<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>181539</bug_id>
          
          <creation_ts>2018-01-11 09:37:39 -0800</creation_ts>
          <short_desc>Reserve a fast TLS key for GC TLC</short_desc>
          <delta_ts>2018-01-11 10:00:18 -0800</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Web Template Framework</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Filip Pizlo">fpizlo</reporter>
          <assigned_to name="Filip Pizlo">fpizlo</assigned_to>
          <cc>benjamin</cc>
    
    <cc>cdumez</cc>
    
    <cc>cmarcelo</cc>
    
    <cc>dbates</cc>
    
    <cc>ews-watchlist</cc>
    
    <cc>webkit-bug-importer</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1388263</commentid>
    <comment_count>0</comment_count>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2018-01-11 09:37:39 -0800</bug_when>
    <thetext>Who knew that thread-local caches would be an essential mitigation for timing attacks.  But here&apos;s how it works: if we have TLCs then we can &quot;context switch&quot; them when we &quot;context switch&quot; origins.  This allows us to put some minimal distance between objects from different origins, which gives us the ability to allow small overflows when doing certain bounds checks without creating a useful Spectre information leak.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1388264</commentid>
    <comment_count>1</comment_count>
      <attachid>331061</attachid>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2018-01-11 09:48:31 -0800</bug_when>
    <thetext>Created attachment 331061
the patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1388274</commentid>
    <comment_count>2</comment_count>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2018-01-11 09:59:26 -0800</bug_when>
    <thetext>Landed in http://trac.webkit.org/changeset/226784/webkit</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1388275</commentid>
    <comment_count>3</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2018-01-11 10:00:18 -0800</bug_when>
    <thetext>&lt;rdar://problem/36441606&gt;</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>331061</attachid>
            <date>2018-01-11 09:48:31 -0800</date>
            <delta_ts>2018-01-11 09:56:05 -0800</delta_ts>
            <desc>the patch</desc>
            <filename>blah.patch</filename>
            <type>text/plain</type>
            <size>1785</size>
            <attacher name="Filip Pizlo">fpizlo</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XVEYvQ2hhbmdlTG9nCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFNvdXJjZS9XVEYvQ2hh
bmdlTG9nCShyZXZpc2lvbiAyMjY3ODMpCisrKyBTb3VyY2UvV1RGL0NoYW5nZUxvZwkod29ya2lu
ZyBjb3B5KQpAQCAtMSwzICsxLDIxIEBACisyMDE4LTAxLTExICBGaWxpcCBQaXpsbyAgPGZwaXps
b0BhcHBsZS5jb20+CisKKyAgICAgICAgUmVzZXJ2ZSBhIGZhc3QgVExTIGtleSBmb3IgR0MgVExD
CisgICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD0xODE1MzkK
KworICAgICAgICBSZXZpZXdlZCBieSBOT0JPRFkgKE9PUFMhKS4KKyAgICAgICAgCisgICAgICAg
IFdobyBrbmV3IHRoYXQgdGhyZWFkLWxvY2FsIGNhY2hlcyB3b3VsZCBiZSBhIG1pdGlnYXRpb24g
Zm9yIHRpbWluZyBhdHRhY2tzLiBIZXJlJ3MgaG93IGl0CisgICAgICAgIHdvcmtzOiBpZiB3ZSBo
YXZlIFRMQ3MgdGhlbiB3ZSBjYW4gImNvbnRleHQgc3dpdGNoIiB0aGVtIHdoZW4gd2UgImNvbnRl
eHQgc3dpdGNoIiBvcmlnaW5zLiAKKyAgICAgICAgVGhpcyBhbGxvd3MgdXMgdG8gcHV0IHNvbWUg
bWluaW1hbCBkaXN0YW5jZSBiZXR3ZWVuIG9iamVjdHMgZnJvbSBkaWZmZXJlbnQgb3JpZ2lucywg
d2hpY2gKKyAgICAgICAgZ2l2ZXMgdXMgdGhlIGFiaWxpdHkgdG8gYWxsb3cgc21hbGwgb3ZlcmZs
b3dzIHdoZW4gZG9pbmcgY2VydGFpbiBib3VuZHMgY2hlY2tzIHdpdGhvdXQKKyAgICAgICAgY3Jl
YXRpbmcgYSB1c2VmdWwgU3BlY3RyZSBpbmZvcm1hdGlvbiBsZWFrLgorICAgICAgICAKKyAgICAg
ICAgU28gSSB0aGluayB0aGF0IG1lYW5zIHdlIGhhdmUgdG8gaW1wbGVtZW50IHRocmVhZC1sb2Nh
bCBjYWNoZXMgKGFsc28ga25vd24gYXMgdGhyZWFkLWxvY2FsCisgICAgICAgIGFsbG9jYXRpb24g
YnVmZmVycywgYnV0IEkgcHJlZmVyIHRoZSBUTEMgdGVybWlub2xvZ3kpLgorCisgICAgICAgICog
d3RmL0Zhc3RUTFMuaDoKKwogMjAxOC0wMS0wNCAgRmlsaXAgUGl6bG8gIDxmcGl6bG9AYXBwbGUu
Y29tPgogCiAgICAgICAgIENvZGVCbG9ja3Mgc2hvdWxkIGJlIGluIElzb1N1YnNwYWNlcwpJbmRl
eDogU291cmNlL1dURi93dGYvRmFzdFRMUy5oCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIFNvdXJjZS9XVEYvd3Rm
L0Zhc3RUTFMuaAkocmV2aXNpb24gMjI2NzgzKQorKysgU291cmNlL1dURi93dGYvRmFzdFRMUy5o
CSh3b3JraW5nIGNvcHkpCkBAIC00NSw3ICs0NSw4IEBAIG5hbWVzcGFjZSBXVEYgewogCiAjZGVm
aW5lIFdURl9USFJFQURfREFUQV9LRVkgV1RGX0ZBU1RfVExTX0tFWTAKICNkZWZpbmUgV1RGX1dB
U01fQ09OVEVYVF9LRVkgV1RGX0ZBU1RfVExTX0tFWTEKLSNkZWZpbmUgV1RGX1RFU1RJTkdfS0VZ
IFdURl9GQVNUX1RMU19LRVkyCisjZGVmaW5lIFdURl9URVNUSU5HX0tFWSBXVEZfV0FTTV9DT05U
RVhUX0tFWSAvLyBTbyBmYXIsIHRoaXMga2V5IGlzIG9ubHkgdXNlZCBpbiBwbGFjZXMgdGhhdCBk
b24ndCBkbyBXZWJBc3NlbWJseSwgc28gaXQncyBPSyB0aGF0IHRoZXkgc2hhcmUgdGhlIHNhbWUg
a2V5LgorI2RlZmluZSBXVEZfR0NfVExDX0tFWSBXVEZfRkFTVF9UTFNfS0VZMgogCiAjaWYgRU5B
QkxFKEZBU1RfVExTX0pJVCkKIGlubGluZSB1bnNpZ25lZCBmYXN0VExTT2Zmc2V0Rm9yS2V5KHVu
c2lnbmVkIGxvbmcgc2xvdCkK
</data>
<flag name="review"
          id="350055"
          type_id="1"
          status="+"
          setter="ap"
    />
          </attachment>
      

    </bug>

</bugzilla>