add_task(async function test_bug1969341() {
// Bug 1969341 was an assertion crash due to a race condition. To hit the
// assertion you had to rapidly initiate a new WebAuthn transaction
// before the previous transaction state was fully torn down. The reproducer
// attached to bug 1969341 kicked off a WebAuthn transaction in the getter
// for PublicKeyCredential.then, which caused uncontrolled recursion.
// This test case limits the recursion depth. In manual tests, 10 levels
// was sufficient to hit the crash with high probability.
const maxRecursionDepth = 10
let currentRecursionDepth = 0;
var triggerDone; var done = new Promise((resolve) => {
triggerDone = resolve;
});
// Set up a PublicKeyCredential prior to making PublicKeyCredential thenable,
// this lets us control when the recursion starts.
let credential = await navigator.credentials
.create({
publicKey: { rp: { id: document.domain, name: "none" },
user: { id: crypto.getRandomValues(new Uint8Array(16)), displayName: "A", name: "A" },
challenge: crypto.getRandomValues(new Uint8Array(16)),
pubKeyCredParams: [
{ type: "public-key", alg: cose_alg_ECDSA_w_SHA256 },
],
},
})
ok(
currentRecursionDepth == 0, "the 'PublicKeyCredential.then' getter should not have been evaluated"
);
// This will invoke the PublicKeyCredential.then getter.
await credential;
// Wait until we've reached maxRecursionDepth.
await done;
ok(
currentRecursionDepth == maxRecursionDepth, "the 'PublicKeyCredential.then' getter should been called recursively"
);
});
</script>
</body>
</html>
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.