File: JDK-8098578.js

package info (click to toggle)
openjdk-11 11.0.4%2B11-1
  • links: PTS, VCS
  • area: main
  • in suites: sid
  • size: 757,028 kB
  • sloc: java: 5,016,041; xml: 1,191,974; cpp: 934,731; ansic: 555,697; sh: 24,299; objc: 12,703; python: 3,602; asm: 3,415; makefile: 2,772; awk: 351; sed: 172; perl: 114; jsp: 24; csh: 3
file content (107 lines) | stat: -rw-r--r-- 3,449 bytes parent folder | download | duplicates (7)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
/*
 * Copyright (c) 2015, Oracle and/or its affiliates. All rights reserved.
 * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
 *
 * This code is free software; you can redistribute it and/or modify it
 * under the terms of the GNU General Public License version 2 only, as
 * published by the Free Software Foundation.
 *
 * This code is distributed in the hope that it will be useful, but WITHOUT
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
 * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
 * version 2 for more details (a copy is included in the LICENSE file that
 * accompanied this code).
 *
 * You should have received a copy of the GNU General Public License version
 * 2 along with this work; if not, write to the Free Software Foundation,
 * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
 *
 * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
 * or visit www.oracle.com if you need additional information or have any
 * questions.
 */

/**
 * JDK-8098578: Global scope is not accessible with indirect load call
 *
 * @test
 * @run
 */

var obj = { foo: 343 };
var global = this;
var x = 434;

// indirect load call
var res = load.call(obj, {
   name: "t.js",
   // global is accessible. All declarations go into
   // intermediate inaccessible scope. "this" is global
   // User's passed object's properties are accessible
   // as variables.
   script: "foo -= 300; var bar = x; Assert.assertTrue(bar == 434); function func() {}; this"
})

// 'this' for the evaluated code is global
Assert.assertTrue(res === global);

// properties of passed object are accessible in evaluated code
Assert.assertTrue(obj.foo == 43);

// vars, functions definined in evaluated code don't go into passed object
Assert.assertTrue(typeof obj.bar == "undefined");
Assert.assertTrue(typeof obj.func == "undefined");

// vars, functions definined in evaluated code don't go leak into global
Assert.assertTrue(typeof bar == "undefined");
Assert.assertTrue(typeof func == "undefined");
Assert.assertTrue(typeof foo == "undefined");

var res = load.call(undefined, {
    name: "t1.js",
    // still global is accessible and 'this' is global
    script: "Assert.assertTrue(x == 434); this"
});

// indirect load with 'undefined' this is same as as direct load
// or load on global itself.
Assert.assertTrue(res === global);

// indirect load with 'undefined' this is same as as direct load
// or load on global itself.
var res = load.call(null, {
    name: "t2.js",
    // still global is accessible and 'this' is global
    script: "Assert.assertTrue(x == 434); this"
});
Assert.assertTrue(res === global);

// indirect load with mirror object
var mirror = loadWithNewGlobal({
    name: "t3.js",
    script: "({ foo: 'hello', x: Math.PI })"
});

var res = load.call(mirror, {
    name: "t4.js",
    script: "Assert.assertTrue(foo == 'hello'); Assert.assertTrue(x == Math.PI); this"
});
Assert.assertTrue(res === global);

// indirect load on non-script object, non-mirror results in TypeError
function tryLoad(obj) {
    try {
        load.call(obj, {
            name: "t5.js", script: "this"
        });
        throw new Error("should thrown TypeError for: " + obj);
    } catch (e if TypeError) {}
}

tryLoad("hello");
tryLoad(Math.E);
tryLoad(true);
tryLoad(false);

// indirect load of a large script
load.call({}, __DIR__ + "JDK-8098807-payload.js");