Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: 2676375986f3d74df26b9ebaf3b3027e51ae4a9d
https://github.com/WebKit/WebKit/commit/2676375986f3d74df26b9ebaf3b3027e51ae4a9d
Author: Kristian Monsen <[email protected]>
Date: 2026-10-01 (Thu, 01 Oct 2026)
Changed paths:
M Source/WebCore/Modules/webaudio/BiquadDSPKernel.cpp
M Source/WebCore/Modules/webaudio/BiquadDSPKernel.h
M Source/WebCore/Modules/webaudio/BiquadFilterNode.cpp
M Source/WebCore/Modules/webaudio/BiquadProcessor.cpp
M Source/WebCore/Modules/webaudio/BiquadProcessor.h
M Source/WebCore/Modules/webaudio/IIRDSPKernel.cpp
M Source/WebCore/Modules/webaudio/IIRDSPKernel.h
M Source/WebCore/Modules/webaudio/IIRFilterNode.cpp
M Source/WebCore/Modules/webaudio/IIRProcessor.cpp
M Source/WebCore/Modules/webaudio/IIRProcessor.h
M Source/WebCore/platform/audio/Biquad.cpp
M Source/WebCore/platform/audio/Biquad.h
M Source/WebCore/platform/audio/IIRFilter.cpp
M Source/WebCore/platform/audio/IIRFilter.h
Log Message:
-----------
Harden Biquad and IIRFilter getFrequencyResponse() by removing the
caller-sized temporary Vector
https://bugs.webkit.org/show_bug.cgi?id=325749
rdar://188708139
Reviewed by Chris Dumez.
BiquadDSPKernel and IIRDSPKernel allocated a temporary Vector<float> sized by
the
caller's array to hold the Hz -> normalized frequency conversion. WTF::Vector
caps
capacity at (UINT_MAX >> 1) / sizeof(T), so any Float32Array with more than
0x1FFFFFFF
elements hit CRASH() in allocateBuffer() before anything was allocated or
written.
A 16GB Float32Array is legal (MAX_ARRAY_BUFFER_SIZE is 1<<34) and its pages are
mapped
lazily, so a page could terminate the WebContent process at almost no cost. The
crash
was fail-closed, so this is a denial of service rather than a memory-safety
issue.
The conversion is now done inline in the loop that Biquad and IIRFilter were
already
running over the same elements, so nothing on this path is sized by the input
and the
limit can no longer be reached.
This costs roughly 3-4% on large inputs. As a separate pass the conversion
auto-vectorized (fcvtl plus fdiv.2d); fused into the response loop the division
is
scalar, because that loop cannot vectorize anyway due to cos/sin/atan2.
Chunking the
conversion into a fixed-size stack buffer recovers the difference, but the
simpler code
was judged the better trade.
The explicit frequency count is also dropped throughout the chain, since the
spans
already carry their size. That fixes a truncation on these same oversized
arrays:
Float32Array::length() was narrowed to unsigned, so a 2^32-element array became
0, making
BiquadFilterNode reject three equally sized arrays with InvalidAccessError and
IIRFilterNode silently produce no output.
The static_cast<float> on the quotient is deliberate. The previous code stored
the
result into a Vector<float>, so it was narrowed to float before the 0..1 range
test and
the -pi * frequency multiply. Keeping the cast preserves the existing results
exactly.
Covered by existing tests, in particular
imported/w3c/web-platform-tests/webaudio/the-audio-api/the-biquadfilternode-interface/biquad-getFrequencyResponse.html
and
imported/w3c/web-platform-tests/webaudio/the-audio-api/the-iirfilternode-interface/iirfilter-getFrequencyResponse.html.
No new test for the crash itself: the smallest reproducing input needs three 2GB
Float32Arrays and a 536870912-element response loop taking minutes, and the
truncation
needs three 16GB arrays and roughly twenty minutes, either of which would time
out on
the bots.
* Source/WebCore/Modules/webaudio/BiquadDSPKernel.cpp:
(WebCore::BiquadDSPKernel::getFrequencyResponse):
* Source/WebCore/Modules/webaudio/BiquadDSPKernel.h:
* Source/WebCore/Modules/webaudio/BiquadFilterNode.cpp:
(WebCore::BiquadFilterNode::getFrequencyResponse):
* Source/WebCore/Modules/webaudio/BiquadProcessor.cpp:
(WebCore::BiquadProcessor::getFrequencyResponse):
* Source/WebCore/Modules/webaudio/BiquadProcessor.h:
* Source/WebCore/Modules/webaudio/IIRDSPKernel.cpp:
(WebCore::IIRDSPKernel::getFrequencyResponse):
* Source/WebCore/Modules/webaudio/IIRDSPKernel.h:
* Source/WebCore/Modules/webaudio/IIRFilterNode.cpp:
(WebCore::IIRFilterNode::getFrequencyResponse):
* Source/WebCore/Modules/webaudio/IIRProcessor.cpp:
(WebCore::IIRProcessor::getFrequencyResponse):
* Source/WebCore/Modules/webaudio/IIRProcessor.h:
* Source/WebCore/platform/audio/Biquad.cpp:
(WebCore::Biquad::getFrequencyResponse):
* Source/WebCore/platform/audio/Biquad.h:
* Source/WebCore/platform/audio/IIRFilter.cpp:
(WebCore::IIRFilter::getFrequencyResponse):
* Source/WebCore/platform/audio/IIRFilter.h:
Canonical link: https://commits.webkit.org/322424@main
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications