Let's scramble ClassInfo pointers in cells.
authormark.lam@apple.com <mark.lam@apple.com@268f45cc-cd09-0410-ab3c-d52691b4dbfc>
Sat, 2 Dec 2017 01:12:48 +0000 (01:12 +0000)
committermark.lam@apple.com <mark.lam@apple.com@268f45cc-cd09-0410-ab3c-d52691b4dbfc>
Sat, 2 Dec 2017 01:12:48 +0000 (01:12 +0000)
https://bugs.webkit.org/show_bug.cgi?id=180291
<rdar://problem/35807620>

Reviewed by JF Bastien.

Source/JavaScriptCore:

* API/JSCallbackObject.h:
* API/JSObjectRef.cpp:
(classInfoPrivate):
* JavaScriptCore.xcodeproj/project.pbxproj:
* Sources.txt:
* assembler/MacroAssemblerCodeRef.cpp:
(JSC::MacroAssemblerCodePtr::initialize): Deleted.
* assembler/MacroAssemblerCodeRef.h:
(JSC::MacroAssemblerCodePtr:: const):
(JSC::MacroAssemblerCodePtr::hash const):
* dfg/DFGSpeculativeJIT.cpp:
(JSC::DFG::SpeculativeJIT::checkArray):
(JSC::DFG::SpeculativeJIT::compileCheckSubClass):
(JSC::DFG::SpeculativeJIT::compileNewStringObject):
* ftl/FTLLowerDFGToB3.cpp:
(JSC::FTL::DFG::LowerDFGToB3::compileNewStringObject):
(JSC::FTL::DFG::LowerDFGToB3::compileCheckSubClass):
* jit/AssemblyHelpers.h:
(JSC::AssemblyHelpers::emitAllocateDestructibleObject):
* jit/SpecializedThunkJIT.h:
(JSC::SpecializedThunkJIT::loadArgumentWithSpecificClass):
* runtime/InitializeThreading.cpp:
(JSC::initializeThreading):
* runtime/JSCScrambledPtr.cpp: Added.
(JSC::initializeScrambledPtrKeys):
* runtime/JSCScrambledPtr.h: Added.
* runtime/JSDestructibleObject.h:
(JSC::JSDestructibleObject::classInfo const):
* runtime/JSSegmentedVariableObject.h:
(JSC::JSSegmentedVariableObject::classInfo const):
* runtime/Structure.h:
* runtime/VM.h:

Source/WTF:

* wtf/ScrambledPtr.h:
(WTF::ScrambledPtr::descrambled const):
(WTF::ScrambledPtr::bits const):
(WTF::ScrambledPtr::operator==):
(WTF::ScrambledPtr::operator=):
(WTF::ScrambledPtr::scramble):
(WTF::ScrambledPtr::descramble):
(WTF::ScrambledPtr:: const): Deleted.
(WTF::ScrambledPtr::scrambledBits const): Deleted.

git-svn-id: https://svn.webkit.org/repository/webkit/trunk@225437 268f45cc-cd09-0410-ab3c-d52691b4dbfc

20 files changed:
Source/JavaScriptCore/API/JSCallbackObject.h
Source/JavaScriptCore/API/JSObjectRef.cpp
Source/JavaScriptCore/ChangeLog
Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj
Source/JavaScriptCore/Sources.txt
Source/JavaScriptCore/assembler/MacroAssemblerCodeRef.cpp
Source/JavaScriptCore/assembler/MacroAssemblerCodeRef.h
Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp
Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp
Source/JavaScriptCore/jit/AssemblyHelpers.h
Source/JavaScriptCore/jit/SpecializedThunkJIT.h
Source/JavaScriptCore/runtime/InitializeThreading.cpp
Source/JavaScriptCore/runtime/JSCScrambledPtr.cpp [new file with mode: 0644]
Source/JavaScriptCore/runtime/JSCScrambledPtr.h [new file with mode: 0644]
Source/JavaScriptCore/runtime/JSDestructibleObject.h
Source/JavaScriptCore/runtime/JSSegmentedVariableObject.h
Source/JavaScriptCore/runtime/Structure.h
Source/JavaScriptCore/runtime/VM.h
Source/WTF/ChangeLog
Source/WTF/wtf/ScrambledPtr.h

index 29b2c72..83f38be 100644 (file)
@@ -27,6 +27,7 @@
 #ifndef JSCallbackObject_h
 #define JSCallbackObject_h
 
+#include "JSCScrambledPtr.h"
 #include "JSObjectRef.h"
 #include "JSValueRef.h"
 #include "JSObject.h"
@@ -233,7 +234,7 @@ private:
     static EncodedJSValue callbackGetter(ExecState*, EncodedJSValue, PropertyName);
 
     std::unique_ptr<JSCallbackObjectData> m_callbackObjectData;
-    const ClassInfo* m_classInfo;
+    ClassInfoScrambledPtr m_classInfo;
 };
 
 } // namespace JSC
index 1ab6da5..5bff2af 100644 (file)
@@ -431,7 +431,7 @@ static const ClassInfo* classInfoPrivate(JSObject* jsObject)
     if (vm.currentlyDestructingCallbackObject != jsObject)
         return jsObject->classInfo(vm);
 
-    return vm.currentlyDestructingCallbackObjectClassInfo;
+    return vm.currentlyDestructingCallbackObjectClassInfo.descrambled();
 }
 
 void* JSObjectGetPrivate(JSObjectRef object)
index b0e1920..4a85cb4 100644 (file)
@@ -1,3 +1,44 @@
+2017-12-01  Mark Lam  <mark.lam@apple.com>
+
+        Let's scramble ClassInfo pointers in cells.
+        https://bugs.webkit.org/show_bug.cgi?id=180291
+        <rdar://problem/35807620>
+
+        Reviewed by JF Bastien.
+
+        * API/JSCallbackObject.h:
+        * API/JSObjectRef.cpp:
+        (classInfoPrivate):
+        * JavaScriptCore.xcodeproj/project.pbxproj:
+        * Sources.txt:
+        * assembler/MacroAssemblerCodeRef.cpp:
+        (JSC::MacroAssemblerCodePtr::initialize): Deleted.
+        * assembler/MacroAssemblerCodeRef.h:
+        (JSC::MacroAssemblerCodePtr:: const):
+        (JSC::MacroAssemblerCodePtr::hash const):
+        * dfg/DFGSpeculativeJIT.cpp:
+        (JSC::DFG::SpeculativeJIT::checkArray):
+        (JSC::DFG::SpeculativeJIT::compileCheckSubClass):
+        (JSC::DFG::SpeculativeJIT::compileNewStringObject):
+        * ftl/FTLLowerDFGToB3.cpp:
+        (JSC::FTL::DFG::LowerDFGToB3::compileNewStringObject):
+        (JSC::FTL::DFG::LowerDFGToB3::compileCheckSubClass):
+        * jit/AssemblyHelpers.h:
+        (JSC::AssemblyHelpers::emitAllocateDestructibleObject):
+        * jit/SpecializedThunkJIT.h:
+        (JSC::SpecializedThunkJIT::loadArgumentWithSpecificClass):
+        * runtime/InitializeThreading.cpp:
+        (JSC::initializeThreading):
+        * runtime/JSCScrambledPtr.cpp: Added.
+        (JSC::initializeScrambledPtrKeys):
+        * runtime/JSCScrambledPtr.h: Added.
+        * runtime/JSDestructibleObject.h:
+        (JSC::JSDestructibleObject::classInfo const):
+        * runtime/JSSegmentedVariableObject.h:
+        (JSC::JSSegmentedVariableObject::classInfo const):
+        * runtime/Structure.h:
+        * runtime/VM.h:
+
 2017-12-01  Brian Burg  <bburg@apple.com>
 
