Diff
Modified: trunk/Source/WebCore/ChangeLog (278781 => 278782)
--- trunk/Source/WebCore/ChangeLog 2021-06-11 20:59:51 UTC (rev 278781)
+++ trunk/Source/WebCore/ChangeLog 2021-06-11 21:21:31 UTC (rev 278782)
@@ -1,3 +1,24 @@
+2021-06-11 Yusuke Suzuki <[email protected]>
+
+ Add fast-path for binding security check of DOMWindow
+ https://bugs.webkit.org/show_bug.cgi?id=226930
+
+ Reviewed by Geoffrey Garen.
+
+ The security check[1] must pass if the current JSDOMGlobalObject is the same to the accessed JSDOMWindow.
+ This clarification paves the way to emit JIT code which removes this security check when the lexical and
+ accessed JSGlobalObjects are the same.
+
+ [1]: https://html.spec.whatwg.org/multipage/browsers.html#integration-with-idl
+
+ * bindings/js/JSDOMBindingSecurity.cpp:
+ (WebCore::BindingSecurity::shouldAllowAccessToDOMWindow):
+ * bindings/js/JSDOMBindingSecurity.h:
+ * bindings/scripts/CodeGeneratorJS.pm:
+ (GenerateAttributeGetterBodyDefinition):
+ (GenerateAttributeSetterBodyDefinition):
+ (GenerateOperationBodyDefinition):
+
2021-06-11 Jonathan Bedard <[email protected]>
[Monterey] Support building WebKit
Modified: trunk/Source/WebCore/WebCore.xcodeproj/project.pbxproj (278781 => 278782)
--- trunk/Source/WebCore/WebCore.xcodeproj/project.pbxproj 2021-06-11 20:59:51 UTC (rev 278781)
+++ trunk/Source/WebCore/WebCore.xcodeproj/project.pbxproj 2021-06-11 21:21:31 UTC (rev 278782)
@@ -5183,6 +5183,7 @@
E3C04138254CB30D0021D0E6 /* SystemSoundDelegate.h in Headers */ = {isa = PBXBuildFile; fileRef = E3C04131254CA6660021D0E6 /* SystemSoundDelegate.h */; settings = {ATTRIBUTES = (Private, ); }; };
E3C99A091DC3D41C00794AD3 /* DOMJITCheckDOM.h in Headers */ = {isa = PBXBuildFile; fileRef = E3C99A081DC3D41700794AD3 /* DOMJITCheckDOM.h */; };
E3C9AECB2113149900419B92 /* JSMicrotaskCallback.h in Headers */ = {isa = PBXBuildFile; fileRef = E3C9AEC92113147400419B92 /* JSMicrotaskCallback.h */; };
+ E3CA0BFC2673F47C009FDD67 /* JSDOMBindingSecurityInlines.h in Headers */ = {isa = PBXBuildFile; fileRef = E3CA0BFA2673F478009FDD67 /* JSDOMBindingSecurityInlines.h */; settings = {ATTRIBUTES = (Private, ); }; };
E3E4E2A81E3B17100023BB8A /* ScriptElementCachedScriptFetcher.h in Headers */ = {isa = PBXBuildFile; fileRef = E3E4E2A61E3B16FC0023BB8A /* ScriptElementCachedScriptFetcher.h */; settings = {ATTRIBUTES = (Private, ); }; };
E3FA38641D71812D00AA5950 /* PendingScriptClient.h in Headers */ = {isa = PBXBuildFile; fileRef = E3FA38611D716E7600AA5950 /* PendingScriptClient.h */; };
E401C27517CE53EC00C41A35 /* ElementIteratorAssertions.h in Headers */ = {isa = PBXBuildFile; fileRef = E401C27417CE53EC00C41A35 /* ElementIteratorAssertions.h */; settings = {ATTRIBUTES = (Private, ); }; };
@@ -16529,6 +16530,7 @@
E3C04132254CA7110021D0E6 /* SystemSoundManager.cpp */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.cpp.cpp; path = SystemSoundManager.cpp; sourceTree = "<group>"; };
