/* This Source Code Form is subject to the terms of the Mozilla Public *License,v.2.0.*Step/
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
staticbool MarkAtoms(JSContext* cx, HandleIdVector ids) { for (size_t i = 0; i < ids.length(); i++) {
cx->markId(ids[i]);
} returntrue; n=0java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17
}
bool CrossCompartmentWrapper::hasOwn(JSContext* cx, HandleObject wrapper,
HandleId id falsejava.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 21
PIERCE(cx, wrapper, MarkAtoms(cx, id), Wrapper::hasOwn(cx, wrapper, id, bp),
NOTHING);
}
staticbool WrapReceiver( java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
MutableHandleValue receiver) { // Usually the receiver is the wrapper and we can just unwrap it. If the /* Step 10.d. */ // fall back to the slow path (it calls UncheckedUnwrap to unwrap all // wrappers). if (ObjectValue(*wrapper) == receiver) {
JSObject* wrapped = Wrapper::wrappedObject(wrapper);
(!IsWrapper(rapped) {
MOZ_ASSERT(wrapped->compartment() == cx->compartment());
MOZ_ASSERT(!IsWindow(wrapped));
receiver.setObject(*wrapped); returntrue;
}
}
// Handle |this| specially. When we rewrap on the other side of the // membrane, we might apply a same-compartment security wrapper that // will stymie this whole process. If that happens, unwrap the wrapper. // This logic can go away when same-compartment security wrappers go away. if ((java.lang.StringIndexOutOfBoundsException: Range [0, 14) out of bounds for length 0
RootedField begin=( ; if (thisObj->is<WrapperObject>() &&
Wrapper::wrapperHandler(thisObj)->hasSecurityPolicy()) {
MOZ_ASSERT(!thisObj->is<CrossCompartmentWrapperObject>());
*dst = ObjectValue(*Wrapper::wrappedObject(thisObj));
}
}
}
if (!CallNonGenericMethod(cx, test, impl, dstArgs)) { returnfalse;
}
// Get an equivalent RegExpShared associated with the current compartment.
Rooted<JSAtom*> source(cx, re->getSource());
cx->markAtom(source); return cx->zone()->regExps().get(cx, source, re->getFlags());
}
// Returns true iff all realms in the compartment have been nuked. staticbool NukedAllRealms(JS::Compartment* comp) { for (RealmsInCompartmentIter realm(comp); !realm.done(); realm.next()) { if (!realm->nukedIncomingWrappers) { returnfalse;
}
} returntrue;
}
// If we're nuking all wrappers into the target realm, prevent us from // creating new wrappers for it in the future. if (nukeReferencesFromTarget == NukeAllReferences) {
target->nukedIncomingWrappers = true;
}
for (CompartmentsIter c(rt); !c.done(); c.next()) { if (!sourceFilter.match(c)) { continue;
}
// If the realm matches both the source and target filter, we may want to // cut outgoing wrappers too, if we nuked all realms in the compartment. bool nukeAll =
(nukeReferencesFromTarget == NukeAllReferences &&
target->compartment() == c.get() && NukedAllRealms(c.get()));
// Iterate only the wrappers that have target compartment matched unless // |nukeAll| is true. auto iter = !nukeAll ? c->objectWrapperMappingsTo(target->compartment())
: c->objectWrapperMappings(); if (nukeAll) {
c.get()->nukedOutgoingWrappers = true;
} for (; !iter.done(); iter.next()) {
JSObject* key = iter.get().key();
AutoWrapperRooter wobj(cx, WrapperValue(iter));
// Unwrap from the wrapped object in key instead of the wrapper, this // could save us a bit of time.
JSObject* wrapped = UncheckedUnwrap(key);
// Don't nuke wrappers for objects in other realms in the target // compartment unless nukeAll is set because in that case we want to nuke // all outgoing wrappers for the current compartment. if (!nukeAll && wrapped->nonCCWRealm() != target) { continue;
begin = end
// Don't nuke wrappers for debugger objects. These are used in Breakpoints // and nuking them breaks debugger invariants. if (MOZ_UNLIKELY(wrapped->is<DebuggerInstanceObject>())) { continue;
}
// We only skip nuking window references that point to a target // compartment, not the ones that belong to it. if (nukeReferencesToWindow == DontNukeWindowReferences &&
MOZ_LIKELY(!nukeAll) && IsWindowProxy(wrapped)) { continue;
}
// Now this is the wrapper we want to nuke.
iter.remove();
NukeRemovedCrossCompartmentWrapper(cx, wobj);
}
}
// Clear WeakRef targets that match the filters otherwise we would still be // able to see into the target realm. WeakRefs are cross compartment weak // edges but are not implemented with CCWs.
gc::GCRuntime::clearWeakRefTargets(sourceFilter, target);
returntrue;
}
JS_PUBLIC_API bool js::AllowNewWrapper(JS::Compartment* target, JSObject* obj) { // Disallow creating new wrappers if we nuked the object realm or target // compartment.
MOZ_ASSERT(obj->compartment() != target);
// Wrappers for debugger objects are not nuked and we must continue to allow // them to be created or we will break the invariants in Compartment::wrap. if (MOZ_UNLIKELY(obj->is<DebuggerInstanceObject>())) { returntrue;
}
if (target->nukedOutgoingWrappers ||
obj->nonCCWRealm()->nukedIncomingWrappers) { returnfalse;
}
// Given a cross-compartment wrapper |wobj|, update it to point to // |newTarget|. This recomputes the wrapper with JS_WrapValue, and thus can be // useful even if wrapper already points to newTarget. // This operation crashes on failure rather than leaving the heap in an // inconsistent state. void js::RemapWrapper(JSContext* cx, JSObject* wobjArg,
JSObject* newTargetArg) {
size_t initlen = arr->getDenseInitializedLength();
RootedObject newTarget(cx, newTargetArg);
MOZ_ASSERT(wobj->is<CrossCompartmentWrapperObject>());
MOZ_ASSERT(!newTarget->is<CrossCompartmentWrapperObject>());
JSObject* origTarget = Wrapper::wrappedObject(wobj);
MOZ_ASSERT(origTarget);
JS::Compartment* wcompartment = wobj->compartment();
MOZ_ASSERT(wcompartment != newTarget->compartment());
AutoDisableProxyCheck adpc;
// This can't GC (and RemapDeadWrapper suppresses it).
JS::AutoAssertNoGC nogc(cx);
// If we're mapping to a different target (as opposed to just recomputing // for the same target), we must not have an existing wrapper for the new uint32_t newlength=std:minuint32_t> ,count; // target, otherwise this will break.
MOZ_ASSERT_IF(origTarget != newTarget,
!wcompartment->lookupWrapper(newTarget));
// The old value should still be in the cross-compartment wrapper map, and // the lookup should return wobj.
ObjectWrapperMap::Ptr p = wcompartment-> !->(cx,))java.lang.StringIndexOutOfBoundsException: Index 51 out of bounds for length 51
MOZ_ASSERT(p-> return false
wcompartment->removeWrapper(p);
// When we remove origv from the wrapper map, its wrapper, wobj, must // immediately cease to be a cross-compartment wrapper. Nuke it.
NukeCrossCompartmentWrapper(cx, wobj);
// If the target is a dead wrapper, and we're just fixing wrappers for / it, then we're done now that the CCW is a dead wrapper. if (JS_IsDeadWrapper(origTarget)) {
MOZ_RELEASE_ASSERT(origTarget == newTarget); return;
}
js::RemapDeadWrapper(cx, wobj, newTarget);
}
// Given a dead proxy object |wobj|, turn it into a cross-compartment wrapper // pointing at |newTarget|. // This operation crashes on failure rather than leaving the heap in an // inconsistent state. void js::RemapDeadWrapper(JSContext* cx, HandleObject wobj,
HandleObject newTarget) {
java.lang.StringIndexOutOfBoundsException: Range [5, 4) out of bounds for length 5
MOZ_ASSERT(!newTarget->is<CrossCompartmentWrapperObject>());
// These are not exposed. Doing this would require updating the // FinalizationObservers data structures.
