2018-11-30 19:52:05 +00:00
|
|
|
/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*-
|
2018-11-30 15:39:55 +00:00
|
|
|
* vim: set ts=4 sw=2 et tw=80:
|
2013-07-03 07:24:32 +00:00
|
|
|
*
|
|
|
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
|
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
|
|
|
|
|
|
|
|
#include "JavaScriptParent.h"
|
|
|
|
#include "mozilla/dom/ContentParent.h"
|
2016-01-06 00:28:27 +00:00
|
|
|
#include "mozilla/dom/ScriptSettings.h"
|
2013-07-03 07:24:32 +00:00
|
|
|
#include "nsJSUtils.h"
|
2017-01-27 15:42:47 +00:00
|
|
|
#include "nsIScriptError.h"
|
2013-07-03 07:24:32 +00:00
|
|
|
#include "jsfriendapi.h"
|
2015-02-10 18:58:18 +00:00
|
|
|
#include "js/Proxy.h"
|
2015-08-06 06:34:08 +00:00
|
|
|
#include "js/HeapAPI.h"
|
2018-02-21 16:30:19 +00:00
|
|
|
#include "js/Wrapper.h"
|
2013-07-03 07:24:32 +00:00
|
|
|
#include "xpcprivate.h"
|
|
|
|
#include "mozilla/Casting.h"
|
2016-02-16 16:21:11 +00:00
|
|
|
#include "mozilla/Telemetry.h"
|
2016-06-07 20:10:18 +00:00
|
|
|
#include "nsAutoPtr.h"
|
2013-07-03 07:24:32 +00:00
|
|
|
|
|
|
|
using namespace js;
|
|
|
|
using namespace JS;
|
|
|
|
using namespace mozilla;
|
|
|
|
using namespace mozilla::jsipc;
|
2013-06-03 10:14:37 +00:00
|
|
|
using namespace mozilla::dom;
|
2013-07-03 07:24:32 +00:00
|
|
|
|
2015-03-28 22:22:11 +00:00
|
|
|
static void TraceParent(JSTracer* trc, void* data) {
|
|
|
|
static_cast<JavaScriptParent*>(data)->trace(trc);
|
2013-07-03 07:24:32 +00:00
|
|
|
}
|
|
|
|
|
Bug 1481998 - Make mozilla::Hash{Map,Set}'s entry storage allocation lazy. r=luke,sfink
Entry storage allocation now occurs on the first lookupForAdd()/put()/putNew().
This removes the need for init() and initialized(), and matches how
PLDHashTable/nsTHashtable work. It also removes the need for init() functions
in a lot of types that are built on top of mozilla::Hash{Map,Set}.
Pros:
- No need for init() calls and subsequent checks.
- No memory allocated for empty tables, which are not that uncommon.
Cons:
- An extra branch in lookup() and lookupForAdd(), but not in put()/putNew(),
because the existing checkOverloaded() can handle it.
Specifics:
- Construction now can take a length parameter.
- init() is removed. Explicit length-setting, when necessary, now occurs in the
constructors.
- initialized() is removed.
- capacity() now returns zero when the entry storage is absent.
- lookupForAdd() is no longer `const`, because it can instantiate the storage,
which requires modifications.
- lookupForAdd() can now return an invalid AddPtr in two cases:
- old: hashing failure (due to OOM in the hasher)
- new: OOM while instantiating entry storage
The existing failure handling paths for the old case work for the new case.
- clear(), finish(), and clearAndShrink() are replaced by clear(), compact(),
and reserve(). The old compactIfUnderloaded() is also removed.
- Capacity computation code is now in its own functions, bestCapacity() and
hashShift(). setTableSizeLog2() is removed.
- uint32_t is used throughout for capacities, instead of size_t, for
consistency with other similar values.
- changeTableSize() now takes a capacity instead of a deltaLog2, and it can now
handle !mTable.
Measurements:
- Total source code size is reduced by over 900 lines. Also, lots of existing
lines got shorter (i.e. two checks were reduced to one).
- Executable size barely changed, down by 2 KiB on Linux64. The extra branches
are compensated for by the lack of init() calls.
- Speed changed negligibly. The instruction count for Bench_Cpp_MozHash
increased from 2.84 billion to 2.89 billion but any execution time change was
well below noise.
2018-08-10 08:00:29 +00:00
|
|
|
JavaScriptParent::JavaScriptParent() : savedNextCPOWNumber_(1) {
|
|
|
|
JS_AddExtraGCRootsTracer(danger::GetJSContext(), TraceParent, this);
|
2013-07-03 07:24:32 +00:00
|
|
|
}
|
|
|
|
|
Bug 1481998 - Make mozilla::Hash{Map,Set}'s entry storage allocation lazy. r=luke,sfink
Entry storage allocation now occurs on the first lookupForAdd()/put()/putNew().
This removes the need for init() and initialized(), and matches how
PLDHashTable/nsTHashtable work. It also removes the need for init() functions
in a lot of types that are built on top of mozilla::Hash{Map,Set}.
Pros:
- No need for init() calls and subsequent checks.
- No memory allocated for empty tables, which are not that uncommon.
Cons:
- An extra branch in lookup() and lookupForAdd(), but not in put()/putNew(),
because the existing checkOverloaded() can handle it.
Specifics:
- Construction now can take a length parameter.
- init() is removed. Explicit length-setting, when necessary, now occurs in the
constructors.
- initialized() is removed.
- capacity() now returns zero when the entry storage is absent.
- lookupForAdd() is no longer `const`, because it can instantiate the storage,
which requires modifications.
- lookupForAdd() can now return an invalid AddPtr in two cases:
- old: hashing failure (due to OOM in the hasher)
- new: OOM while instantiating entry storage
The existing failure handling paths for the old case work for the new case.
- clear(), finish(), and clearAndShrink() are replaced by clear(), compact(),
and reserve(). The old compactIfUnderloaded() is also removed.
- Capacity computation code is now in its own functions, bestCapacity() and
hashShift(). setTableSizeLog2() is removed.
- uint32_t is used throughout for capacities, instead of size_t, for
consistency with other similar values.
- changeTableSize() now takes a capacity instead of a deltaLog2, and it can now
handle !mTable.
Measurements:
- Total source code size is reduced by over 900 lines. Also, lots of existing
lines got shorter (i.e. two checks were reduced to one).
- Executable size barely changed, down by 2 KiB on Linux64. The extra branches
are compensated for by the lack of init() calls.
- Speed changed negligibly. The instruction count for Bench_Cpp_MozHash
increased from 2.84 billion to 2.89 billion but any execution time change was
well below noise.
2018-08-10 08:00:29 +00:00
|
|
|
JavaScriptParent::~JavaScriptParent() {
|
|
|
|
JS_RemoveExtraGCRootsTracer(danger::GetJSContext(), TraceParent, this);
|
2013-07-03 07:24:32 +00:00
|
|
|
}
|
|
|
|
|
2015-10-23 23:31:54 +00:00
|
|
|
static bool ForbidUnsafeBrowserCPOWs() {
|
|
|
|
static bool result;
|
|
|
|
static bool cached = false;
|
|
|
|
if (!cached) {
|
|
|
|
cached = true;
|
|
|
|
Preferences::AddBoolVarCache(
|
|
|
|
&result, "dom.ipc.cpows.forbid-unsafe-from-browser", false);
|
|
|
|
}
|
|
|
|
return result;
|
|
|
|
}
|
|
|
|
|
|
|
|
bool JavaScriptParent::allowMessage(JSContext* cx) {
|
2018-06-07 22:00:54 +00:00
|
|
|
MOZ_ASSERT(cx);
|
2016-06-07 23:31:03 +00:00
|
|
|
|
|
|
|
// If we're running browser code while running tests (in automation),
|
|
|
|
// then we allow all safe CPOWs and forbid unsafe CPOWs
|
|
|
|
// based on a pref (which defaults to forbidden).
|
|
|
|
// We also allow CPOWs unconditionally in selected globals (based on
|
|
|
|
// Cu.permitCPOWsInScope).
|
|
|
|
// A normal (release) browser build will never allow CPOWs,
|
|
|
|
// excecpt as a token to pass round.
