Skip to content

Cage Blob payload pointers relative to the JS heap - #7666

Open
floitsch wants to merge 1 commit into
mainfrom
floitsch/blob-second-cage
Open

floitsch wants to merge 1 commit into
mainfrom
floitsch/blob-second-cage

Conversation

@floitsch

@floitsch floitsch commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Blob payload views use a 32-bit offset relative to the current isolate's JS cage plus 4 GiB, so a corrupted stored offset cannot select another isolate group's memory. SandboxedBytes also stores a 32-bit length and aborts if a sandboxed view cannot be represented at construction; reads reconstruct the pointer through the public sandbox-address-space API without a range check. Non-sandbox builds retain ordinary pointers.

Sandbox-enabled backing-store allocations must fit in that second 4 GiB region, with sandbox guard regions disabled. The downstream 8 GiB sandbox layout already provides it, so this needs no V8 changes. The length bounds overrun distance. The helper does not validate allocation ownership or object type.

Validation: ten focused downstream test targets passed with --runs_per_test=5, including corruption and cross-isolate cage tests, Blob C++/JS tests, FormData, streams, and R2 variants. Clang-tidy and formatting checks passed. The helper also passed a syntax check with sandbox support disabled.

@floitsch
floitsch marked this pull request as ready for review October 8, 2026 15:20
@floitsch
floitsch requested review from a team as code owners October 8, 2026 15:20
@floitsch
floitsch requested a review from erikcorry October 8, 2026 15:20
@ask-bonk

ask-bonk Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Since last review: 1 resolved, 0 still open, 0 new.
LGTM!


Reviewed commit: b10911d9 · github run

Comment thread src/workerd/api/blob-test.c++
Comment thread src/workerd/jsg/sandbox.c++ Outdated
Comment thread src/workerd/jsg/sandbox.c++ Outdated
Comment thread src/workerd/jsg/sandbox.c++ Outdated
Comment thread src/workerd/jsg/sandbox.c++ Outdated
@floitsch
floitsch force-pushed the floitsch/blob-second-cage branch from 1ce9b0b to 0d7ec47 Compare October 9, 2026 09:47
Comment thread src/workerd/jsg/sandbox.c++ Outdated
Absolute native Blob payload pointers can select memory outside the
current isolate group if native state is corrupted. Store sandboxed
byte views as a 32-bit offset from the current JS cage plus 4 GiB,
with a 32-bit length, and decode using the supplied isolate's base.

Use the public sandbox address-space API with guard regions disabled.
Require exactly two 4 GiB cages at compile time.
Unrepresentable sandbox views log a fatal error and abort. Decoding
needs no range check; bounded overruns rely on protected neighbors.
Non-sandbox builds retain ordinary pointers and recoverable size
errors.

Thread the isolate lock through Blob readers, File views, FormData,
and buffered streams. Cover nested slices, empty payloads, File data,
and R2 Blob bodies, including their instrumentation expectations.

No JavaScript API or valid Blob behavior changes, so no compatibility
flag is required.

Ten focused downstream test targets passed five runs each. Clang-tidy
and formatting checks passed, and the non-sandbox helper compiles.
@floitsch
floitsch force-pushed the floitsch/blob-second-cage branch from 0d7ec47 to b10911d Compare October 9, 2026 13:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants