Closed Bug 1970438 Opened 1 year ago Closed 1 year ago

With self-hosted cache enabled, GC-UAF crash on a demo

Categories

(Core :: JavaScript Engine, defect, P2)

defect

Tracking

()

RESOLVED FIXED
144 Branch
Tracking Status
firefox-esr115 --- unaffected
firefox-esr128 --- unaffected
firefox-esr140 --- disabled
firefox139 --- unaffected
firefox140 --- disabled
firefox141 --- disabled
firefox142 --- disabled
firefox143 --- disabled
firefox144 + fixed

People

(Reporter: mayankleoboy1, Assigned: bthrall)

References

(Blocks 1 open bug, Regression)

Details

(5 keywords)

Crash Data

Attachments

(1 file)

48 bytes, text/x-phabricator-request
Details | Review

enable self-host cache
Go to this link
Click on play

AR: Crash.

I do not crash on a fresh profile, but repro consistently on my daily profile which has a bunch of addons. I tried disabling some, but couldnt find any pattern. Maybe their presence changes some timing or threshold and that causes crash?

Most of the generated crashes do not have appropriate symbol. Example: https://crash-stats.mozilla.org/report/index/5120a3d4-d57b-4054-b1b8-455340250604

Some Crashes do have known signatures :
https://crash-stats.mozilla.org/report/index/aef28a4e-6a80-4f6f-8ad8-4b4b10250604
https://crash-stats.mozilla.org/report/index/385fefa2-c7f3-43bb-8515-b46fe0250604

Duplicate of this bug: 1970431
See Also: → 1970429

Set release status flags based on info from the regressing bug 1827914

:bthrall, since you are the author of the regressor, bug 1827914, could you take a look? Also, could you set the severity field?

For more information, please visit BugBot documentation.

See Also: → 1970164

The bug is linked to a topcrash signature, which matches the following criteria:

  • Top 20 desktop browser crashes on release (startup)
  • Top 20 desktop browser crashes on beta
  • Top 10 content process crashes on release
  • Top 10 AArch64 and ARM crashes on release (startup)

For more information, please visit BugBot documentation.

It looks like the crash signature is clashing with unrelated crashes, since bug 1827914 was only merged as of Firefox 140 and a lot of these crashes are happening on earlier versions.

Filtering the crash reports looking for the poison address 0x4b4b4b, which shows up in Mayank's crashes, only shows about 43 potential crashes.

Since this should only affect systems where self_hosted_cache is turned on (it is off by default), I think this shouldn't have a high severity right now.

Blocks: sm-jits
Severity: -- → S4
Flags: needinfo?(bthrall)

I am removing the crash signature and the top-crash keyword from this bug. The crash signature is a little generic now, so bmo conflates it with existing crashes. This bug is specific to enabling the selfhost cache.

Crash Signature: [@ EnterJit ] [@ xpc::StackScopedClone ]

Copying crash signatures from duplicate bugs.

Crash Signature: [@ xpc::StackScopedClone]
Blocks: 1870391
No longer blocks: sm-jits
Priority: -- → P2

This is the latest crash report: https://crash-stats.mozilla.org/report/index/1e235022-d3be-419b-b8d5-9fca50250610#tab-bugzilla
Now the signature says [@ EnterJit ]

Set release status flags based on info from the regressing bug 1827914

Blocks: sm-early-sh-compile
No longer blocks: 1870391

This is insanely helpful. On my profile this crashes every time with a signature we've been seeking. I'm going to try and see if I can reproduce in an rr recording

Thank you very much Mayank.

I nerd-sniped myself a bit on this.

I'm pretty sure that the problem here is the pre-barrier code here. It looks like it should work for realm-independent code, but to decide whether it can bake in a realm, it checks whether there's a compile realm set on the macroassembler, which is apparently still the case even though we're trying to generate realm-independent code.

We should probably ensure the compile-realm is null in this case.

I saw this crash in my about:crashes: https://crash-stats.mozilla.org/report/index/05c8589b-0708-4c7c-969f-5cbc70250808#tab-details

No idea how/when it happened.

Duplicate of this bug: 1981780

The severity field for this bug is set to S4. However, the following bug duplicate has higher severity:

:sdetar, could you consider increasing the severity of this bug to S3?

For more information, please visit BugBot documentation.

Flags: needinfo?(sdetar)
Flags: needinfo?(sdetar)
Attached file (secure) —

When a Realm is present, MacroAssembler::branchTestNeedsIncrementalBarrier()
bakes a pointer specific to the Realm's Zone into the bytecode, making it not
Realm-independent.

Assignee: nobody → bthrall
Status: NEW → ASSIGNED

This should probably be marked as security-sensitive, since it's a UAF. It's quite slow/difficult to reproduce even with testing functions, and relies on precise timing, so I'll mark it as sec-moderate. Note that this feature is disabled in all releases.

Group: javascript-core-security

Copying crash signatures from duplicate bugs.

Crash Signature: [@ xpc::StackScopedClone] → [@ xpc::StackScopedClone] [@ JSObject::getClass() const]
Duplicate of this bug: 1982184
Attachment #9506933 - Attachment description: Bug 1970438 - Compile with nullptr Realm for realmIndependentJitCode r=iain! → (secure)
Crash Signature: [@ xpc::StackScopedClone] [@ JSObject::getClass() const] → [@ xpc::StackScopedClone] [@ JSObject::getClass() const]
Flags: sec-bounty?
Group: javascript-core-security → core-security-release
Status: ASSIGNED → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Target Milestone: --- → 144 Branch
Flags: sec-bounty? → sec-bounty+
Summary: With self-hosted cache enabled, crash on a demo → With self-hosted cache enabled, GC-UAF crash on a demo
Regressions: 1985224

Bug Bounty note: We are not changing the bounty we have already awarded on this bug, but we do need to note that in retrospect we realized this bug is technically ineligible for a bounty. Features have to be enabled by default in at least Nightly to be eligible.

We note this so you don't have the wrong expectations about future bounties for self-hosted cache or other disabled features.

Group: core-security-release
Keywords: csectype-race
QA Whiteboard: [qa-triage-done-c145/b144]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: