalFunction.h_sec5
79
    JS_EXPORT_PRIVATE static ConstructType getConstructData(JSCell*, ConstructData&);
82
    JS_EXPORT_PRIVATE static ConstructType getConstructData(JSCell*, ConstructData&);
80
    JS_EXPORT_PRIVATE static CallType getCallData(JSCell*, CallData&);
83
    JS_EXPORT_PRIVATE static CallType getCallData(JSCell*, CallData&);
81
84
82
    NativeFunction m_functionForCall;
85
    PoisonedNativeFunction m_functionForCall;
83
    NativeFunction m_functionForConstruct;
86
    PoisonedNativeFunction m_functionForConstruct;
84
    WriteBarrier<JSString> m_originalName;
87
    WriteBarrier<JSString> m_originalName;
85
};
88
};
86
89
- Source/JavaScriptCore/runtime/JSCPoison.h +39 lines
Line 0 Source/JavaScriptCore/runtime/JSCPoison.h_sec1
1
/*
2
 * Copyright (C) 2017 Apple Inc. All rights reserved.
3
 *
4
 * Redistribution and use in source and binary forms, with or without
5
 * modification, are permitted provided that the following conditions
6
 * are met:
7
 * 1. Redistributions of source code must retain the above copyright
8
 *    notice, this list of conditions and the following disclaimer.
9
 * 2. Redistributions in binary form must reproduce the above copyright
10
 *    notice, this list of conditions and the following disclaimer in the
11
 *    documentation and/or other materials provided with the distribution.
12
 *
13
 * THIS SOFTWARE IS PROVIDED BY APPLE INC. ``AS IS'' AND ANY
14
 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
15
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
16
 * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL APPLE INC. OR
17
 * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
18
 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
19
 * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
20
 * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY
21
 * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
22
 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
23
 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
24
 */
25
26
#pragma once
27
28
#include <wtf/Poisoned.h>
29
30
namespace JSC {
31
32
enum Poison {
33
    NotPoisoned = 0,
34
    TransitionMapPoison,
35
    WeakImplPoison,
36
};
37
38
} // namespace JSC
39
- Source/JavaScriptCore/runtime/JSCPoisonedPtr.cpp -4 / +6 lines
Lines 28-42 Source/JavaScriptCore/runtime/JSCPoisonedPtr.cpp_sec1
28
28
29
namespace JSC {
29
namespace JSC {
30
30
31
uintptr_t g_classInfoPoison;
31
uintptr_t g_globalDataPoison;
32
uintptr_t g_masmPoison;
32
uintptr_t g_jitCodePoison;
33
uintptr_t g_nativeCodePoison;
33
34
34
void initializePoison()
35
void initializePoison()
35
{
36
{
36
    static std::once_flag initializeOnceFlag;
37
    static std::once_flag initializeOnceFlag;
37
    std::call_once(initializeOnceFlag, [] {
38
    std::call_once(initializeOnceFlag, [] {
38
        g_classInfoPoison = makePoison();
39
        g_globalDataPoison = makePoison();
39
        g_masmPoison = makePoison();
40
        g_jitCodePoison = makePoison();
41
        g_nativeCodePoison = makePoison();
40
    });
42
    });
41
}
43
}
42
44
- Source/JavaScriptCore/runtime/JSCPoisonedPtr.h -4 / +5 lines
Lines 29-41 Source/JavaScriptCore/runtime/JSCPoisonedPtr.h_sec1
29
29
30
namespace JSC {
30
namespace JSC {
31
31
32
extern "C" JS_EXPORTDATA uintptr_t g_classInfoPoison;
32
extern "C" JS_EXPORTDATA uintptr_t g_globalDataPoison;
33
extern "C" JS_EXPORTDATA uintptr_t g_masmPoison;
33
extern "C" JS_EXPORTDATA uintptr_t g_jitCodePoison;
34
extern "C" JS_EXPORTDATA uintptr_t g_nativeCodePoison;
34
35
35
struct ClassInfo;
36
struct ClassInfo;
36
37
37
using PoisonedClassInfoPtr = Poisoned<g_classInfoPoison, const ClassInfo*>;
38
using PoisonedClassInfoPtr = Poisoned<g_globalDataPoison, const ClassInfo*>;
38
using PoisonedMasmPtr = Poisoned<g_masmPoison, void*>;
39
using PoisonedMasmPtr = Poisoned<g_jitCodePoison, void*>;
39
40
40
void initializePoison();
41
void initializePoison();
41
42
- Source/JavaScriptCore/runtime/NativeExecutable.cpp -4 / +4 lines
Lines 1-5 Source/JavaScriptCore/runtime/NativeExecutable.cpp_sec1
1
/*
1
/*
2
 * Copyright (C) 2009, 2010, 2013, 2015-2016 Apple Inc. All rights reserved.