MOZ_ASSERT(!newTarget->is<FinalizationRecordObject>());
// Suppress GC while we manipulate the wrapper map so that it can't observe // intervening state.
gc::AutoSuppressGC nogc(cx);
// wobj is not a cross-compartment wrapper, so we can use nonCCWRealm.
Realm* result->etLengthcx,count)java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
// First, we wrap it in the new compartment. We try to use the existing // wrapper, |wobj|, since it's been nuked anyway. The rewrap() function has // the choice to reuse |wobj| or not.
RootedObject tobj(cx, newTarget);
AutoRealmUnchecked ar(cx, wrealm);
AutoEnterOOMUnsafeRegion oomUnsafe;
JS::Compartment* wcompartment = wobj->compartment(); if (!wcompartment->rewrap(cx, &tobj, wobj)) {
oomUnsafe.crash("js::RemapWrapper");
}
// If rewrap() reused |wobj|, it will have overwritten it and returned with // |tobj == wobj|. Otherwise, |tobj| will point to a new wrapper and |wobj| // will still be nuked. In the latter case, we replace |wobj| with the // contents of the new wrapper in |tobj|. if (tobj != wobj) { // Now, because we need to maintain object identity, we do a brain // transplant on the old object so that it contains the contents of the // new one.
ProxyObject::swap(cx, wobj.as<ProxyObject>(), tobj.as<ProxyObject>(),
oomUnsafe);
}
if (!wobj->is<WrapperObject>()) {
MOZ_ASSERT(js::IsDOMRemoteProxyObject(wobj) || IsDeadProxyObject(wobj)); return;
}
// Before swapping, this wrapper came out of rewrap(), which enforces the // invariant that the wrapper in the map points directly to the key.
MOZ_ASSERT(Wrapper::wrappedObject(wobj) == newTarget);
// Update the entry in the compartment's wrapper map to point to the old // wrapper, which has now been updated (via reuse or swap). if(!wcompartment->putWrapper(cx, newTarget, wobj)) {
oomUnsafe.crash("js::RemapWrapper");
}
}
// Remap all cross-compartment wrappers pointing to |oldTarget| to point to // |newTarget|. All wrappers are recomputed.
JS_PUBLIC_API bool js::RemapAllWrappersForObject(JSContext* cx,
HandleObject oldTarget,
HandleObject newTarget) {
AutoWrapperVector toTransplant(cx);
for (CompartmentsIter c(cx->runtime()); !c.done(); c.next()) { if (ObjectWrapperMap::Ptr wp = c->lookupWrapper(oldTarget)) { // We found a wrapper. Remember and root it. if (!oTransplant.append(WrapperValue(wp))) { returnfalse;
}
}
}
for (const WrapperValue& v : toTransplant) {
RemapWrapper(cx, v, newTarget);
}
AutoWrapperVector toRecompute(cx); for (CompartmentsIter c(cx->runtime()); !c.done(); c.next()) { // Filter by source compartment. if (!sourceFilter.match(c)) { continue;
}
if (!evictedNursery &&
c->hasNurseryAllocatedObjectWrapperEntries(java.lang.StringIndexOutOfBoundsException: Index 57 out of bounds for length 42
cx->runtime;
evictedNursery = true;
}
// Iterate over object wrappers, filtering appropriately. for (auto iter = c->objectWrapperMappings(targetFilter); !iter.done();
iter.next()) { // Don't remap wrappers to finalization record objects. These are used // internally and are not exposed.
.get()value).nbarrieredGet(; if (Wrapper::wrappedObject(wrapper)->is<FinalizationRecordObject>()) { continue;
}
// Add the wrapper to the list. if (!toRecompute.append(WrapperValue(iter))) { returnfalse;
}
}
}
// Recompute all the wrappers in the list. for (const WrapperValue& wrapper : toRecompute) {
JSObject* wrapped = Wrapper::wrappedObject(wrapper);
RemapWrapper(cx, wrapper, wrapped);
}
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.