         Web Inspector: move Inspector::Protocol::Array<T> to JSON namespace
index 0f50e1c..cc2cec5 100644 (file)
                FE1C0FFD1B193E9800B53FCA /* Exception.h in Headers */ = {isa = PBXBuildFile; fileRef = FE1C0FFC1B193E9800B53FCA /* Exception.h */; settings = {ATTRIBUTES = (Private, ); }; };
                FE20CE9E15F04A9500DF3430 /* LLIntCLoop.h in Headers */ = {isa = PBXBuildFile; fileRef = FE20CE9C15F04A9500DF3430 /* LLIntCLoop.h */; settings = {ATTRIBUTES = (Private, ); }; };
                FE2A87601F02381600EB31B2 /* MinimumReservedZoneSize.h in Headers */ = {isa = PBXBuildFile; fileRef = FE2A875F1F02381600EB31B2 /* MinimumReservedZoneSize.h */; };
+               FE2B0B691FD227E00075DA5F /* JSCScrambledPtr.h in Headers */ = {isa = PBXBuildFile; fileRef = FE2B0B671FD0D2960075DA5F /* JSCScrambledPtr.h */; settings = {ATTRIBUTES = (Private, ); }; };
                FE3022D31E3D73A500BAC493 /* SigillCrashAnalyzer.h in Headers */ = {isa = PBXBuildFile; fileRef = FE3022D11E3D739600BAC493 /* SigillCrashAnalyzer.h */; settings = {ATTRIBUTES = (Private, ); }; };
                FE3022D71E42857300BAC493 /* VMInspector.h in Headers */ = {isa = PBXBuildFile; fileRef = FE3022D51E42856700BAC493 /* VMInspector.h */; };
                FE318FE01CAC982F00DFCC54 /* ECMAScriptSpecInternalFunctions.h in Headers */ = {isa = PBXBuildFile; fileRef = FE318FDE1CAC8C5300DFCC54 /* ECMAScriptSpecInternalFunctions.h */; };
                FE20CE9B15F04A9500DF3430 /* LLIntCLoop.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; name = LLIntCLoop.cpp; path = llint/LLIntCLoop.cpp; sourceTree = "<group>"; };
                FE20CE9C15F04A9500DF3430 /* LLIntCLoop.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; name = LLIntCLoop.h; path = llint/LLIntCLoop.h; sourceTree = "<group>"; };
                FE2A875F1F02381600EB31B2 /* MinimumReservedZoneSize.h */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.c.h; path = MinimumReservedZoneSize.h; sourceTree = "<group>"; };
+               FE2B0B671FD0D2960075DA5F /* JSCScrambledPtr.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = JSCScrambledPtr.h; sourceTree = "<group>"; };
+               FE2B0B681FD0D2970075DA5F /* JSCScrambledPtr.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = JSCScrambledPtr.cpp; sourceTree = "<group>"; };
                FE2E6A7A1D6EA5FE0060F896 /* ThrowScope.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = ThrowScope.cpp; sourceTree = "<group>"; };
                FE3022D01E3D739600BAC493 /* SigillCrashAnalyzer.cpp */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.cpp.cpp; path = SigillCrashAnalyzer.cpp; sourceTree = "<group>"; };
                FE3022D11E3D739600BAC493 /* SigillCrashAnalyzer.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = SigillCrashAnalyzer.h; sourceTree = "<group>"; };
                                F692A8870255597D01FF60F7 /* JSCJSValue.cpp */,
                                14ABB36E099C076400E2A24F /* JSCJSValue.h */,
                                865A30F0135007E100CDB49E /* JSCJSValueInlines.h */,
+                               FE2B0B681FD0D2970075DA5F /* JSCScrambledPtr.cpp */,
+                               FE2B0B671FD0D2960075DA5F /* JSCScrambledPtr.h */,
                                72AAF7CB1D0D318B005E60BE /* JSCustomGetterSetterFunction.cpp */,
                                72AAF7CC1D0D318B005E60BE /* JSCustomGetterSetterFunction.h */,
                                0F2B66BD17B6B5AB00A7AE3F /* JSDataView.cpp */,
                                0FEC852A1BDACDAC0080FF74 /* B3PhaseScope.h in Headers */,
                                0F37308D1C0BD29100052BFA /* B3PhiChildren.h in Headers */,
                                0FEC852C1BDACDAC0080FF74 /* B3Procedure.h in Headers */,
+                               FE2B0B691FD227E00075DA5F /* JSCScrambledPtr.h in Headers */,
                                0FEC852D1BDACDAC0080FF74 /* B3ProcedureInlines.h in Headers */,
                                0F725CAA1C503DED00AD943A /* B3PureCSE.h in Headers */,
                                43422A671C16267800E2EB98 /* B3ReduceDoubleToFloat.h in Headers */,
index a45487e..a71600e 100644 (file)
@@ -769,6 +769,7 @@ runtime/JSAsyncFunction.cpp
 runtime/JSAsyncGeneratorFunction.cpp
 runtime/JSBoundFunction.cpp
 runtime/JSCJSValue.cpp
+runtime/JSCScrambledPtr.cpp
 runtime/JSCallee.cpp
 runtime/JSCell.cpp
 runtime/JSCustomGetterSetterFunction.cpp
index 2e58cc6..21d1834 100644 (file)
 
