Title: [179707] trunk/Source/WebKit2
Revision
179707
Author
[email protected]
Date
2015-02-05 14:13:10 -0800 (Thu, 05 Feb 2015)

Log Message

[WK2] Properly check for mmap() error case
https://bugs.webkit.org/show_bug.cgi?id=141304

Reviewed by Anders Carlsson.

mmap() returns MAP_FAILED, which is (void*)-1, not a null pointer in
case of failure. This patch updates several wrong error checks in
WebKit2.

* Platform/IPC/ArgumentEncoder.cpp:
(IPC::allocBuffer):
(IPC::ArgumentEncoder::reserve):
* Platform/IPC/mac/ConnectionMac.mm:
(IPC::Connection::sendOutgoingMessage):

Modified Paths

Diff

Modified: trunk/Source/WebKit2/ChangeLog (179706 => 179707)


--- trunk/Source/WebKit2/ChangeLog	2015-02-05 21:55:45 UTC (rev 179706)
+++ trunk/Source/WebKit2/ChangeLog	2015-02-05 22:13:10 UTC (rev 179707)
@@ -1,3 +1,20 @@
+2015-02-05  Chris Dumez  <[email protected]>
+
+        [WK2] Properly check for mmap() error case
+        https://bugs.webkit.org/show_bug.cgi?id=141304
+
+        Reviewed by Anders Carlsson.
+
+        mmap() returns MAP_FAILED, which is (void*)-1, not a null pointer in
+        case of failure. This patch updates several wrong error checks in
+        WebKit2.
+
+        * Platform/IPC/ArgumentEncoder.cpp:
+        (IPC::allocBuffer):
+        (IPC::ArgumentEncoder::reserve):
+        * Platform/IPC/mac/ConnectionMac.mm:
+        (IPC::Connection::sendOutgoingMessage):
+
 2015-02-05  Brian J. Burg  <[email protected]>
 
         Clean up WebInspectorProxy and use simpler inspector levels design

Modified: trunk/Source/WebKit2/Platform/IPC/ArgumentEncoder.cpp (179706 => 179707)


--- trunk/Source/WebKit2/Platform/IPC/ArgumentEncoder.cpp	2015-02-05 21:55:45 UTC (rev 179706)
+++ trunk/Source/WebKit2/Platform/IPC/ArgumentEncoder.cpp	2015-02-05 22:13:10 UTC (rev 179707)
@@ -36,12 +36,15 @@
 
 namespace IPC {
 
-static inline void* allocBuffer(size_t size)
+template <typename T>
+static inline bool allocBuffer(T*& buffer, size_t size)
 {
 #if OS(DARWIN)
-    return mmap(0, size, PROT_READ | PROT_WRITE, MAP_ANON | MAP_PRIVATE, -1, 0);
+    buffer = static_cast<T*>(mmap(0, size, PROT_READ | PROT_WRITE, MAP_ANON | MAP_PRIVATE, -1, 0));
+    return buffer != MAP_FAILED;
 #else
-    return fastMalloc(size);
+    buffer = static_cast<T*>(fastMalloc(size));
+    return !!buffer;
 #endif
 }
 
@@ -90,8 +93,8 @@
     while (newCapacity < size)
         newCapacity *= 2;
 
-    uint8_t* newBuffer = static_cast<uint8_t*>(allocBuffer(newCapacity));
-    if (!newBuffer)
+    uint8_t* newBuffer;
+    if (!allocBuffer(newBuffer, newCapacity))
         CRASH();
 
     memcpy(newBuffer, m_buffer, m_bufferSize);

Modified: trunk/Source/WebKit2/Platform/IPC/mac/ConnectionMac.mm (179706 => 179707)


--- trunk/Source/WebKit2/Platform/IPC/mac/ConnectionMac.mm	2015-02-05 21:55:45 UTC (rev 179706)
+++ trunk/Source/WebKit2/Platform/IPC/mac/ConnectionMac.mm	2015-02-05 22:13:10 UTC (rev 179707)
@@ -283,8 +283,11 @@
 
     char stackBuffer[inlineMessageMaxSize];
     char* buffer = &stackBuffer[0];
-    if (messageSize > inlineMessageMaxSize)
+    if (messageSize > inlineMessageMaxSize) {
         buffer = (char*)mmap(0, messageSize, PROT_READ | PROT_WRITE, MAP_ANON | MAP_PRIVATE, -1, 0);
+        if (buffer == MAP_FAILED)
+            return false;
+    }
 
     bool isComplex = (numberOfPortDescriptors + numberOfOOLMemoryDescriptors > 0);
 
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to