Loading...
Searching...
No Matches
v8-sandbox.h
Go to the documentation of this file.
1// Copyright 2024 the V8 project authors. All rights reserved.
2// Use of this source code is governed by a BSD-style license that can be
3// found in the LICENSE file.
4
5#ifndef INCLUDE_V8_SANDBOX_H_
6#define INCLUDE_V8_SANDBOX_H_
7
8#include <cstdint>
9
10#include "v8-internal.h" // NOLINT(build/include_directory)
11#include "v8config.h" // NOLINT(build/include_directory)
12
13namespace v8 {
14
28enum class CppHeapPointerTag : uint16_t {
29 kFirstTag = 0,
30 kNullTag = 0,
31
32 // Subtypes of v8::Object::Wrappable [0x0001 .. 0x6fff]
35
60
61 // V8-internal Oilpan objects that inherit from v8::Object::Wrappable.
63 // Kept temporarily for backwards compatibility with Chromium's
64 // wrapper_type_info.h across the V8 roll.
67
69
70 // Non-v8::Object::Wrappable CppHeap objects [0x7000 .. 0x7ffc]
71 kFirstNonWrappableTag = 0x7000,
72
75
78
80
81#if !V8_ENABLE_SANDBOX
82 // Embedders that use the sandbox should use specific tags for each type.
84#endif // !V8_ENABLE_SANDBOX
85
86 kZappedEntryTag = 0x7ffd,
87 kEvacuationEntryTag = 0x7ffe,
88 kFreeEntryTag = 0x7fff,
89 // The tags are limited to 15 bits, so the last tag is 0x7fff.
90 kLastTag = 0x7fff,
91};
92
94
97
98// All tags that are used with v8::Object::Wrappable have to be within this
99// tag range. The reason is that in some cases, an APIWrapper object has to be
100// unwrapped to access the v8::Object::Wrappable base class, e.g. to get type
101// information.
105
106// The tag range that embedders can use for their own types that inherit from
107// v8::Object::Wrappable.
111
112// The tag range for all non-v8::Object::Wrappable CppHeap objects, both
113// V8-internal and embedder-owned.
117
118// The tag range that embedders can use for their own types that do not inherit
119// from v8::Object::Wrappable.
123
126
134 public:
141};
142
143namespace internal {
144
145#ifdef V8_COMPRESS_POINTERS
146V8_INLINE static Address* GetCppHeapPointerTableBase(v8::Isolate* isolate) {
147 Address addr = reinterpret_cast<Address>(isolate) +
148 Internals::kIsolateCppHeapPointerTableOffset +
150 return *reinterpret_cast<Address**>(addr);
151}
152#endif // V8_COMPRESS_POINTERS
153
154template <typename T>
155V8_INLINE static T* ReadCppHeapPointerField(v8::Isolate* isolate,
156 Address heap_object_ptr, int offset,
157 CppHeapPointerTagRange tag_range) {
158 // This is a specialized version of the CppHeapPointerTable accessors
159 // which (1) allows the code to be inlined into the callers for performance
160 // and (2) is optimized for code size as there are a huge number of callers
161 // from auto-generated bindings code.
162
163#ifdef V8_COMPRESS_POINTERS
164 const CppHeapPointerHandle handle =
165 Internals::ReadRawField<CppHeapPointerHandle>(heap_object_ptr, offset);
166 const uint32_t index = handle >> kExternalPointerIndexShift;
167 const Address* table = GetCppHeapPointerTableBase(isolate);
168 const std::atomic<Address>* ptr =
169 reinterpret_cast<const std::atomic<Address>*>(&table[index]);
170 Address entry = std::atomic_load_explicit(ptr, std::memory_order_relaxed);
171
172 // Note: the cast to uint32_t is important here. Otherwise, the uint16_t's
173 // would be promoted to int in the range check below, which would result in
174 // undefined behavior (signed integer underflow) if the actual value is less
175 // than the lower bound. Then, the compiler would take advantage of the
176 // undefined behavior and turn the range check into a simple
177 // `actual_tag <= last_tag` comparison, which is incorrect.
178 uint32_t actual_tag = static_cast<uint16_t>(entry);
179 // The actual_tag is shifted to the left by one and contains the marking
180 // bit in the LSB. To ignore that during the type check, simply add one to
181 // the (shifted) range.