 namespace JSC {
 
-uintptr_t g_masmScrambledPtrKey;
-
-void MacroAssemblerCodePtr::initialize()
-{
-    static std::once_flag initializeOnceFlag;
-    std::call_once(initializeOnceFlag, [] {
-        g_masmScrambledPtrKey = makeScrambledPtrKey();
-    });
-}
-
 MacroAssemblerCodePtr MacroAssemblerCodePtr::createLLIntCodePtr(OpcodeID codeId)
 {
     return createFromExecutableAddress(LLInt::getCodePtr(codeId));
index 603ab7d..1c82cca 100644 (file)
 #pragma once
 
 #include "ExecutableAllocator.h"
+#include "JSCScrambledPtr.h"
 #include <wtf/DataLog.h>
 #include <wtf/PrintStream.h>
 #include <wtf/RefPtr.h>
-#include <wtf/ScrambledPtr.h>
 #include <wtf/text/CString.h>
 
 // ASSERT_VALID_CODE_POINTER checks that ptr is a non-null pointer, and that it is a valid
 
 namespace JSC {
 
-extern "C" JS_EXPORTDATA uintptr_t g_masmScrambledPtrKey;
-
-using MasmScrambledPtr = ScrambledPtr<g_masmScrambledPtrKey>;
-
 class MacroAssemblerCodePtr;
 
 enum OpcodeID : unsigned;
@@ -323,7 +319,7 @@ public:
     T executableAddress() const
     {
         m_value.assertIsScrambled();
-        return m_value ? m_value.descramble<T>() : static_cast<T>(0);
+        return m_value ? m_value.descrambled<T>() : static_cast<T>(0);
     }
 #if CPU(ARM_THUMB2)
     // To use this pointer as a data address remove the decoration.
@@ -332,7 +328,7 @@ public:
     {
         m_value.assertIsScrambled();
         ASSERT_VALID_CODE_POINTER(m_value);
-        return bitwise_cast<T>(m_value ? m_value.descramble<char*>() - 1 : nullptr);
+        return bitwise_cast<T>(m_value ? m_value.descrambled<char*>() - 1 : nullptr);
     }
 #else
     template<typename T = void*>
@@ -340,7 +336,7 @@ public:
     {
         m_value.assertIsScrambled();
         ASSERT_VALID_CODE_POINTER(m_value);
-        return m_value ? m_value.descramble<T>() : static_cast<T>(0);
+        return m_value ? m_value.descrambled<T>() : static_cast<T>(0);
     }
 #endif
 
@@ -388,7 +384,7 @@ public:
     bool isEmptyValue() const { return m_value == emptyValue(); }
     bool isDeletedValue() const { return m_value == deletedValue(); }
 
-    unsigned hash() const { return IntHash<uintptr_t>::hash(m_value.scrambledBits()); }
+    unsigned hash() const { return IntHash<uintptr_t>::hash(m_value.bits()); }
 
     static void initialize();
 
index e470a94..7efca1f 100644 (file)
@@ -868,8 +868,8 @@ void SpeculativeJIT::checkArray(Node* node)
         m_jit.branchPtr(
             MacroAssembler::NotEqual,
             MacroAssembler::Address(temp.gpr(), Structure::classInfoOffset()),
-            TrustedImmPtr(expectedClassInfo)));
-    
+            TrustedImmPtr(ClassInfoScrambledPtr(expectedClassInfo).bits())));
+
     noResult(m_currentNode);
 }
 
@@ -8705,6 +8705,10 @@ void SpeculativeJIT::compileCheckSubClass(Node* node)
 
         m_jit.emitLoadStructure(*m_jit.vm(), baseGPR, otherGPR, specifiedGPR);
         m_jit.loadPtr(CCallHelpers::Address(otherGPR, Structure::classInfoOffset()), otherGPR);
+#if USE(JSVALUE64)
+        m_jit.move(CCallHelpers::TrustedImm64(g_classInfoScrambledPtrKey), specifiedGPR);
+        m_jit.xor64(specifiedGPR, otherGPR);
+#endif
         m_jit.move(CCallHelpers::TrustedImmPtr(node->classInfo()), specifiedGPR);
 
         CCallHelpers::Label loop = m_jit.label();
@@ -8999,7 +9003,7 @@ void SpeculativeJIT::compileNewStringObject(Node* node)
         slowPath);
     
     m_jit.storePtr(
-        TrustedImmPtr(StringObject::info()),
+        TrustedImmPtr(ClassInfoScrambledPtr(StringObject::info()).bits()),
         JITCompiler::Address(resultGPR, JSDestructibleObject::classInfoOffset()));
 #if USE(JSVALUE64)
     m_jit.store64(
index 63e0d1e..4e406f1 100644 (file)
@@ -5010,7 +5010,7 @@ private:
         LBasicBlock lastNext = m_out.insertNewBlocksBefore(slowCase);
 
         LValue fastResultValue = allocateObject<StringObject>(structure, m_out.intPtrZero, slowCase);
-        m_out.storePtr(m_out.constIntPtr(StringObject::info()), fastResultValue, m_heaps.JSDestructibleObject_classInfo);
+        m_out.storePtr(m_out.constIntPtr(ClassInfoScrambledPtr(StringObject::info()).bits()), fastResultValue, m_heaps.JSDestructibleObject_classInfo);
         m_out.store64(string, fastResultValue, m_heaps.JSWrapperObject_internalValue);
         mutatorFence();
         ValueFromBlock fastResult = m_out.anchor(fastResultValue);
@@ -11160,7 +11160,9 @@ private:
             LBasicBlock continuation = m_out.newBlock();
 
             LValue structure = loadStructure(cell);
-            ValueFromBlock otherAtStart = m_out.anchor(m_out.loadPtr(structure, m_heaps.Structure_classInfo));
+            LValue scrambledClassInfo = m_out.loadPtr(structure, m_heaps.Structure_classInfo);
+            LValue classInfo = m_out.bitXor(scrambledClassInfo, m_out.constInt64(g_classInfoScrambledPtrKey));
+            ValueFromBlock otherAtStart = m_out.anchor(classInfo);
             m_out.jump(loop);
 
             LBasicBlock lastNext = m_out.appendTo(loop, parentClass);
index c83efb7..41cc1bc 100644 (file)
@@ -1625,7 +1625,7 @@ public:
     void emitAllocateDestructibleObject(VM& vm, GPRReg resultGPR, Structure* structure, GPRReg scratchGPR1, GPRReg scratchGPR2, JumpList& slowPath)
     {
         emitAllocateJSObject<ClassType>(vm, resultGPR, TrustedImmPtr(structure), TrustedImmPtr(0), scratchGPR1, scratchGPR2, slowPath);
-        storePtr(TrustedImmPtr(structure->classInfo()), Address(resultGPR, JSDestructibleObject::classInfoOffset()));
+        storePtr(TrustedImmPtr(ClassInfoScrambledPtr(structure->classInfo()).bits()), Address(resultGPR, JSDestructibleObject::classInfoOffset()));
     }
     
     void emitInitializeInlineStorage(GPRReg baseGPR, unsigned inlineCapacity)
index 1d3d117..4baa1e8 100644 (file)
@@ -1,5 +1,5 @@
 /*
- * Copyright (C) 2010, 2016 Apple Inc. All rights reserved.
+ * Copyright (C) 2010-2017 Apple Inc. All rights reserved.
  *
  * Redistribution and use in source and binary forms, with or without
  * modification, are permitted provided that the following conditions
@@ -77,7 +77,7 @@ namespace JSC {
         {
             loadCellArgument(argument, dst);
             emitLoadStructure(*vm(), dst, scratch, dst);
-            appendFailure(branchPtr(NotEqual, Address(scratch, Structure::classInfoOffset()), TrustedImmPtr(classInfo)));
+            appendFailure(branchPtr(NotEqual, Address(scratch, Structure::classInfoOffset()), TrustedImmPtr(ClassInfoScrambledPtr(classInfo).bits())));
             // We have to reload the argument since emitLoadStructure clobbered it.
             loadCellArgument(argument, dst);
         }
index 2c4c0e8..af286cc 100644 (file)
@@ -1,5 +1,5 @@
 /*
- * Copyright (C) 2008, 2015-2017 Apple Inc. All rights reserved.
+ * Copyright (C) 2008-2017 Apple Inc. All rights reserved.
  *
  * Redistribution and use in source and binary forms, with or without
  * modification, are permitted provided that the following conditions
@@ -59,7 +59,7 @@ void initializeThreading()
 