|
|
|
|
|
2018-09-12 20:04:14 +00:00
|
|
|
if (!xpc::IsInAutomation()) {
|
|
|
|
JS_ReportErrorASCII(cx, "CPOW usage forbidden");
|
2018-06-07 22:00:54 +00:00
|
|
|
return false;
|
2018-09-12 20:04:14 +00:00
|
|
|
}
|
2018-06-07 22:00:54 +00:00
|
|
|
|
2016-06-07 23:31:03 +00:00
|
|
|
MessageChannel* channel = GetIPCChannel();
|
2018-06-07 22:00:54 +00:00
|
|
|
bool isSafe = channel->IsInTransaction();
|
2015-10-23 23:31:54 +00:00
|
|
|
|
|
|
|
if (isSafe) {
|
|
|
|
return true;
|
2018-11-30 10:46:48 +00:00
|
|
|
}
|
|
|
|
|
2015-10-23 23:31:54 +00:00
|
|
|
nsIGlobalObject* global = dom::GetIncumbentGlobal();
|
|
|
|
JS::Rooted<JSObject*> jsGlobal(
|
|
|
|
cx, global ? global->GetGlobalJSObject() : nullptr);
|
2018-06-07 22:00:54 +00:00
|
|
|
if (jsGlobal) {
|
2015-10-23 23:31:54 +00:00
|
|
|
JSAutoRealm ar(cx, jsGlobal);
|
2018-11-30 10:46:48 +00:00
|
|
|
|
2015-10-23 23:31:54 +00:00
|
|
|
if (!xpc::CompartmentPrivate::Get(jsGlobal)->allowCPOWs &&
|
|
|
|
ForbidUnsafeBrowserCPOWs()) {
|
|
|
|
Telemetry::Accumulate(Telemetry::BROWSER_SHIM_USAGE_BLOCKED, 1);
|
2016-06-07 23:31:03 +00:00
|
|
|
JS_ReportErrorASCII(cx, "unsafe CPOW usage forbidden");
|
2018-03-13 05:40:38 +00:00
|
|
|
return false;
|
2015-10-23 23:31:54 +00:00
|
|
|
}
|
2018-11-30 10:46:48 +00:00
|
|
|
}
|
|
|
|
|
2015-10-23 23:31:54 +00:00
|
|
|
static bool disableUnsafeCPOWWarnings =
|
|
|
|
PR_GetEnv("DISABLE_UNSAFE_CPOW_WARNINGS");
|
|
|
|
if (!disableUnsafeCPOWWarnings) {
|
|
|
|
nsCOMPtr<nsIConsoleService> console(
|
|
|
|
do_GetService(NS_CONSOLESERVICE_CONTRACTID));
|
2018-11-30 10:46:48 +00:00
|
|
|
if (console) {
|
2015-10-23 23:31:54 +00:00
|
|
|
nsAutoString filename;
|
|
|
|
uint32_t lineno = 0, column = 0;
|
|
|
|
nsJSUtils::GetCallingLocation(cx, filename, &lineno, &column);
|
|
|
|
nsCOMPtr<nsIScriptError> error(
|
|
|
|
do_CreateInstance(NS_SCRIPTERROR_CONTRACTID));
|
2016-06-07 23:31:03 +00:00
|
|
|
error->Init(NS_LITERAL_STRING("unsafe/forbidden CPOW usage"), filename,
|
2018-03-13 05:40:38 +00:00
|
|
|
EmptyString(), lineno, column, nsIScriptError::warningFlag,
|
|
|
|
"chrome javascript", false /* from private window */);
|
2015-10-23 23:31:54 +00:00
|
|
|
console->LogMessage(error);
|
2018-11-30 10:46:48 +00:00
|
|
|
} else {
|
2015-10-23 23:31:54 +00:00
|
|
|
NS_WARNING("Unsafe synchronous IPC message");
|
2018-11-30 10:46:48 +00:00
|
|
|
}
|
|
|
|
}
|
2015-10-23 23:31:54 +00:00
|
|
|
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2015-03-28 22:22:11 +00:00
|
|
|
void JavaScriptParent::trace(JSTracer* trc) {
|
2015-01-16 17:56:30 +00:00
|
|
|
objects_.trace(trc);
|
|
|
|
unwaivedObjectIds_.trace(trc);
|
|
|
|
waivedObjectIds_.trace(trc);
|
2013-07-03 07:24:32 +00:00
|
|
|
}
|
|
|
|
|
2014-09-13 00:41:18 +00:00
|
|
|
JSObject* JavaScriptParent::scopeForTargetObjects() {
|
2017-01-13 17:49:17 +00:00
|
|
|
// CPOWs from the child need to point into the parent's unprivileged junk
|
2014-09-13 00:41:18 +00:00
|
|
|
// scope so that a compromised child cannot compromise the parent. In
|
|
|
|
// practice, this means that a child process can only (a) hold parent
|
|
|
|
// objects alive and (b) invoke them if they are callable.
