Audit JSAPI and add jsapi-tests for large ArrayBuffers
Categories
(Core :: JavaScript Engine, task, P3)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox87 | --- | fixed |
People
(Reporter: jandem, Assigned: jandem)
References
Details
Attachments
(13 files)
|
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
Bug 1674777 part 12 - Add test for XPConnect array conversions involving large typed arrays. r?kmag!
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
Details | Review |
This is not the most urgent thing to address for bug 1673557, but we should ensure we have proper tests for this eventually.
Especially the APIs that don't go through the internal accessors are easy to overlook in an audit.
| Assignee | ||
Comment 1•5 years ago
|
||
A later patch will add a jsapi-test for this.
Updated•5 years ago
|
| Assignee | ||
Comment 2•5 years ago
|
||
Depends on D103273
| Assignee | ||
Comment 3•5 years ago
|
||
Depends on D103274
| Assignee | ||
Comment 4•5 years ago
|
||
Of these four, only JS_GetTypedArrayByteLength is used outside jsapi-tests.
| Assignee | ||
Updated•5 years ago
|
Comment 6•5 years ago
|
||
| bugherder | ||
| Assignee | ||
Comment 7•5 years ago
|
||
Note that in the IndexedDB code we pass a Span to Key::EncodeAsString where we check
for large lengths.
| Assignee | ||
Comment 8•5 years ago
|
||
There's only one caller outside jsapi-tests so these are easy to convert.
Depends on D103679
| Assignee | ||
Comment 10•5 years ago
|
||
We're adding support for ArrayBuffers larger than 4 GB to the JS engine (on 64-bit
platforms).
ReadArrayBuffer uses uint32_t values in a number of places. This patch ensures we
throw an exception for code like this: stream.readArrayBuffer(ab.byteLength, ab, ...)).
| Assignee | ||
Comment 11•5 years ago
|
||
Similar to the previous patch. Prevent truncation when assigning to mBufferLength.
Depends on D103759
| Assignee | ||
Comment 12•5 years ago
|
||
Note that previous patches already fixed various other callers.
Depends on D103760
Comment 13•5 years ago
|
||
| bugherder | ||
Updated•5 years ago
|
| Assignee | ||
Comment 14•5 years ago
|
||
For enumerateNames on Xrays, throw an OOM exception upfront. This matches what we do
inside the JS engine when enumerating large typed arrays.
| Assignee | ||
Comment 15•5 years ago
|
||
The callers in AudioWorkletNode.cpp are just comparing the length to the expected length
to guard against detachment.
Depends on D103902
| Assignee | ||
Comment 16•5 years ago
|
||
| Assignee | ||
Comment 17•5 years ago
|
||
Also change wasmMaxSize and wasmMappedSize to use 'get' instead of 'deprecatedGetUint32'.
Comment 18•5 years ago
|
||
Comment 19•5 years ago
|
||
| bugherder | ||
Comment 20•5 years ago
|
||
Comment 21•5 years ago
|
||
| Assignee | ||
Updated•5 years ago
|
Comment 22•5 years ago
|
||
| bugherder | ||
https://hg.mozilla.org/mozilla-central/rev/031bc0b1e8e5
https://hg.mozilla.org/mozilla-central/rev/e23dca0763fc
https://hg.mozilla.org/mozilla-central/rev/42239f7a0ddf
Comment 23•5 years ago
|
||
| bugherder | ||
Description
•