     std::call_once(initializeThreadingOnceFlag, []{
         WTF::initializeThreading();
-        MacroAssemblerCodePtr::initialize();
+        initializeScrambledPtrKeys();
         Options::initialize();
 #if ENABLE(WRITE_BARRIER_PROFILING)
         WriteBarrierCounters::initialize();
diff --git a/Source/JavaScriptCore/runtime/JSCScrambledPtr.cpp b/Source/JavaScriptCore/runtime/JSCScrambledPtr.cpp
new file mode 100644 (file)
index 0000000..a03dd24
--- /dev/null
@@ -0,0 +1,44 @@
+/*
+ * Copyright (C) 2017 Apple Inc. All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ *    notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ *    notice, this list of conditions and the following disclaimer in the
+ *    documentation and/or other materials provided with the distribution.
+ *
+ * THIS SOFTWARE IS PROVIDED BY APPLE INC. ``AS IS'' AND ANY
+ * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
+ * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL APPLE INC. OR
+ * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
+ * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
+ * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
+ * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY
+ * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+
+#include "config.h"
+#include "JSCScrambledPtr.h"
+
+namespace JSC {
+
+uintptr_t g_classInfoScrambledPtrKey;
+uintptr_t g_masmScrambledPtrKey;
+
+void initializeScrambledPtrKeys()
+{
+    static std::once_flag initializeOnceFlag;
+    std::call_once(initializeOnceFlag, [] {
+        g_classInfoScrambledPtrKey = makeScrambledPtrKey();
+        g_masmScrambledPtrKey = makeScrambledPtrKey();
+    });
+}
+
+} // namespace JSC
+
diff --git a/Source/JavaScriptCore/runtime/JSCScrambledPtr.h b/Source/JavaScriptCore/runtime/JSCScrambledPtr.h
new file mode 100644 (file)
index 0000000..481505e
--- /dev/null
@@ -0,0 +1,43 @@
+/*
+ * Copyright (C) 2017 Apple Inc. All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ *    notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ *    notice, this list of conditions and the following disclaimer in the
+ *    documentation and/or other materials provided with the distribution.
+ *
+ * THIS SOFTWARE IS PROVIDED BY APPLE INC. ``AS IS'' AND ANY
+ * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
+ * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL APPLE INC. OR
+ * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
+ * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
+ * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
+ * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY
+ * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+
+#pragma once
+
+#include <wtf/ScrambledPtr.h>
+
+namespace JSC {
+
+extern "C" JS_EXPORTDATA uintptr_t g_classInfoScrambledPtrKey;
+extern "C" JS_EXPORTDATA uintptr_t g_masmScrambledPtrKey;
+
+struct ClassInfo;
+
+using ClassInfoScrambledPtr = ScrambledPtr<const ClassInfo*, g_classInfoScrambledPtrKey>;
+using MasmScrambledPtr = ScrambledPtr<void*, g_masmScrambledPtrKey>;
+
+void initializeScrambledPtrKeys();
+
+} // namespace JSC
+
index effe71e..a1fc2b7 100644 (file)
@@ -43,7 +43,7 @@ public:
         return &vm.destructibleObjectSpace;
     }
 
-    const ClassInfo* classInfo() const { return m_classInfo; }
+    const ClassInfo* classInfo() const { return m_classInfo.descrambled(); }
     
     static ptrdiff_t classInfoOffset() { return OBJECT_OFFSETOF(JSDestructibleObject, m_classInfo); }
 
@@ -56,7 +56,7 @@ protected:
     }
 
 private:
-    const ClassInfo* m_classInfo;
+    ClassInfoScrambledPtr m_classInfo;
 };
 
 } // namespace JSC
index 07e9c04..21ae6e6 100644 (file)
@@ -94,7 +94,7 @@ public:
         return &vm.segmentedVariableObjectSpace;
     }
     
-    const ClassInfo* classInfo() const { return m_classInfo; }
+    const ClassInfo* classInfo() const { return m_classInfo.descrambled(); }
     
 protected:
     JSSegmentedVariableObject(VM&, Structure*, JSScope*);
@@ -107,7 +107,7 @@ private:
     SegmentedVector<WriteBarrier<Unknown>, 16> m_variables;
     ConcurrentJSLock m_lock;
     bool m_alreadyDestroyed { false }; // We use these assertions to check that we aren't doing ancient hacks that result in this being destroyed more than once.
-    const ClassInfo* m_classInfo;
+    ClassInfoScrambledPtr m_classInfo;
 };
 
 } // namespace JSC
index f16feb4..65d658b 100644 (file)
@@ -1,5 +1,5 @@
 /*
- * Copyright (C) 2008, 2009, 2012-2016 Apple Inc. All rights reserved.
+ * Copyright (C) 2008-2017 Apple Inc. All rights reserved.
  *
  * Redistribution and use in source and binary forms, with or without
  * modification, are permitted provided that the following conditions
@@ -468,7 +468,7 @@ public:
 
     void setObjectToStringValue(ExecState*, VM&, JSString* value, PropertySlot toStringTagSymbolSlot);
 
-    const ClassInfo* classInfo() const { return m_classInfo; }
+    const ClassInfo* classInfo() const { return m_classInfo.descrambled(); }
 
     static ptrdiff_t structureIDOffset()
     {
@@ -798,7 +798,7 @@ private:
 
     RefPtr<UniquedStringImpl> m_nameInPrevious;
 
-    const ClassInfo* m_classInfo;
+    ClassInfoScrambledPtr m_classInfo;
 
     StructureTransitionTable m_transitionTable;
 
index 015f7e4..366873b 100644 (file)
@@ -414,7 +414,7 @@ public:
     std::unique_ptr<PromiseDeferredTimer> promiseDeferredTimer;
     
     JSCell* currentlyDestructingCallbackObject;
-    const ClassInfo* currentlyDestructingCallbackObjectClassInfo;
+    ClassInfoScrambledPtr currentlyDestructingCallbackObjectClassInfo;
 
     AtomicStringTable* m_atomicStringTable;
     WTF::SymbolRegistry m_symbolRegistry;
index 2ba8e07..517918a 100644 (file)
@@ -1,3 +1,21 @@
+2017-12-01  Mark Lam  <mark.lam@apple.com>
+
+        Let's scramble ClassInfo pointers in cells.
+        https://bugs.webkit.org/show_bug.cgi?id=180291
+        <rdar://problem/35807620>
+
+        Reviewed by JF Bastien.
+
+        * wtf/ScrambledPtr.h:
+        (WTF::ScrambledPtr::descrambled const):
+        (WTF::ScrambledPtr::bits const):
+        (WTF::ScrambledPtr::operator==):
+        (WTF::ScrambledPtr::operator=):
+        (WTF::ScrambledPtr::scramble):
+        (WTF::ScrambledPtr::descramble):
+        (WTF::ScrambledPtr:: const): Deleted.
+        (WTF::ScrambledPtr::scrambledBits const): Deleted.
+
 2017-12-01  Christopher Reid  <chris.reid@sony.com>
 
         Move DateComponents into WTF
index 33d4485..f49f029 100644 (file)
@@ -40,12 +40,11 @@ namespace WTF {
 
 using ScrambledPtrBits = uintptr_t;
 
-template<uintptr_t& key>
+template<typename T, uintptr_t& key, typename = std::enable_if_t<std::is_pointer<T>::value>>
 class ScrambledPtr {
 public:
     ScrambledPtr() { }
 
-    template<typename T, typename = typename std::enable_if<std::is_pointer<T>::value>::type>
     explicit ScrambledPtr(T ptr)
         : m_scrambledBits(scramble(ptr))
     {
@@ -61,26 +60,26 @@ public:
     }
 
 #if ENABLE(SCRAMBLED_PTR_ASSERTS)
-    template<typename T = void*>
-    static bool isScrambled(T value) { return !value || (reinterpret_cast<uintptr_t>(value) & 0xffff000000000000); }
-    template<typename T = void*>
-    static void assertIsScrambled(T value) { RELEASE_ASSERT(isScrambled(value)); }
-    template<typename T = void*>
-    static void assertIsNotScrambled(T value) { RELEASE_ASSERT(!isScrambled(value)); }
+    template<typename U = void*>
+    static bool isScrambled(U value) { return !value || (reinterpret_cast<uintptr_t>(value) & 0xffff000000000000); }
+    template<typename U = void*>
+    static void assertIsScrambled(U value) { RELEASE_ASSERT(isScrambled(value)); }
+    template<typename U = void*>
+    static void assertIsNotScrambled(U value) { RELEASE_ASSERT(!isScrambled(value)); }
 #else
-    template<typename T = void*> static void assertIsScrambled(T) { }
-    template<typename T = void*> static void assertIsNotScrambled(T) { }
+    template<typename U = void*> static void assertIsScrambled(U) { }
+    template<typename U = void*> static void assertIsNotScrambled(U) { }
 #endif
     void assertIsScrambled() const { assertIsScrambled(m_scrambledBits); }
     void assertIsNotScrambled() const { assertIsNotScrambled(m_scrambledBits); }
 
-    template<typename T = void*>
-    T descramble() const { return descramble<T>(m_scrambledBits); }
+    template<typename U = T>
+    U descrambled() const { return descramble<U>(m_scrambledBits); }
 
-    template<typename T, typename = typename std::enable_if<std::is_pointer<T>::value>::type>
     ALWAYS_INLINE T operator->() const { return descramble<T>(m_scrambledBits); }
 
-    ScrambledPtrBits scrambledBits() const { return m_scrambledBits; }
+    template<typename U = ScrambledPtrBits>
+    U bits() const { return bitwise_cast<U>(m_scrambledBits); }
 
     bool operator!() const { return !m_scrambledBits; }
     explicit operator bool() const { return !!m_scrambledBits; }
@@ -93,20 +92,27 @@ public:
     template<typename PtrType = void*, typename = typename std::enable_if<std::is_pointer<PtrType>::value>::type>
     bool operator==(const PtrType b)
     {
-        return descramble<PtrType>() == b;
+        return descrambled<PtrType>() == b;
     }
 
+    ScrambledPtr& operator=(T ptr)
+    {
+        m_scrambledBits = ptr ? scramble(ptr) : 0;
+        return *this;
+    }
+    ScrambledPtr& operator=(const ScrambledPtr&) = default;
+
 private:
 #if USE(JSVALUE64)
-    template<typename T>
-    ALWAYS_INLINE static ScrambledPtrBits scramble(T ptr) { return bitwise_cast<ScrambledPtrBits>(ptr) ^ key; }
-    template<typename T>
-    ALWAYS_INLINE static T descramble(ScrambledPtrBits scrambledBits) { return bitwise_cast<T>(scrambledBits ^ key); }
+    template<typename U>
+    ALWAYS_INLINE static ScrambledPtrBits scramble(U ptr) { return bitwise_cast<ScrambledPtrBits>(ptr) ^ key; }
+    template<typename U>
+    ALWAYS_INLINE static U descramble(ScrambledPtrBits scrambledBits) { return bitwise_cast<U>(scrambledBits ^ key); }
 #else
-    template<typename T>
-    ALWAYS_INLINE static ScrambledPtrBits scramble(T ptr) { return bitwise_cast<ScrambledPtrBits>(ptr); }
-    template<typename T>
-    ALWAYS_INLINE static T descramble(ScrambledPtrBits scrambledBits) { return bitwise_cast<T>(scrambledBits); }
+    template<typename U>
+    ALWAYS_INLINE static ScrambledPtrBits scramble(U ptr) { return bitwise_cast<ScrambledPtrBits>(ptr); }
+    template<typename U>
+    ALWAYS_INLINE static U descramble(ScrambledPtrBits scrambledBits) { return bitwise_cast<U>(scrambledBits); }
 #endif
 
     ScrambledPtrBits m_scrambledBits { 0 };