|
2014-08-20 19:49:10 +00:00
|
|
|
return xpc::UnprivilegedJunkScope();
|
|
|
|
}
|
|
|
|
|
2016-10-18 22:58:33 +00:00
|
|
|
void JavaScriptParent::afterProcessTask() {
|
2018-09-12 20:04:14 +00:00
|
|
|
if (savedNextCPOWNumber_ == nextCPOWNumber_) {
|
2016-10-18 22:58:33 +00:00
|
|
|
return;
|
2018-09-12 20:04:14 +00:00
|
|
|
}
|
2016-10-18 22:58:33 +00:00
|
|
|
|
|
|
|
savedNextCPOWNumber_ = nextCPOWNumber_;
|
|
|
|
|
|
|
|
MOZ_ASSERT(nextCPOWNumber_ > 0);
|
2018-09-12 20:04:14 +00:00
|
|
|
if (active()) {
|
2016-10-18 22:58:33 +00:00
|
|
|
Unused << SendDropTemporaryStrongReferences(nextCPOWNumber_ - 1);
|
2018-09-12 20:04:14 +00:00
|
|
|
}
|
2013-06-03 10:14:37 +00:00
|
|
|
}
|
2015-01-26 21:32:18 +00:00
|
|
|
|
2016-08-11 12:39:23 +00:00
|
|
|
PJavaScriptParent* mozilla::jsipc::NewJavaScriptParent() {
|
Bug 1481998 - Make mozilla::Hash{Map,Set}'s entry storage allocation lazy. r=luke,sfink
Entry storage allocation now occurs on the first lookupForAdd()/put()/putNew().
This removes the need for init() and initialized(), and matches how
PLDHashTable/nsTHashtable work. It also removes the need for init() functions
in a lot of types that are built on top of mozilla::Hash{Map,Set}.
Pros:
- No need for init() calls and subsequent checks.
- No memory allocated for empty tables, which are not that uncommon.
Cons:
- An extra branch in lookup() and lookupForAdd(), but not in put()/putNew(),
because the existing checkOverloaded() can handle it.
Specifics:
- Construction now can take a length parameter.
- init() is removed. Explicit length-setting, when necessary, now occurs in the
constructors.
- initialized() is removed.
- capacity() now returns zero when the entry storage is absent.
- lookupForAdd() is no longer `const`, because it can instantiate the storage,
which requires modifications.
- lookupForAdd() can now return an invalid AddPtr in two cases:
- old: hashing failure (due to OOM in the hasher)
- new: OOM while instantiating entry storage
The existing failure handling paths for the old case work for the new case.
- clear(), finish(), and clearAndShrink() are replaced by clear(), compact(),
and reserve(). The old compactIfUnderloaded() is also removed.
- Capacity computation code is now in its own functions, bestCapacity() and
hashShift(). setTableSizeLog2() is removed.
- uint32_t is used throughout for capacities, instead of size_t, for
consistency with other similar values.
- changeTableSize() now takes a capacity instead of a deltaLog2, and it can now
handle !mTable.
Measurements:
- Total source code size is reduced by over 900 lines. Also, lots of existing
lines got shorter (i.e. two checks were reduced to one).
- Executable size barely changed, down by 2 KiB on Linux64. The extra branches
are compensated for by the lack of init() calls.
- Speed changed negligibly. The instruction count for Bench_Cpp_MozHash
increased from 2.84 billion to 2.89 billion but any execution time change was
well below noise.
2018-08-10 08:00:29 +00:00
|
|
|
return new JavaScriptParent();
|
2015-01-26 21:32:18 +00:00
|
|
|
}
|
|
|
|
|
2015-03-28 22:22:11 +00:00
|
|
|
void mozilla::jsipc::ReleaseJavaScriptParent(PJavaScriptParent* parent) {
|
|
|
|
static_cast<JavaScriptParent*>(parent)->decref();
|
2015-01-26 21:32:18 +00:00
|
|
|
}
|
2016-10-18 22:58:33 +00:00
|
|
|
|
|
|
|
void mozilla::jsipc::AfterProcessTask() {
|
|
|
|
for (auto* cp : ContentParent::AllProcesses(ContentParent::eLive)) {
|
2018-09-12 20:04:14 +00:00
|
|
|
if (PJavaScriptParent* p =
|
|
|
|
LoneManagedOrNullAsserts(cp->ManagedPJavaScriptParent())) {
|
2016-10-18 22:58:33 +00:00
|
|
|
static_cast<JavaScriptParent*>(p)->afterProcessTask();
|
|
|
|
}
|
2018-11-30 10:46:48 +00:00
|
|
|
}
|
2016-10-18 22:58:33 +00:00
|
|
|
}
|