2
 * Copyright (C) 2009-2017 Apple Inc. All rights reserved.
3
 *
3
 *
4
 * Redistribution and use in source and binary forms, with or without
4
 * Redistribution and use in source and binary forms, with or without
5
 * modification, are permitted provided that the following conditions
5
 * modification, are permitted provided that the following conditions
Lines 79-88 NativeExecutable::NativeExecutable(VM& v Source/JavaScriptCore/runtime/NativeExecutable.cpp_sec2
79
CodeBlockHash NativeExecutable::hashFor(CodeSpecializationKind kind) const
79
CodeBlockHash NativeExecutable::hashFor(CodeSpecializationKind kind) const
80
{
80
{
81
    if (kind == CodeForCall)
81
    if (kind == CodeForCall)
82
        return CodeBlockHash(static_cast<unsigned>(bitwise_cast<size_t>(m_function)));
82
        return CodeBlockHash(m_function.bits());
83
    
83
84
    RELEASE_ASSERT(kind == CodeForConstruct);
84
    RELEASE_ASSERT(kind == CodeForConstruct);
85
    return CodeBlockHash(static_cast<unsigned>(bitwise_cast<size_t>(m_constructor)));
85
    return CodeBlockHash(m_constructor.bits());
86
}
86
}
87
87
88
} // namespace JSC
88
} // namespace JSC
- Source/JavaScriptCore/runtime/NativeExecutable.h -4 / +6 lines
Lines 26-31 Source/JavaScriptCore/runtime/NativeExecutable.h_sec1
26
#pragma once
26
#pragma once
27
27
28
#include "ExecutableBase.h"
28
#include "ExecutableBase.h"
29
#include "JSCPoisonedPtr.h"
29
30
30
namespace JSC {
31
namespace JSC {
31
namespace DOMJIT {
32
namespace DOMJIT {
Lines 51-58 public: Source/JavaScriptCore/runtime/NativeExecutable.h_sec2
51
52
52
    CodeBlockHash hashFor(CodeSpecializationKind) const;
53
    CodeBlockHash hashFor(CodeSpecializationKind) const;
53
54
54
    NativeFunction function() { return m_function; }
55
    NativeFunction function() { return m_function.unpoisoned(); }
55
    NativeFunction constructor() { return m_constructor; }
56
    NativeFunction constructor() { return m_constructor.unpoisoned(); }
56
        
57
        
57
    NativeFunction nativeFunctionFor(CodeSpecializationKind kind)
58
    NativeFunction nativeFunctionFor(CodeSpecializationKind kind)
58
    {
59
    {
Lines 89-99 protected: Source/JavaScriptCore/runtime/NativeExecutable.h_sec3
89
90
90
private:
91
private:
91
    friend class ExecutableBase;
92
    friend class ExecutableBase;
93
    using PoisonedNativeFunction = Poisoned<g_nativeCodePoison, NativeFunction>;
92
94
93
    NativeExecutable(VM&, NativeFunction function, NativeFunction constructor, Intrinsic, const DOMJIT::Signature*);
95
    NativeExecutable(VM&, NativeFunction function, NativeFunction constructor, Intrinsic, const DOMJIT::Signature*);
94
96
95
    NativeFunction m_function;
97
    PoisonedNativeFunction m_function;
96
    NativeFunction m_constructor;
98
    PoisonedNativeFunction m_constructor;
97
    const DOMJIT::Signature* m_signature;
99
    const DOMJIT::Signature* m_signature;
98
100
99
    String m_name;
101
    String m_name;
- Source/JavaScriptCore/runtime/Structure.cpp -1 / +1 lines
Lines 86-92 inline void StructureTransitionTable::se Source/JavaScriptCore/runtime/Structure.cpp_sec1
86
    if (WeakImpl* impl = this->weakImpl())
86
    if (WeakImpl* impl = this->weakImpl())
