Repository navigation
Conversation
Contributor
|
Since last review: 1 resolved, 0 still open, 0 new. Reviewed commit: b10911d9 · github run |
erikcorry
approved these changes
Oct 9, 2026
floitsch
force-pushed
the
floitsch/blob-second-cage
branch
from
October 9, 2026 09:47
1ce9b0b to
0d7ec47
Compare
Absolute native Blob payload pointers can select memory outside the current isolate group if native state is corrupted. Store sandboxed byte views as a 32-bit offset from the current JS cage plus 4 GiB, with a 32-bit length, and decode using the supplied isolate's base. Use the public sandbox address-space API with guard regions disabled. Require exactly two 4 GiB cages at compile time. Unrepresentable sandbox views log a fatal error and abort. Decoding needs no range check; bounded overruns rely on protected neighbors. Non-sandbox builds retain ordinary pointers and recoverable size errors. Thread the isolate lock through Blob readers, File views, FormData, and buffered streams. Cover nested slices, empty payloads, File data, and R2 Blob bodies, including their instrumentation expectations. No JavaScript API or valid Blob behavior changes, so no compatibility flag is required. Ten focused downstream test targets passed five runs each. Clang-tidy and formatting checks passed, and the non-sandbox helper compiles.
floitsch
force-pushed
the
floitsch/blob-second-cage
branch
from
October 9, 2026 13:16
0d7ec47 to
b10911d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Blob payload views use a 32-bit offset relative to the current isolate's JS cage plus 4 GiB, so a corrupted stored offset cannot select another isolate group's memory.
SandboxedBytesalso stores a 32-bit length and aborts if a sandboxed view cannot be represented at construction; reads reconstruct the pointer through the public sandbox-address-space API without a range check. Non-sandbox builds retain ordinary pointers.Sandbox-enabled backing-store allocations must fit in that second 4 GiB region, with sandbox guard regions disabled. The downstream 8 GiB sandbox layout already provides it, so this needs no V8 changes. The length bounds overrun distance. The helper does not validate allocation ownership or object type.
Validation: ten focused downstream test targets passed with
--runs_per_test=5, including corruption and cross-isolate cage tests, Blob C++/JS tests, FormData, streams, and R2 variants. Clang-tidy and formatting checks passed. The helper also passed a syntax check with sandbox support disabled.