Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 2676375986f3d74df26b9ebaf3b3027e51ae4a9d
      
https://github.com/WebKit/WebKit/commit/2676375986f3d74df26b9ebaf3b3027e51ae4a9d
  Author: Kristian Monsen <[email protected]>
  Date:   2026-10-01 (Thu, 01 Oct 2026)

  Changed paths:
    M Source/WebCore/Modules/webaudio/BiquadDSPKernel.cpp
    M Source/WebCore/Modules/webaudio/BiquadDSPKernel.h
    M Source/WebCore/Modules/webaudio/BiquadFilterNode.cpp
    M Source/WebCore/Modules/webaudio/BiquadProcessor.cpp
    M Source/WebCore/Modules/webaudio/BiquadProcessor.h
    M Source/WebCore/Modules/webaudio/IIRDSPKernel.cpp
    M Source/WebCore/Modules/webaudio/IIRDSPKernel.h
    M Source/WebCore/Modules/webaudio/IIRFilterNode.cpp
    M Source/WebCore/Modules/webaudio/IIRProcessor.cpp
    M Source/WebCore/Modules/webaudio/IIRProcessor.h
    M Source/WebCore/platform/audio/Biquad.cpp
    M Source/WebCore/platform/audio/Biquad.h
    M Source/WebCore/platform/audio/IIRFilter.cpp
    M Source/WebCore/platform/audio/IIRFilter.h

  Log Message:
  -----------
  Harden Biquad and IIRFilter getFrequencyResponse() by removing the 
caller-sized temporary Vector
https://bugs.webkit.org/show_bug.cgi?id=325749
rdar://188708139

Reviewed by Chris Dumez.

BiquadDSPKernel and IIRDSPKernel allocated a temporary Vector<float> sized by 
the
caller's array to hold the Hz -> normalized frequency conversion. WTF::Vector 
caps
capacity at (UINT_MAX >> 1) / sizeof(T), so any Float32Array with more than 
0x1FFFFFFF
elements hit CRASH() in allocateBuffer() before anything was allocated or 
written.
A 16GB Float32Array is legal (MAX_ARRAY_BUFFER_SIZE is 1<<34) and its pages are 
mapped
lazily, so a page could terminate the WebContent process at almost no cost. The 
crash
was fail-closed, so this is a denial of service rather than a memory-safety 
issue.

The conversion is now done inline in the loop that Biquad and IIRFilter were 
already
running over the same elements, so nothing on this path is sized by the input 
and the
limit can no longer be reached.

This costs roughly 3-4% on large inputs. As a separate pass the conversion
auto-vectorized (fcvtl plus fdiv.2d); fused into the response loop the division 
is
scalar, because that loop cannot vectorize anyway due to cos/sin/atan2. 
Chunking the
conversion into a fixed-size stack buffer recovers the difference, but the 
simpler code
was judged the better trade.

The explicit frequency count is also dropped throughout the chain, since the 
spans
already carry their size. That fixes a truncation on these same oversized 
arrays:
Float32Array::length() was narrowed to unsigned, so a 2^32-element array became 
0, making
BiquadFilterNode reject three equally sized arrays with InvalidAccessError and
IIRFilterNode silently produce no output.

The static_cast<float> on the quotient is deliberate. The previous code stored 
the
result into a Vector<float>, so it was narrowed to float before the 0..1 range 
test and
the -pi * frequency multiply. Keeping the cast preserves the existing results 
exactly.

Covered by existing tests, in particular
imported/w3c/web-platform-tests/webaudio/the-audio-api/the-biquadfilternode-interface/biquad-getFrequencyResponse.html
and
imported/w3c/web-platform-tests/webaudio/the-audio-api/the-iirfilternode-interface/iirfilter-getFrequencyResponse.html.
No new test for the crash itself: the smallest reproducing input needs three 2GB
Float32Arrays and a 536870912-element response loop taking minutes, and the 
truncation
needs three 16GB arrays and roughly twenty minutes, either of which would time 
out on
the bots.

* Source/WebCore/Modules/webaudio/BiquadDSPKernel.cpp:
(WebCore::BiquadDSPKernel::getFrequencyResponse):
* Source/WebCore/Modules/webaudio/BiquadDSPKernel.h:
* Source/WebCore/Modules/webaudio/BiquadFilterNode.cpp:
(WebCore::BiquadFilterNode::getFrequencyResponse):
* Source/WebCore/Modules/webaudio/BiquadProcessor.cpp:
(WebCore::BiquadProcessor::getFrequencyResponse):
* Source/WebCore/Modules/webaudio/BiquadProcessor.h:
* Source/WebCore/Modules/webaudio/IIRDSPKernel.cpp:
(WebCore::IIRDSPKernel::getFrequencyResponse):
* Source/WebCore/Modules/webaudio/IIRDSPKernel.h:
* Source/WebCore/Modules/webaudio/IIRFilterNode.cpp:
(WebCore::IIRFilterNode::getFrequencyResponse):
* Source/WebCore/Modules/webaudio/IIRProcessor.cpp:
(WebCore::IIRProcessor::getFrequencyResponse):
* Source/WebCore/Modules/webaudio/IIRProcessor.h:
* Source/WebCore/platform/audio/Biquad.cpp:
(WebCore::Biquad::getFrequencyResponse):
* Source/WebCore/platform/audio/Biquad.h:
* Source/WebCore/platform/audio/IIRFilter.cpp:
(WebCore::IIRFilter::getFrequencyResponse):
* Source/WebCore/platform/audio/IIRFilter.h:

Canonical link: https://commits.webkit.org/322424@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to