ported from mozilla: Bug 1538622 - StructuredClone serialize and deserialize should treat back reference consistently r=jorendorff (aca6f427e0)

This commit is contained in:
roytam1 2023-10-22 23:11:52 +08:00
commit e7c5600d7d
4 changed files with 64 additions and 4 deletions

View file

@ -764,6 +764,7 @@ skip-if = debug == false
[test_setting_opener.html]
[test_simplecontentpolicy.html]
skip-if = e10s # Bug 1156489.
[test_structuredclone_backref.html]
[test_text_wholeText.html]
[test_textnode_normalize_in_selection.html]
[test_textnode_split_in_selection.html]

View file

@ -0,0 +1,32 @@
<!DOCTYPE HTML>
<script src="/tests/SimpleTest/SimpleTest.js"></script>
<link rel="stylesheet" href="/tests/SimpleTest/test.css">
<a target="_blank" href="https://bugzilla.mozilla.org/show_bug.cgi?id=1538622">Mozilla Bug 1538622</a>
<script>
SimpleTest.waitForExplicitFinish();
let o1 = new ImageData(25, 1),
o2 = new ImageData(50, 1),
o3 = new ImageData(75, 1),
o4 = new ImageData(100, 1);
let data = {
img1: o1,
img2: o2,
img3: o3,
img4: o4,
img5: o4,
};
window.addEventListener("message", windowMessage);
window.postMessage(data);
function windowMessage(e) {
let dataCopied = e.data;
ok(dataCopied.img5 instanceof ImageData, "backref ImageData should still be an ImageData");
is(dataCopied.img5, dataCopied.img4, "backref ImageData should be the referenced one");
SimpleTest.finish();
}
</script>

View file

@ -54,8 +54,7 @@ function windowMessage(evt) {
ok(checkPattern(imageData, pattern),
'postMessage from self worked correctly');
// We're not spec compliant on this yet.
todo_is(imageData.data, evt.data.dataRef,
is(imageData.data, evt.data.dataRef,
'Should have backrefs for imagedata buffer');
// Make a new pattern, and send it to a worker.

View file

@ -2046,6 +2046,7 @@ bool
JSStructuredCloneReader::startRead(MutableHandleValue vp)
{
uint32_t tag, data;
bool alreadAppended = false;
if (!in.readPair(&tag, &data))
return false;
@ -2246,15 +2247,29 @@ JSStructuredCloneReader::startRead(MutableHandleValue vp)
"unsupported type");
return false;
}
// callbacks->read() might read other objects from the buffer.
// In startWrite we always write the object itself before calling
// the custom function. We should do the same here to keep
// indexing consistent.
uint32_t placeholderIndex = allObjs.length();
Value dummy = UndefinedValue();
if (!allObjs.append(dummy)) {
return false;
}
JSObject* obj = callbacks->read(context(), this, tag, data, closure);
if (!obj)
return false;
vp.setObject(*obj);
allObjs[placeholderIndex].set(vp);
alreadAppended = true;
}
}
if (vp.isObject() && !allObjs.append(vp))
if (!alreadAppended && vp.isObject() && !allObjs.append(vp)) {
return false;
}
return true;
}
@ -2828,7 +2843,20 @@ JS_WriteTypedArray(JSStructuredCloneWriter* w, HandleValue v)
MOZ_ASSERT(v.isObject());
assertSameCompartment(w->context(), v);
RootedObject obj(w->context(), &v.toObject());
return w->writeTypedArray(obj);
// startWrite can write everything, thus we should check here
// and report error if the user passes a wrong type.
if (!JS_IsTypedArrayObject(obj)) {
JS_ReportErrorNumberASCII(w->context(), GetErrorMessage, nullptr,
JSMSG_SC_BAD_SERIALIZED_DATA,
"expected type array");
return false;
}
// We should use startWrite instead of writeTypedArray, because
// typed array is an object, we should add it to the |memory|
// (allObjs) list. Directly calling writeTypedArray won't add it.
return w->startWrite(v);
}
JS_PUBLIC_API(bool)