Visitar URL original
Do not deserialize RTCCertificate in workers by annevk · Pull Request #76301 · WebKit/WebKit · GitHub
Skip to content

Do not deserialize RTCCertificate in workers - #76301

Merged
webkit-commit-queue merged 1 commit into
WebKit:mainfrom
annevk:eng/Do-not-deserialize-RTCCertificate-in-workers
Oct 9, 2026
Merged

webkit-commit-queue merged 1 commit into
WebKit:mainfrom
annevk:eng/Do-not-deserialize-RTCCertificate-in-workers

Conversation

@annevk

@annevk annevk commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

a0577c1

Do not deserialize RTCCertificate in workers
https://bugs.webkit.org/show_bug.cgi?id=326793
rdar://189499857

Reviewed by Youenn Fablet.

RTCCertificate is [Exposed=Window], but posting one to a dedicated,
shared, or service worker delivered it there. Use the generated exposure
check, through isInterfaceExposedInGlobalObject() from 322979@main, so
that those messages fail to deserialize and result in a messageerror
event.

RTCCertificate can also be stored in IndexedDB, and reading one back in a
worker used to deliver it there too. Now that it fails to deserialize,
IDBRequest's result, IDBCursorWithValue's value, and IDBRecord's value
would be null, silently losing the record. Align with Firefox instead:
the request succeeds and reading the value throws. Throw a DataCloneError
rather than Firefox's InvalidStateError, as proposed in
w3c/IndexedDB#391

(Chromium deserializes as null, which seems less useful.)

Tests: imported/w3c/web-platform-tests/IndexedDB/value-not-exposed-in-worker.tentative.html
       imported/w3c/web-platform-tests/webrtc/RTCCertificate-postMessage-to-workers.https.html

Canonical link: https://commits.webkit.org/323182@main

108be83

Misc iOS, visionOS, tvOS & watchOS macOS Linux Windows Apple Internal
✅ 🧪 style ✅ 🛠 ios ✅ 🛠 mac ✅ 🛠 wpe ✅ 🛠 win ✅ 🛠 ios-apple
✅ 🧪 bindings ✅ 🛠 ios-sim ✅ 🛠 mac-AS-debug ✅ 🧪 wpe-wk2   🧪 win-tests ✅ 🛠 mac-apple
✅ 🧪 webkitperl ✅ 🧪 ios-wk2 ✅ 🧪 api-mac ✅ 🧪 api-wpe ✅ 🛠 vision-apple
✅ 🧪 ios-wk2-wpt   🧪 api-mac-debug
✅ 🧪 api-ios ✅ 🧪 mac-wk2 ✅ 🛠 gtk3-gcc
✅ 🛠 ios-safer-cpp ✅ 🧪 mac-AS-debug-wk2 ✅ 🛠 gtk
✅ 🛠 vision ✅ 🧪 mac-wk2-stress ✅ 🧪 gtk-wk2
✅ 🛠 vision-sim ✅ 🧪 mac-intel-wk2 ✅ 🧪 api-gtk
✅ 🛠 🧪 unsafe-merge ✅ 🧪 vision-wk2 ✅ 🛠 mac-safer-cpp ✅ 🛠 playstation
✅ 🛠 tv ✅ 🧪 mac-site-isolation
✅ 🛠 tv-sim
✅ 🛠 watch
✅ 🛠 watch-sim

@annevk
annevk requested a review from cdumez as a code owner October 8, 2026 10:19
@annevk annevk self-assigned this Oct 8, 2026
@annevk annevk added the DOM For bugs specific to XML/HTML DOM elements (including parsing). label Oct 8, 2026
@annevk
annevk requested a review from youennf October 8, 2026 10:23
@webkit-ews-buildbot webkit-ews-buildbot added the merging-blocked Applied to prevent a change from being merged label Oct 8, 2026
@annevk annevk removed the merging-blocked Applied to prevent a change from being merged label Oct 8, 2026
Comment thread Source/WebCore/bindings/js/IDBBindingUtilities.cpp Outdated
@annevk
annevk force-pushed the eng/Do-not-deserialize-RTCCertificate-in-workers branch from 796e147 to 108be83 Compare October 8, 2026 17:14
@annevk annevk added safe-merge-queue Applied to automatically send a pull-request to merge-queue after passing EWS checks unsafe-merge-queue Applied to send a pull request to merge-queue, but skip building and testing labels Oct 8, 2026
https://bugs.webkit.org/show_bug.cgi?id=326793
rdar://189499857

Reviewed by Youenn Fablet.

RTCCertificate is [Exposed=Window], but posting one to a dedicated,
shared, or service worker delivered it there. Use the generated exposure
check, through isInterfaceExposedInGlobalObject() from 322979@main, so
that those messages fail to deserialize and result in a messageerror
event.

RTCCertificate can also be stored in IndexedDB, and reading one back in a
worker used to deliver it there too. Now that it fails to deserialize,
IDBRequest's result, IDBCursorWithValue's value, and IDBRecord's value
would be null, silently losing the record. Align with Firefox instead:
the request succeeds and reading the value throws. Throw a DataCloneError
rather than Firefox's InvalidStateError, as proposed in
w3c/IndexedDB#391

(Chromium deserializes as null, which seems less useful.)

Tests: imported/w3c/web-platform-tests/IndexedDB/value-not-exposed-in-worker.tentative.html
       imported/w3c/web-platform-tests/webrtc/RTCCertificate-postMessage-to-workers.https.html

Canonical link: https://commits.webkit.org/323182@main
@webkit-commit-queue
webkit-commit-queue force-pushed the eng/Do-not-deserialize-RTCCertificate-in-workers branch from 108be83 to a0577c1 Compare October 9, 2026 04:53
@webkit-commit-queue

Copy link
Copy Markdown
Collaborator

Committed 323182@main (a0577c1): https://commits.webkit.org/323182@main

Reviewed commits have been landed. Closing PR #76301 and removing active labels.

@webkit-commit-queue
webkit-commit-queue merged commit a0577c1 into WebKit:main Oct 9, 2026
@webkit-commit-queue webkit-commit-queue removed unsafe-merge-queue Applied to send a pull request to merge-queue, but skip building and testing safe-merge-queue Applied to automatically send a pull-request to merge-queue after passing EWS checks labels Oct 9, 2026
@annevk
annevk deleted the eng/Do-not-deserialize-RTCCertificate-in-workers branch October 9, 2026 04:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

DOM For bugs specific to XML/HTML DOM elements (including parsing).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants