Closed Bug 1200345 Opened 4 years ago Closed 4 years ago

JS::ubi::Node comments should mention security concerns

Categories

(Core :: JavaScript Engine, defect, minor)

defect
Not set
minor

Tracking

()

RESOLVED FIXED
mozilla43
Tracking Status
firefox43 --- fixed

People

(Reporter: jimb, Assigned: jimb)

Details

Attachments

(1 file)

Since analyses on the ubi::Node graph are operating on data influenced by content, they must be robust when consuming graphs produced by hostile code. The comments in js/public/UbiNode.h should point this out.
Attachment #8654990 - Flags: review?(nfitzgerald)
Assignee: nobody → jimb
Status: NEW → ASSIGNED
Comment on attachment 8654990 [details] [diff] [review]
Add comment to js/public/UbiNode.h warning about operating on graphs constructed by hostile code.

Review of attachment 8654990 [details] [diff] [review]:
-----------------------------------------------------------------

Awesome, thanks!
Attachment #8654990 - Flags: review?(nfitzgerald) → review+
+CC sfink, just FYI since you're the other person primarily looking at and reviewing ubi::Node stuff.
https://hg.mozilla.org/mozilla-central/rev/8985a835958c
Status: ASSIGNED → RESOLVED
Closed: 4 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla43
Thanks, I hadn't really thought about that angle. It's a good thing to keep in mind.
You need to log in before you can comment on or make changes to this bug.