diff --git a/lib/internal/webstreams/readablestream.js b/lib/internal/webstreams/readablestream.js index 876e3a5bf6e2f0..b610c34740cfd1 100644 --- a/lib/internal/webstreams/readablestream.js +++ b/lib/internal/webstreams/readablestream.js @@ -93,9 +93,6 @@ const { } = require('internal/streams/utils'); const { - ArrayBufferViewGetBuffer, - ArrayBufferViewGetByteLength, - ArrayBufferViewGetByteOffset, AsyncIterator, canCopyArrayBuffer, cloneAsUint8Array, @@ -106,6 +103,7 @@ const { enqueueValueWithSize, extractHighWaterMark, extractSizeAlgorithm, + getArrayBufferView, getNonWritablePropertyDescriptor, isBrandCheck, kState, @@ -688,8 +686,9 @@ class ReadableStreamBYOBRequest { 'This BYOB request has been invalidated'); } - const viewByteLength = ArrayBufferViewGetByteLength(view); - const viewBuffer = ArrayBufferViewGetBuffer(view); + const arrayBufferView = getArrayBufferView(view); + const viewBuffer = arrayBufferView[0]; + const viewByteLength = arrayBufferView[2]; const viewBufferByteLength = ArrayBufferPrototypeGetByteLength(viewBuffer); if (ArrayBufferPrototypeGetDetached(viewBuffer)) { @@ -980,8 +979,9 @@ class ReadableStreamBYOBReader { } validateObject(options, 'options', kValidateObjectAllowObjectsAndNull); - const viewByteLength = ArrayBufferViewGetByteLength(view); - const viewBuffer = ArrayBufferViewGetBuffer(view); + const arrayBufferView = getArrayBufferView(view); + const viewBuffer = arrayBufferView[0]; + const viewByteLength = arrayBufferView[2]; if (isSharedArrayBuffer(viewBuffer)) { throw new ERR_INVALID_ARG_VALUE( @@ -1198,8 +1198,9 @@ class ReadableByteStreamController { if (!isReadableByteStreamController(this)) throw new ERR_INVALID_THIS('ReadableByteStreamController'); validateBuffer(chunk); - const chunkByteLength = ArrayBufferViewGetByteLength(chunk); - const chunkBuffer = ArrayBufferViewGetBuffer(chunk); + const arrayBufferView = getArrayBufferView(chunk); + const chunkBuffer = arrayBufferView[0]; + const chunkByteLength = arrayBufferView[2]; if (isSharedArrayBuffer(chunkBuffer)) { throw new ERR_INVALID_ARG_VALUE( @@ -2745,9 +2746,10 @@ function readableByteStreamControllerPullInto( assert(minimumFill >= elementSize && minimumFill <= view.byteLength); assert(minimumFill % elementSize === 0); - const buffer = ArrayBufferViewGetBuffer(view); - const byteOffset = ArrayBufferViewGetByteOffset(view); - const byteLength = ArrayBufferViewGetByteLength(view); + const arrayBufferView = getArrayBufferView(view); + const buffer = arrayBufferView[0]; + const byteOffset = arrayBufferView[1]; + const byteLength = arrayBufferView[2]; const bufferByteLength = ArrayBufferPrototypeGetByteLength(buffer); let transferredBuffer; @@ -2888,9 +2890,10 @@ function readableByteStreamControllerEnqueue(controller, chunk) { stream, } = controller[kState]; - const buffer = ArrayBufferViewGetBuffer(chunk); - const byteOffset = ArrayBufferViewGetByteOffset(chunk); - const byteLength = ArrayBufferViewGetByteLength(chunk); + const arrayBufferView = getArrayBufferView(chunk); + const buffer = arrayBufferView[0]; + const byteOffset = arrayBufferView[1]; + const byteLength = arrayBufferView[2]; if (closeRequested || stream[kState].state !== 'readable') return; @@ -3183,9 +3186,10 @@ function readableByteStreamControllerRespondWithNewView(controller, view) { const desc = pendingPullIntos[0]; assert(stream[kState].state !