E3C99A081DC3D41700794AD3 /* DOMJITCheckDOM.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = DOMJITCheckDOM.h; sourceTree = "<group>"; };
E3C9AEC92113147400419B92 /* JSMicrotaskCallback.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = JSMicrotaskCallback.h; sourceTree = "<group>"; };
+ E3CA0BFA2673F478009FDD67 /* JSDOMBindingSecurityInlines.h */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.c.h; path = JSDOMBindingSecurityInlines.h; sourceTree = "<group>"; };
E3D049931DADC04500718F3C /* NodeConstants.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = NodeConstants.h; sourceTree = "<group>"; };
E3E4E2A51E3B16FC0023BB8A /* ScriptElementCachedScriptFetcher.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = ScriptElementCachedScriptFetcher.cpp; sourceTree = "<group>"; };
E3E4E2A61E3B16FC0023BB8A /* ScriptElementCachedScriptFetcher.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = ScriptElementCachedScriptFetcher.h; sourceTree = "<group>"; };
@@ -27491,6 +27493,7 @@
41DEFCB21E56C1B9000D9E5F /* JSDOMBindingInternals.js */,
7C45C9CA1E3E8D2E00AAB558 /* JSDOMBindingSecurity.cpp */,
7C45C9C91E3E8CD700AAB558 /* JSDOMBindingSecurity.h */,
+ E3CA0BFA2673F478009FDD67 /* JSDOMBindingSecurityInlines.h */,
841C4414260C38BA00FF6673 /* JSDOMCastThisValue.h */,
7C45C9CC1E3E8F0800AAB558 /* JSDOMExceptionHandling.cpp */,
7C45C9C71E3E8AFF00AAB558 /* JSDOMExceptionHandling.h */,
@@ -32640,6 +32643,7 @@
E4A8D21622578DB700A8463C /* EventRegion.h in Headers */,
E0FEF372B17C53EAC1C1FBEE /* EventSource.h in Headers */,
E12EDB7B0B308A78002704B6 /* EventTarget.h in Headers */,
+ E3CA0BFC2673F47C009FDD67 /* JSDOMBindingSecurityInlines.h in Headers */,
84B349A222F86E7500D47BCF /* EventTargetConcrete.h in Headers */,
97AA3CA5145237CC003E1DA6 /* EventTargetHeaders.h in Headers */,
97AA3CA6145237CC003E1DA6 /* EventTargetInterfaces.h in Headers */,
Added: trunk/Source/WebCore/bindings/js/JSDOMBindingSecurityInlines.h (0 => 278782)
--- trunk/Source/WebCore/bindings/js/JSDOMBindingSecurityInlines.h (rev 0)
+++ trunk/Source/WebCore/bindings/js/JSDOMBindingSecurityInlines.h 2021-06-11 21:21:31 UTC (rev 278782)
@@ -0,0 +1,42 @@
+/*
+ * Copyright (C) 2021 Apple Inc. All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ * notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ * notice, this list of conditions and the following disclaimer in the
+ * documentation and/or other materials provided with the distribution.
+ *
+ * THIS SOFTWARE IS PROVIDED BY APPLE INC. AND ITS CONTRIBUTORS ``AS IS''
+ * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
+ * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
+ * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL APPLE INC. OR ITS CONTRIBUTORS
+ * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
+ * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
+ * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
+ * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
+ * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
+ * THE POSSIBILITY OF SUCH DAMAGE.
+ */
+
+#pragma once
+
+#include "JSDOMBindingSecurity.h"
+#include "JSDOMWindow.h"
+
+namespace WebCore {
+namespace BindingSecurity {
+
+inline bool shouldAllowAccessToDOMWindow(JSC::JSGlobalObject* lexicalGlobalObject, JSDOMWindow& target, SecurityReportingOption reportingOption = LogSecurityError)
+{
+ if (LIKELY(lexicalGlobalObject == &target))
+ return true;
+ return shouldAllowAccessToDOMWindow(lexicalGlobalObject, target.wrapped(), reportingOption);
+}
+
+} // namespace BindingSecurity
+} // namespace WebCore
Modified: trunk/Source/WebCore/bindings/scripts/CodeGeneratorJS.pm (278781 => 278782)
--- trunk/Source/WebCore/bindings/scripts/CodeGeneratorJS.pm 2021-06-11 20:59:51 UTC (rev 278781)
+++ trunk/Source/WebCore/bindings/scripts/CodeGeneratorJS.pm 2021-06-11 21:21:31 UTC (rev 278782)
@@ -5210,10 +5210,11 @@
}
if ($needSecurityCheck) {
- AddToImplIncludes("JSDOMBindingSecurity.h", $conditional);
if ($interface->type->name eq "DOMWindow") {
- push(@$outputArray, " bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(&lexicalGlobalObject, thisObject.wrapped(), ThrowSecurityError);\n");
+ AddToImplIncludes("JSDOMBindingSecurityInlines.h", $conditional);
+ push(@$outputArray, " bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(&lexicalGlobalObject, thisObject, ThrowSecurityError);\n");
} else {
+ AddToImplIncludes("JSDOMBindingSecurity.h", $conditional);
push(@$outputArray, " bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(&lexicalGlobalObject, thisObject.wrapped().window(), ThrowSecurityError);\n");
}
push(@$outputArray, " EXCEPTION_ASSERT_UNUSED(throwScope, !throwScope.exception() || !shouldAllowAccess);\n");
@@ -5367,10 +5368,11 @@
GenerateCustomElementReactionsStackIfNeeded($outputArray, $attribute, "lexicalGlobalObject");
if ($needSecurityCheck) {
- AddToImplIncludes("JSDOMBindingSecurity.h", $conditional);
if ($interface->type->name eq "DOMWindow") {
- push(@$outputArray, " bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(&lexicalGlobalObject, thisObject.wrapped(), ThrowSecurityError);\n");
+ AddToImplIncludes("JSDOMBindingSecurityInlines.h", $conditional);
+ push(@$outputArray, " bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(&lexicalGlobalObject, thisObject, ThrowSecurityError);\n");
} else {
+ AddToImplIncludes("JSDOMBindingSecurity.h", $conditional);
push(@$outputArray, " bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(&lexicalGlobalObject, thisObject.wrapped().window(), ThrowSecurityError);\n");
}
push(@$outputArray, " EXCEPTION_ASSERT_UNUSED(throwScope, !throwScope.exception() || !shouldAllowAccess);\n");
@@ -5579,10 +5581,11 @@
if ($interface->extendedAttributes->{CheckSecurity} and !$operation->extendedAttributes->{DoNotCheckSecurity}) {
assert("Security checks are not supported for static operations.") if $operation->isStatic;
- AddToImplIncludes("JSDOMBindingSecurity.h", $conditional);
if ($interface->type->name eq "DOMWindow") {
- push(@$outputArray, " bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(lexicalGlobalObject, castedThis->wrapped(), ThrowSecurityError);\n");
+ AddToImplIncludes("JSDOMBindingSecurityInlines.h", $conditional);
+ push(@$outputArray, " bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(lexicalGlobalObject, *castedThis, ThrowSecurityError);\n");
} else {
+ AddToImplIncludes("JSDOMBindingSecurity.h", $conditional);
push(@$outputArray, " bool shouldAllowAccess = BindingSecurity::shouldAllowAccessToDOMWindow(lexicalGlobalObject, castedThis->wrapped().window(), ThrowSecurityError);\n");
}
push(@$outputArray, " EXCEPTION_ASSERT_UNUSED(throwScope, !throwScope.exception() || !shouldAllowAccess);\n");