Skip to content

Commit e9f08a7

Browse files
authored
Put reference on executable object's this_binding to avoid unwanted f… (#5169)
…rees before exiting execution This patch fixes #4870. The implementation is based on PR #4966, only resolved the conflicts and applied requested changes. Co-authored-by: Martin Negyokru [email protected] JerryScript-DCO-1.0-Signed-off-by: Gergo Csizi [email protected]
1 parent 348e6a4 commit e9f08a7

File tree

3 files changed

+92
-2
lines changed

3 files changed

+92
-2
lines changed

.github/workflows/gh-actions.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -171,7 +171,7 @@ jobs:
171171
- run: >-
172172
$RUNNER -q --jerry-tests
173173
--buildoptions=--stack-limit=0,--compile-flag=-fsanitize=address,--compile-flag=-m32,--compile-flag=-fno-omit-frame-pointer,--compile-flag=-fno-common,--compile-flag=-O2,--debug,--system-allocator=on,--linker-flag=-fuse-ld=gold
174-
--skip-list=parser-oom.js,parser-oom2.js,stack-limit.js,regression-test-issue-4901.js,regression-test-issue-4848.js,regression-test-issue-4890.js,regression-test-issue-2190.js,regression-test-issue-2258-2963.js,regression-test-issue-2448.js,regression-test-issue-2905.js,regression-test-issue-3785.js,proxy-evil-recursion.js,regression-test-issue-5101.js
174+
--skip-list=parser-oom.js,parser-oom2.js,stack-limit.js,regression-test-issue-4870.js,regression-test-issue-4901.js,regression-test-issue-4848.js,regression-test-issue-4890.js,regression-test-issue-2190.js,regression-test-issue-2258-2963.js,regression-test-issue-2448.js,regression-test-issue-2905.js,regression-test-issue-3785.js,proxy-evil-recursion.js,regression-test-issue-5101.js
175175
176176
ASAN_Tests_Debug:
177177
runs-on: ubuntu-latest
@@ -187,7 +187,7 @@ jobs:
187187
- run: >-
188188
$RUNNER -q --jerry-tests --build-debug
189189
--buildoptions=--stack-limit=0,--compile-flag=-fsanitize=address,--compile-flag=-m32,--compile-flag=-fno-omit-frame-pointer,--compile-flag=-fno-common,--compile-flag=-O2,--debug,--system-allocator=on,--linker-flag=-fuse-ld=gold
190-
--skip-list=parser-oom.js,parser-oom2.js,stack-limit.js,regression-test-issue-4901.js,regression-test-issue-4848.js,regression-test-issue-4890.js,regression-test-issue-2190.js,regression-test-issue-2258-2963.js,regression-test-issue-2448.js,regression-test-issue-2905.js,regression-test-issue-3785.js,proxy-evil-recursion.js,regression-test-issue-5101.js
190+
--skip-list=parser-oom.js,parser-oom2.js,stack-limit.js,regression-test-issue-4870.js,regression-test-issue-4901.js,regression-test-issue-4848.js,regression-test-issue-4890.js,regression-test-issue-2190.js,regression-test-issue-2258-2963.js,regression-test-issue-2448.js,regression-test-issue-2905.js,regression-test-issue-3785.js,proxy-evil-recursion.js,regression-test-issue-5101.js
191191
192192
UBSAN_Tests:
193193
runs-on: ubuntu-latest

jerry-core/vm/opcodes.c

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -737,6 +737,7 @@ opfunc_resume_executable_object (vm_executable_object_t *executable_object_p, /*
737737
ecma_ref_if_object (*register_p++);
738738
}
739739

740+
ecma_ref_if_object (executable_object_p->frame_ctx.this_binding);
740741
ecma_ref_if_object (executable_object_p->iterator);
741742

742743
JERRY_ASSERT (ECMA_EXECUTABLE_OBJECT_IS_SUSPENDED (executable_object_p));
@@ -770,6 +771,7 @@ opfunc_resume_executable_object (vm_executable_object_t *executable_object_p, /*
770771

