Issue #2765 - Follow-up: Fix UAF when returning the non-NAC style context from a frameless node

This commit is contained in:
Francis Dominic Fajardo 2025-06-27 23:43:23 +08:00 committed by roytam1
commit 6e358f1039
6 changed files with 8 additions and 12 deletions

View file

@ -9338,7 +9338,7 @@ nsLayoutUtils::ComputeGeometryBox(nsIFrame* aFrame,
return r;
}
/* static */ nsStyleContext*
/* static */ already_AddRefed<nsStyleContext>
nsLayoutUtils::GetNonAnonymousStyleContext(nsIFrame* aFrame)
{
nsIContent* node = aFrame->GetContent();
@ -9348,7 +9348,7 @@ nsLayoutUtils::GetNonAnonymousStyleContext(nsIFrame* aFrame)
}
MOZ_ASSERT(node, "Native anonymous element with no originating node?");
if (nsIFrame* primaryFrame = node->GetPrimaryFrame()) {
return primaryFrame->StyleContext();
return RefPtr<nsStyleContext>(primaryFrame->StyleContext()).forget();
}
// If the element doesn't have primary frame, get the computed style
// from the element directly.
@ -9356,9 +9356,5 @@ nsLayoutUtils::GetNonAnonymousStyleContext(nsIFrame* aFrame)
MOZ_ASSERT(node == pc->Document()->GetRootElement(),
"Root element is the only case for this fallback "
"path to be triggered");
RefPtr<nsStyleContext> styleContext =
pc->StyleSet()->ResolveStyleFor(node->AsElement(), nullptr);
// Dropping the strong reference is fine because the style should be
// held strongly by the element.
return styleContext.get();
return pc->StyleSet()->ResolveStyleFor(node->AsElement(), nullptr);
}

View file

@ -2885,7 +2885,7 @@ public:
* @param aFrame The frame associated with native anonymous content.
* @return The resolved style context of the nearest non-anonymous DOM ancestor.
*/
static nsStyleContext* GetNonAnonymousStyleContext(nsIFrame* aFrame);
static already_AddRefed<nsStyleContext> GetNonAnonymousStyleContext(nsIFrame* aFrame);
private:
static uint32_t sFontSizeInflationEmPerLine;

View file

@ -1058,7 +1058,7 @@ nsHTMLScrollFrame::Reflow(nsPresContext* aPresContext,
// This is only needed for root element because scrollbars of non-
// root elements with "scrollbar-width: none" is already suppressed
// in ScrollFrameHelper::CreateAnonymousContent.
nsStyleContext* scrollbarStyle = nsLayoutUtils::GetNonAnonymousStyleContext(this);
RefPtr<nsStyleContext> scrollbarStyle = nsLayoutUtils::GetNonAnonymousStyleContext(this);
auto scrollbarWidth = scrollbarStyle->StyleUIReset()->mScrollbarWidth;
if (scrollbarWidth == StyleScrollbarWidth::None) {
state.mVScrollbar = ShowScrollbar::Never;

View file

@ -2282,7 +2282,7 @@ IsHiDPIContext(nsPresContext* aContext)
static bool
IsScrollbarWidthThin(nsIFrame* aFrame)
{
nsStyleContext* styleContext = nsLayoutUtils::GetNonAnonymousStyleContext(aFrame);
RefPtr<nsStyleContext> styleContext = nsLayoutUtils::GetNonAnonymousStyleContext(aFrame);
auto scrollbarWidth = styleContext->StyleUIReset()->mScrollbarWidth;
return scrollbarWidth == StyleScrollbarWidth::Thin;
}

View file

@ -1101,7 +1101,7 @@ nsNativeThemeGTK::GetExtraSizeForWidget(nsIFrame* aFrame, uint8_t aWidgetType,
static bool
IsScrollbarWidthThin(nsIFrame* aFrame)
{
nsStyleContext* styleContext = nsLayoutUtils::GetNonAnonymousStyleContext(aFrame);
RefPtr<nsStyleContext> styleContext = nsLayoutUtils::GetNonAnonymousStyleContext(aFrame);
auto scrollbarWidth = styleContext->StyleUIReset()->mScrollbarWidth;
return scrollbarWidth == StyleScrollbarWidth::Thin;
}

View file

@ -1572,7 +1572,7 @@ GetThemeDpiScaleFactor(nsIFrame* aFrame)
static bool
IsScrollbarWidthThin(nsIFrame* aFrame)
{
nsStyleContext* styleContext = nsLayoutUtils::GetNonAnonymousStyleContext(aFrame);
RefPtr<nsStyleContext> styleContext = nsLayoutUtils::GetNonAnonymousStyleContext(aFrame);
auto scrollbarWidth = styleContext->StyleUIReset()->mScrollbarWidth;
return scrollbarWidth == StyleScrollbarWidth::Thin;
}