== 'errored'); - const viewByteLength = ArrayBufferViewGetByteLength(view); - const viewByteOffset = ArrayBufferViewGetByteOffset(view); - const viewBuffer = ArrayBufferViewGetBuffer(view); + const arrayBufferView = getArrayBufferView(view); + const viewBuffer = arrayBufferView[0]; + const viewByteOffset = arrayBufferView[1]; + const viewByteLength = arrayBufferView[2]; const viewBufferByteLength = ArrayBufferPrototypeGetByteLength(viewBuffer); if (stream[kState].state === 'closed') { diff --git a/lib/internal/webstreams/util.js b/lib/internal/webstreams/util.js index 808b0b069e57f7..9efee974625973 100644 --- a/lib/internal/webstreams/util.js +++ b/lib/internal/webstreams/util.js @@ -1,9 +1,6 @@ 'use strict'; const { - ArrayBufferPrototypeGetByteLength, - ArrayBufferPrototypeGetDetached, - ArrayBufferPrototypeSlice, ArrayPrototypePush, ArrayPrototypeShift, AsyncIteratorPrototype, @@ -11,9 +8,7 @@ const { NumberIsNaN, PromisePrototypeThen, ReflectApply, - ReflectGet, Symbol, - Uint8Array, } = primordials; const { @@ -27,16 +22,19 @@ const { } = internalBinding('buffer'); const { - inspect, -} = require('util'); - -const { + canCopyArrayBuffer, + cloneAsUint8Array, constants: { kPending, }, + getArrayBufferView, getPromiseDetails, } = internalBinding('util'); +const { + inspect, +} = require('util'); + const assert = require('internal/assert'); const { @@ -87,38 +85,11 @@ function customInspect(depth, options, name, data) { return `${name} ${inspect(data, opts)}`; } -// These are defensive to work around the possibility that -// the buffer, byteLength, and byteOffset properties on -// ArrayBuffer and ArrayBufferView's may have been tampered with. - -function ArrayBufferViewGetBuffer(view) { - return ReflectGet(view.constructor.prototype, 'buffer', view); -} - -function ArrayBufferViewGetByteLength(view) { - return ReflectGet(view.constructor.prototype, 'byteLength', view); -} - -function ArrayBufferViewGetByteOffset(view) { - return ReflectGet(view.constructor.prototype, 'byteOffset', view); -} - -function cloneAsUint8Array(view) { - const buffer = ArrayBufferViewGetBuffer(view); - const byteOffset = ArrayBufferViewGetByteOffset(view); - const byteLength = ArrayBufferViewGetByteLength(view); - return new Uint8Array( - ArrayBufferPrototypeSlice(buffer, byteOffset, byteOffset + byteLength), - ); -} - -function canCopyArrayBuffer(toBuffer, toIndex, fromBuffer, fromIndex, count) { - return toBuffer !== fromBuffer && - !ArrayBufferPrototypeGetDetached(toBuffer) && - !ArrayBufferPrototypeGetDetached(fromBuffer) && - toIndex + count <= ArrayBufferPrototypeGetByteLength(toBuffer) && - fromIndex + count <= ArrayBufferPrototypeGetByteLength(fromBuffer); -} +// getArrayBufferView, canCopyArrayBuffer, and cloneAsUint8Array are +// implemented in src/node_util.cc via direct V8 API calls. They are immune to +// user tampering of typed-array prototypes (matching the defensive behavior of +// the previous Reflect.get-based JS implementation) and faster on hot +// byte-stream paths. function isBrandCheck(brand) { return (value) => { @@ -206,9 +177,6 @@ function lazyTransfer() { } module.exports = { - ArrayBufferViewGetBuffer, - ArrayBufferViewGetByteLength, - ArrayBufferViewGetByteOffset, AsyncIterator, canCopyArrayBuffer, cloneAsUint8Array, @@ -219,6 +187,7 @@ module.exports = { enqueueValueWithSize, extractHighWaterMark, extractSizeAlgorithm, + getArrayBufferView, getNonWritablePropertyDescriptor, isBrandCheck, isPromisePending, diff --git a/src/node_buffer.cc b/src/node_buffer.cc index 2778422ea4e7b7..05c73785ea6718 100644 --- a/src/node_buffer.cc +++ b/src/node_buffer.cc @@ -1480,11 +1480,12 @@ void CopyArrayBuffer(const FunctionCallbackInfo& args) { // args[3] == Source ArrayBuffer Offset // args[4] == bytesToCopy + Environment* env = Environment::GetCurrent(args); CHECK(args[0]->IsArrayBuffer() || args[0]->IsSharedArrayBuffer()); - CHECK(args[1]->IsUint32()); + CHECK(args[1]->IsNumber()); CHECK(args[2]->IsArrayBuffer() || args[2]->IsSharedArrayBuffer()); - CHECK(args[3]->IsUint32()); - CHECK(args[4]->IsUint32()); + CHECK(args[3]->IsNumber()); + CHECK(args[4]->IsNumber()); void* destination; size_t destination_byte_length; @@ -1495,16 +1496,36 @@ void CopyArrayBuffer(const FunctionCallbackInfo& args) { size_t source_byte_length; std::tie(source, source_byte_length) = DecomposeBufferToParts(args[2]); - uint32_t destination_offset = args[1].As()->Value(); - uint32_t source_offset = args[3].As()->Value(); - size_t bytes_to_copy = args[4].As()->Value(); - - CHECK_GE(destination_byte_length - destination_offset, bytes_to_copy); - CHECK_GE(source_byte_length - source_offset, bytes_to_copy); + int64_t destination_offset; + int64_t source_offset; + int64_t bytes_to_copy; + if (!args[1]->IntegerValue(env->context()).To(&destination_offset) || + !args[3]->IntegerValue(env->context()).To(&source_offset) || + !args[4]->IntegerValue(env->context()).To(&bytes_to_copy)) { + return; + } - uint8_t* dest = static_cast(destination) + destination_offset; - uint8_t* src = static_cast(source) + source_offset; - memcpy(dest, src, bytes_to_copy); + CHECK_GE(destination_offset, 0); + CHECK_GE(source_offset, 0); + CHECK_GE(bytes_to_copy, 0); + + const uint64_t destination_offset_u = + static_cast(destination_offset); + const uint64_t source_offset_u = static_cast(source_offset); + const uint64_t bytes_to_copy_u = static_cast(bytes_to_copy); + const uint64_t destination_byte_length_u = destination_byte_length; + const uint64_t source_byte_length_u = source_byte_length; + CHECK_LE(destination_offset_u, destination_byte_length_u); + CHECK_LE(source_offset_u, source_byte_length_u); + CHECK_LE(bytes_to_copy_u, destination_byte_length_u - destination_offset_u); + CHECK_LE(bytes_to_copy_u, source_byte_length_u - source_offset_u); + + const size_t destination_offset_s = static_cast(destination_offset_u); + const size_t source_offset_s = static_cast(source_offset_u); + const size_t bytes_to_copy_s = static_cast(bytes_to_copy_u); + uint8_t* dest = static_cast(destination) + destination_offset_s; + uint8_t* src = static_cast(source) + source_offset_s; + memcpy(dest, src, bytes_to_copy_s); } // Converts a number parameter to size_t suitable for ArrayBuffer sizes diff --git a/src/node_util.cc b/src/node_util.cc index 6d3373caae6c5c..be4961f63a6006 100644 --- a/src/node_util.cc +++ b/src/node_util.cc @@ -27,6 +27,7 @@ using v8::Local; using v8::LocalVector; using v8::MaybeLocal; using v8::Name; +using v8::Number; using v8::Object; using v8::ObjectTemplate; using v8::ONLY_CONFIGURABLE; @@ -42,6 +43,7 @@ using v8::StackFrame; using v8::StackTrace; using v8::String; using v8::Uint32; +using v8::Uint8Array; using v8::Value; // If a UTF-16 character is a low/trailing surrogate. @@ -194,6 +196,111 @@ void ArrayBufferViewHasBuffer(const FunctionCallbackInfo& args) { args.GetReturnValue().Set(args[0].As()->HasBuffer()); } +// Returns [buffer, byteOffset, byteLength] in a single binding crossing, +// equivalent to reading the three properties via +// Reflect.get(view.constructor.prototype, ..., view). Uses the V8 API +// directly so it is immune to prototype tampering and avoids the JS-side +// overhead of the defensive accessors in lib/internal/. +void GetArrayBufferView(const FunctionCallbackInfo& args) { + Isolate* isolate = args.GetIsolate(); + CHECK(args[0]->IsArrayBufferView()); + Local view = args[0].As(); + Local values[] = { + view->Buffer(), + Number::New(isolate, static_cast(view->ByteOffset())), + Number::New(isolate, static_cast(view->ByteLength())), + }; + args.GetReturnValue().Set(Array::New(isolate, values, arraysize(values))); +} + +static bool ReadNonNegativeInteger(Environment* env, + Local value, + uint64_t* result) { + int64_t integer; + if (!value->IntegerValue(env->context()).To(&integer)) { + return false; + } + if (integer < 0) { + return false; + } + *result = static_cast(integer); + return true; +} + +// Returns true iff bytes can be safely copied between the buffers given the +// requested offsets and count. Matches lib/internal/webstreams/util.js: +// toBuffer !== fromBuffer && +// !toBuffer.detached && +// !fromBuffer.detached && +// toIndex + count <= toBuffer.byteLength && +// fromIndex + count <= fromBuffer.byteLength +void CanCopyArrayBuffer(const FunctionCallbackInfo& args) { + Environment* env = Environment::GetCurrent(args); + CHECK(args[0]->IsArrayBuffer() || args[0]->IsSharedArrayBuffer()); + CHECK(args[1]->IsNumber()); + CHECK(args[2]->IsArrayBuffer() || args[2]->IsSharedArrayBuffer()); + CHECK(args[3]->IsNumber()); + CHECK(args[4]->IsNumber()); + + // SharedArrayBuffer handles are interoperable with ArrayBuffer handles in + // V8, so we can use the ArrayBuffer accessors uniformly. WasDetached() + // always returns false on a SAB. + Local to_buffer = args[0].As(); + Local from_buffer = args[2].As(); + + if (to_buffer->StrictEquals(from_buffer)) { + args.GetReturnValue().Set(false); + return; + } + if (to_buffer->WasDetached() || from_buffer->WasDetached()) { + args.GetReturnValue().Set(false); + return; + } + + uint64_t to_index; + uint64_t from_index; + uint64_t count; + if (!ReadNonNegativeInteger(env, args[1], &to_index) || + !ReadNonNegativeInteger(env, args[3], &from_index) || + !ReadNonNegativeInteger(env, args[4], &count)) { + args.GetReturnValue().Set(false); + return; + } + + const uint64_t to_byte_length = to_buffer->ByteLength(); + const uint64_t from_byte_length = from_buffer->ByteLength(); + + bool ok = to_index <= to_byte_length && count <= to_byte_length - to_index && + from_index <= from_byte_length && + count <= from_byte_length - from_index; + args.GetReturnValue().Set(ok); +} + +// Equivalent to: +// new Uint8Array(view.buffer.slice(view.byteOffset, +// view.byteOffset + view.byteLength)) +// Allocates a fresh ArrayBuffer with the view's bytes copied into it, then +// returns a Uint8Array over the full new buffer. Avoids the JS-side +// Reflect.get + slice round-trip. +void CloneAsUint8Array(const FunctionCallbackInfo& args) { + Environment* env = Environment::GetCurrent(args); + Isolate* isolate = env->isolate(); + CHECK(args[0]->IsArrayBufferView()); + Local view = args[0].As(); + size_t byte_length = view->ByteLength(); + Local new_buffer; + if (!ArrayBuffer::MaybeNew(isolate, byte_length).ToLocal(&new_buffer)) { + // MaybeNew does not schedule an exception on allocation failure. + THROW_ERR_MEMORY_ALLOCATION_FAILED(isolate); + return; + } + if (byte_length > 0) { + size_t copied = view->CopyContents(new_buffer->Data(), byte_length); + CHECK_EQ(copied, byte_length); + } + args.GetReturnValue().Set(Uint8Array::New(new_buffer, 0, byte_length)); +} + static uint32_t GetUVHandleTypeCode(const uv_handle_type type) { // TODO(anonrig): We can use an enum here and then create the array in the // binding, which will remove the hard-coding in C++ and JS land. @@ -480,6 +587,9 @@ void RegisterExternalReferences(ExternalReferenceRegistry* registry) { registry->Register(GetExternalValue); registry->Register(Sleep); registry->Register(ArrayBufferViewHasBuffer); + registry->Register(GetArrayBufferView); + registry->Register(CanCopyArrayBuffer); + registry->Register(CloneAsUint8Array); registry->Register(GuessHandleType); registry->Register(fast_guess_handle_type_); registry->Register(ParseEnv); @@ -589,6 +699,11 @@ void Initialize(Local target, SetMethod(context, target, "parseEnv", ParseEnv); SetMethod( context, target, "arrayBufferViewHasBuffer", ArrayBufferViewHasBuffer); + SetMethodNoSideEffect( + context, target, "getArrayBufferView", GetArrayBufferView); + SetMethodNoSideEffect( + context, target, "canCopyArrayBuffer", CanCopyArrayBuffer); + SetMethod(context, target, "cloneAsUint8Array", CloneAsUint8Array); SetMethod(context, target, "constructSharedArrayBuffer", diff --git a/test/parallel/test-util-internal.js b/test/parallel/test-util-internal.js index e2b500daa70060..b446042ac3b226 100644 --- a/test/parallel/test-util-internal.js +++ b/test/parallel/test-util-internal.js @@ -7,6 +7,9 @@ const fixtures = require('../common/fixtures'); const { internalBinding } = require('internal/test/binding'); const { + canCopyArrayBuffer, + cloneAsUint8Array, + getArrayBufferView, privateSymbols: { arrow_message_private_symbol, }, @@ -28,3 +31,28 @@ try { } assert.match(arrowMessage, /bad_syntax\.js:1/); + +{ + const view = new Uint8Array(new ArrayBuffer(8), 2, 4); + assert.deepStrictEqual(getArrayBufferView(view), [view.buffer, 2, 4]); + + const sabView = new Uint8Array(new SharedArrayBuffer(8), 2, 4); + assert.deepStrictEqual(getArrayBufferView(sabView), [sabView.buffer, 2, 4]); +} + +{ + const source = new Uint8Array([1, 2, 3, 4]); + const clone = cloneAsUint8Array(source.subarray(1, 3)); + assert.deepStrictEqual([...clone], [2, 3]); + assert.notStrictEqual(clone.buffer, source.buffer); +} + +{ + const to = new ArrayBuffer(8); + const from = new ArrayBuffer(8); + const sab = new SharedArrayBuffer(8); + assert.strictEqual(canCopyArrayBuffer(to, 0, from, 0, 8), true); + assert.strictEqual(canCopyArrayBuffer(sab, 0, from, 0, 8), true); + assert.strictEqual(canCopyArrayBuffer(to, 2 ** 32, from, 0, 1), false); + assert.strictEqual(canCopyArrayBuffer(to, 0, from, 0, 2 ** 32), false); +}