771772
/* All resources are released. */
772773
executable_object_p->extended_object.u.cls.u2.executable_obj_flags |= ECMA_EXECUTABLE_OBJECT_COMPLETED;
774+
ecma_deref_if_object (executable_object_p->frame_ctx.this_binding);
773775
return result;
774776
}
775777

@@ -798,6 +800,7 @@ opfunc_resume_executable_object (vm_executable_object_t *executable_object_p, /*
798800
ecma_deref_if_object (*register_p++);
799801
}
800802

803+
ecma_deref_if_object (executable_object_p->frame_ctx.this_binding);
801804
ecma_deref_if_object (executable_object_p->iterator);
802805

803806
return result;
Lines changed: 87 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,87 @@
1+
// Copyright JS Foundation and other contributors, http://js.foundation
2+
//
3+
// Licensed under the Apache License, Version 2.0 (the "License");
4+
// you may not use this file except in compliance with the License.
5+
// You may obtain a copy of the License at
6+
//
7+
// http://www.apache.org/licenses/LICENSE-2.0
8+
//
9+
// Unless required by applicable law or agreed to in writing, software
10+
// distributed under the License is distributed on an "AS IS" BASIS
11+
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12+
// See the License for the specific language governing permissions and
13+
// limitations under the License.
14+
15+
async function f() {
16+
let arr = [0.000000];
17+
let fuzz_v152 = arr;
18+
let fuzz_v159 = fuzz_v152.__proto__;
19+
fuzz_v152.valueOf = function* (fuzz_v166, fuzz_v167) {
20+
while (arr) {
21+
}
22+
var fuzz_v172 = ~f;
23+
arr >>= [1.100000];
24+
return fuzz_v167;
25+
};
26+
arr.includes(arr, [340282346638528859811704183484516925440.000000], arr);
27+
delete [10];
28+
let fuzz_v253 = f.__proto__;
29+
let fuzz_v256 = {
30+
"D5FP8": f
31+
};
32+
arr["map"](f, new Object(true));
33+
arr.flat();
34+
let fuzz_v69 = false;
35+
await this;
36+
await f;
37+
var fuzz_v43 = arr -= new Date(new String({
38+
"findIndex": arr
39+
}));
40+
await this;
41+
let fuzz_v286 = Symbol.reject();
42+
await f;
43+
await new Promise(f);
44+
await new Promise(async function* (fuzz_v80) {
45+
var fuzz_v82 = new Uint32Array(fuzz_v80, arr, [1.100000], fuzz_v80, fuzz_v80);
46+
let fuzz_v96 = fuzz_v82.__proto__;
47+
this.length = 4;
48+
});
49+
await new Promise(async function* (fuzz_v138, fuzz_v139) {
50+
fuzz_v138.__proto__ = fuzz_v139;
51+
let fuzz_v147 = function* (fuzz_v149, fuzz_v150, fuzz_v151, fuzz_v152) {
52+
let fuzz_v165 = Reflect.apply(fuzz_v152, {
53+
"findIndex": fuzz_v150
54+
}, [{}]);
55+
switch ({
56+
includes: fuzz_v138,
57+
set valueOf(fuzz_v175) {
58+
fuzz_v150.valueOf = fuzz_v175;
59+
return;
60+
}
61+
}) {
62+
case [1.100000]:
63+
throw arr;
64+
break;
65+
case 5643033980980220.000000:
66+
let fuzz_v203 = String.prototype.trim.call(new String());
67+
break;
68+
default:
69+
fuzz_v43.valueOf = fuzz_v150;
70+
}
71+
let fuzz_v214 = fuzz_v69;
72+
let fuzz_v223 = Number.isInteger(2147483648);
73+
};
74+
var fuzz_v228 = f;
75+
delete f.__proto__;
76+
let fuzz_v237 = {};
77+
});
78+
await new Promise(f);
79+
await new Promise(async function* (fuzz_v269, fuzz_v270, fuzz_v271) {
80+
class fuzz_class273 extends f {
81+
82+
}
83+
return arr;
84+
});
85+
await new Promise(fuzz_v286);
86+
}
87+
f(f, f);

0 commit comments

Comments
 (0)