87
        WeakSet::deallocate(impl);
87
        WeakSet::deallocate(impl);
88
    WeakImpl* impl = WeakSet::allocate(structure, &singleSlotTransitionWeakOwner(), this);
88
    WeakImpl* impl = WeakSet::allocate(structure, &singleSlotTransitionWeakOwner(), this);
89
    m_data = reinterpret_cast<intptr_t>(impl) | UsingSingleSlotFlag;
89
    m_data = PoisonedWeakImplPtr(impl).bits() | UsingSingleSlotFlag;
90
}
90
}
91
91
92
bool StructureTransitionTable::contains(UniquedStringImpl* rep, unsigned attributes) const
92
bool StructureTransitionTable::contains(UniquedStringImpl* rep, unsigned attributes) const
- Source/JavaScriptCore/runtime/StructureTransitionTable.h -3 / +6 lines
Lines 26-31 Source/JavaScriptCore/runtime/StructureTransitionTable.h_sec1
26
#pragma once
26
#pragma once
27
27
28
#include "IndexingType.h"
28
#include "IndexingType.h"
29
#include "JSCPoison.h"
29
#include "WeakGCMap.h"
30
#include "WeakGCMap.h"
30
#include <wtf/HashFunctions.h>
31
#include <wtf/HashFunctions.h>
31
#include <wtf/text/UniquedStringImpl.h>
32
#include <wtf/text/UniquedStringImpl.h>
Lines 186-191 public: Source/JavaScriptCore/runtime/StructureTransitionTable.h_sec2
186
187
187
private:
188
private:
188
    friend class SingleSlotTransitionWeakOwner;
189
    friend class SingleSlotTransitionWeakOwner;
190
    using PoisonedTransitionMapPtr = Int32Poisoned<TransitionMapPoison, TransitionMap*>;
191
    using PoisonedWeakImplPtr = Int32Poisoned<WeakImplPoison, WeakImpl*>;
189
192
190
    bool isUsingSingleSlot() const
193
    bool isUsingSingleSlot() const
191
    {
194
    {
Lines 195-207 private: Source/JavaScriptCore/runtime/StructureTransitionTable.h_sec3
195
    TransitionMap* map() const
198
    TransitionMap* map() const
196
    {
199
    {
197
        ASSERT(!isUsingSingleSlot());
200
        ASSERT(!isUsingSingleSlot());
198
        return reinterpret_cast<TransitionMap*>(m_data);
201
        return PoisonedTransitionMapPtr(m_data).unpoisoned();
199
    }
202
    }
200
203
201
    WeakImpl* weakImpl() const
204
    WeakImpl* weakImpl() const
202
    {
205
    {
203
        ASSERT(isUsingSingleSlot());
206
        ASSERT(isUsingSingleSlot());
204
        return reinterpret_cast<WeakImpl*>(m_data & ~UsingSingleSlotFlag);
207
        return PoisonedWeakImplPtr(m_data & ~UsingSingleSlotFlag).unpoisoned();
205
    }
208
    }
206
209
207
    void setMap(TransitionMap* map)
210
    void setMap(TransitionMap* map)
Lines 212-218 private: Source/JavaScriptCore/runtime/StructureTransitionTable.h_sec4
212
            WeakSet::deallocate(impl);
215
            WeakSet::deallocate(impl);
213
216
214
        // This implicitly clears the flag that indicates we're using a single transition
217
        // This implicitly clears the flag that indicates we're using a single transition
215
        m_data = reinterpret_cast<intptr_t>(map);
218
        m_data = PoisonedTransitionMapPtr(map).bits();
216
219
217
        ASSERT(!isUsingSingleSlot());
220
        ASSERT(!isUsingSingleSlot());
218
    }
221
    }
- Source/WTF/ChangeLog +29 lines
Lines 1-3 Source/WTF/ChangeLog_sec1
1
2017-12-07  Mark Lam  <mark.lam@apple.com>
2
3
        Apply poisoning to some native code pointers.
