Bug 179448

Summary: Let's make the gigacage runway 32GB
Product: WebKit Reporter: Saam Barati <saam>
Component: JavaScriptCoreAssignee: Saam Barati <saam>
Status: RESOLVED DUPLICATE    
Severity: Normal CC: benjamin, fpizlo, ggaren, gskachkov, jfbastien, keith_miller, mark.lam, msaboff, rmorisset, ticaiolima, ysuzuki
Priority: P2    
Version: WebKit Nightly Build   
Hardware: Unspecified   
OS: Unspecified   

Saam Barati
Reported 2017-11-08 14:26:20 PST
This will prevent (almost) all buffer overflows from reaching passed other things in the cage. The reason being, is we use 32-bits as indexes for things, and: 2^32 * sizeof(JSValue) = 2^32 * 8 = 32GB
Attachments
Saam Barati
Comment 1 2017-11-13 20:56:24 PST
*** This bug has been marked as a duplicate of bug 175062 ***
Note You need to log in before you can comment on or make changes to this bug.