182 constexpr int kTagShift = internal::kCppHeapPointerTagShift;
183 uint32_t first_tag = static_cast<uint32_t>(tag_range.first) << kTagShift;
184 uint32_t last_tag = (static_cast<uint32_t>(tag_range.last) << kTagShift) + 1;
185 // Avoid DCE of the entry logic using volatile.
186 volatile Address safe_entry;
187 if (actual_tag >= first_tag && actual_tag <= last_tag) [[likely]] {
188 safe_entry = entry >> kCppHeapPointerPayloadShift;
189 } else {
190 // If the type check failed, we simply return nullptr here. That way:
191 // 1. The null handle always results in nullptr being returned here, which
192 // is a desired property. Otherwise, we would need an explicit check for
193 // the null handle above, and therefore an additional branch. This
194 // works because the 0th entry of the table always contains nullptr
195 // tagged with the null tag (i.e. an all-zeros entry). As such,
196 // regardless of whether the type check succeeds, the result will
197 // always be nullptr.
198 // 2. The returned pointer is guaranteed to crash even on platforms with
199 // top byte ignore (TBI), such as Arm64. The alternative would be to
200 // simply return the original entry with the left-shifted payload.
201 // However, due to TBI, an access to that may not always result in a
202 // crash (specifically, if the second most significant byte happens to
203 // be zero). In addition, there shouldn't be a difference on Arm64
204 // between returning nullptr or the original entry, since it will
205 // simply compile to a `csel x0, x8, xzr, lo` instead of a
206 // `csel x0, x10, x8, lo` instruction.
207 // 3. The machine code sequence ends up being pretty short, which is
208 // important here as this code will be inlined into a lot of functions.
209 safe_entry = 0;
210 }
211 return reinterpret_cast<T*>(safe_entry);
212#else // !V8_COMPRESS_POINTERS
213 return reinterpret_cast<T*>(
214 Internals::ReadRawField<Address>(heap_object_ptr, offset));
215#endif // !V8_COMPRESS_POINTERS
216}
217
218// TODO(saelo): temporary workaround needed to introduce range-based type
219// checks for the external pointer table. See comment above
220// ExternalPointerCanBeEmpty(ExternalPointerTagRange) function for details.
221V8_INLINE static constexpr bool ExternalPointerCanBeEmpty(
222 CppHeapPointerTagRange tag_range) {
223 return true;
224}
225
226} // namespace internal
227} // namespace v8
228
229#endif // INCLUDE_V8_SANDBOX_H_
Definition: v8-isolate.h:298
Definition: v8-sandbox.h:133
static void InitializeBeforeThreadCreation()
static const int kExternalEntityTableBasePointerOffset
Definition: v8-internal.h:1041
uint32_t CppHeapPointerHandle
Definition: v8-internal.h:413
constexpr uint64_t kCppHeapPointerPayloadShift
Definition: v8-internal.h:430
constexpr uint64_t kCppHeapPointerTagShift
Definition: v8-internal.h:429
uintptr_t Address
Definition: v8-internal.h:38
Definition: libplatform.h:15
constexpr CppHeapPointerTagRange kAnyCppHeapPointer(CppHeapPointerTag::kFirstTag, CppHeapPointerTag::kZappedEntryTag)
internal::TagRange< CppHeapPointerTag > CppHeapPointerTagRange
Definition: v8-sandbox.h:93
constexpr CppHeapPointerTagRange kEmbedderNonWrappableTagRange(CppHeapPointerTag::kFirstEmbedderNonWrappableTag, CppHeapPointerTag::kLastEmbedderNonWrappableTag)
constexpr CppHeapPointerTagRange kNonWrappableTagRange(CppHeapPointerTag::kFirstNonWrappableTag, CppHeapPointerTag::kLastNonWrappableTag)
constexpr CppHeapPointerTagRange kEmbedderWrappableTagRange(CppHeapPointerTag::kFirstEmbedderWrappableTag, CppHeapPointerTag::kLastEmbedderWrappableTag)
CppHeapPointerTag
Definition: v8-sandbox.h:28
constexpr CppHeapPointerTagRange kObjectWrappableTagRange(CppHeapPointerTag::kFirstObjectWrappableTag, CppHeapPointerTag::kLastObjectWrappableTag)
Definition: v8-internal.h:528
constexpr bool Contains(Tag tag) const
Definition: v8-internal.h:563
#define V8_EXPORT
Definition: v8config.h:874
#define V8_INLINE
Definition: v8config.h:518