4
        https://bugs.webkit.org/show_bug.cgi?id=180541
5
        <rdar://problem/35916875>
6
7
        Reviewed by Filip Pizlo.
8
9
        Ensure that the resultant poisoned bits still looks like a pointer in that its
10
        bottom bits are 0, just like the alignment bits of a pointer.  This allows the
11
        client to use the bottom bits of the poisoned bits as flag bits just like the
12
        client was previously able to do with pointer values.
13
14
        Note: we only ensure that the bottom alignment bits of the generated poison
15
        value is 0.  We're not masking out the poisoned bits.  This means that the bottom
16
        bits of the poisoned bits will only be null if the original pointer is aligned.
17
        Hence, if the client applies the poison to an unaligned pointer, we do not lose
18
        any information on the low bits.
19
20
        Also removed 2 wrong assertions in PoisonedImpl's constructors.  We were
21
        asserting that Poisoned will never be used with a null value, but that's invalid.
22
        We do want to allow a null value so that we don't have to constantly do null
23
        checks in the clients.  This was uncovered by some layout tests.
24
25
        * wtf/Poisoned.cpp:
26
        (WTF::makePoison):
27
        * wtf/Poisoned.h:
28
        (WTF::PoisonedImpl::PoisonedImpl):
29
1
2017-12-07  Mark Lam  <mark.lam@apple.com>
30
2017-12-07  Mark Lam  <mark.lam@apple.com>
2
31
3
        [Re-landing r225620] Refactoring: Rename ScrambledPtr to Poisoned.
32
        [Re-landing r225620] Refactoring: Rename ScrambledPtr to Poisoned.
- Source/WTF/wtf/Poisoned.cpp +5 lines
Lines 39-44 uintptr_t makePoison() Source/WTF/wtf/Poisoned.cpp_sec1
39
    // cannot be 0. We ensure that it is zero so that the poisoned bits can also be
39
    // cannot be 0. We ensure that it is zero so that the poisoned bits can also be
40
    // used for a notmal zero check without needing to decoded first.
40
    // used for a notmal zero check without needing to decoded first.
41
    key |= (static_cast<uintptr_t>(0x1) << 63);
41
    key |= (static_cast<uintptr_t>(0x1) << 63);
42
    // Ensure that the bottom alignment bits are still 0 so that the poisoned bits will
43
    // still preserve the properties of a pointer where these bits are expected to be 0.
44
    // This allows the poisoned bits to be used in place of the pointer by clients that
45
    // rely on this property of pointers and sets flags in the low bits.
46
    key &= ~static_cast<uintptr_t>(0x7);
42
#else
47
#else
43
    key = 0; // Poisoning is not supported on 32-bit or non-darwin platforms yet.
48
    key = 0; // Poisoning is not supported on 32-bit or non-darwin platforms yet.
44
#endif
49
#endif
- Source/WTF/wtf/Poisoned.h -6 / +2 lines
Lines 47-63 public: Source/WTF/wtf/Poisoned.h_sec1
47
47
48
    explicit PoisonedImpl(T ptr)
48
    explicit PoisonedImpl(T ptr)
49
        : m_poisonedBits(poison(ptr))
49
        : m_poisonedBits(poison(ptr))
50
    {
50
    { }
51
        ASSERT(ptr && m_poisonedBits);
52
    }
53
51
54
    PoisonedImpl(const PoisonedImpl&) = default;
52
    PoisonedImpl(const PoisonedImpl&) = default;
55
53
56
    explicit PoisonedImpl(PoisonedBits poisonedBits)
54
    explicit PoisonedImpl(PoisonedBits poisonedBits)
57
        : m_poisonedBits(poisonedBits)
55
        : m_poisonedBits(poisonedBits)
58
    {
56
    { }
59
        ASSERT(m_poisonedBits);
60
    }
61
57
62
#if ENABLE(POISON_ASSERTS)
58
#if ENABLE(POISON_ASSERTS)
63
    template<typename U = void*>
59
    template<typename U = void*>

Return to Bug 180541