forked from LeenkxTeam/Kmake
43 lines
1.9 KiB
JavaScript
43 lines
1.9 KiB
JavaScript
|
|
// Copyright 2024 the V8 project authors. All rights reserved.
|
||
|
|
// Use of this source code is governed by a BSD-style license that can be
|
||
|
|
// found in the LICENSE file.
|
||
|
|
|
||
|
|
// Flags: --sandbox-testing
|
||
|
|
|
||
|
|
const kTypedArrayType = Sandbox.getInstanceTypeIdFor("JS_TYPED_ARRAY_TYPE");
|
||
|
|
const kTypedArrayByteOffsetOffset =
|
||
|
|
Sandbox.getFieldOffset(kTypedArrayType, "byte_offset");
|
||
|
|
const kTypedArrayByteLengthOffset =
|
||
|
|
Sandbox.getFieldOffset(kTypedArrayType, "byte_length");
|
||
|
|
const kTypedArrayLengthOffset =
|
||
|
|
Sandbox.getFieldOffset(kTypedArrayType, "length");
|
||
|
|
const GB = 1024 * 1024 * 1024;
|
||
|
|
const kMaxInSandboxBufferSize = 32*GB - 1;
|
||
|
|
// Something reasonable, must be smaller than the maximum module size.
|
||
|
|
const kBufferSize = 1 * GB;
|
||
|
|
// When stored on-heap, these offsets and sizes are left shifted to guarantee
|
||
|
|
// that they are always smaller than the maximum buffer size.
|
||
|
|
const kBoundedSizeShift = 29;
|
||
|
|
const kShiftedBufferSize = BigInt(kBufferSize) << BigInt(kBoundedSizeShift);
|
||
|
|
|
||
|
|
let memory = new DataView(new Sandbox.MemoryView(0, 0x100000000));
|
||
|
|
|
||
|
|
let array = new Uint8Array(new ArrayBuffer(0));
|
||
|
|
let array_address = Sandbox.getAddressOf(array);
|
||
|
|
|
||
|
|
let byte_offset_address = array_address + kTypedArrayByteOffsetOffset;
|
||
|
|
memory.setBigUint64(byte_offset_address, 0xffffffffffffffffn, true);
|
||
|
|
let byte_length_offset_address = array_address + kTypedArrayByteLengthOffset;
|
||
|
|
memory.setBigUint64(byte_length_offset_address, kShiftedBufferSize, true);
|
||
|
|
let length_offset_address = array_address + kTypedArrayLengthOffset;
|
||
|
|
memory.setBigUint64(length_offset_address, kShiftedBufferSize, true);
|
||
|
|
|
||
|
|
assertEquals(array.byteOffset, kMaxInSandboxBufferSize);
|
||
|
|
assertEquals(array.byteLength, kBufferSize);
|
||
|
|
|
||
|
|
// WebAssembly.Validate (and similar APIs) will access the TypedArray's data by
|
||
|
|
// fetching the Data() of the associated ArrayBuffer's BackingStore, then
|
||
|
|
// adding the ByteOffset(). The Data() of the BackingStore must never be
|
||
|
|
// nullptr, otherwise we'd end up accessing out-of-sandbox memory.
|
||
|
|
WebAssembly.validate(array);
|