- Package:
- libqt4-script
- Source:
- qt4-x11
- Submitter:
- Russell Coker
- Date:
- 2024-08-05 03:33:16 UTC
- Severity:
- normal
- Tags:
When kwin is run without execmem access it will SEGV. This makes things difficult for people who want to restrict such access to make it more difficult for their programs to be exploited. #0 0x00007ffff65615f4 in QTJSC::ExecutablePool::systemAlloc (n=16384) at ../3rdparty/javascriptcore/JavaScriptCore/jit/ExecutableAllocatorPosix.cpp:49 #1 0x00007ffff65e9393 in ExecutablePool (this=<optimized out>, n=<optimized out>) at ../3rdparty/javascriptcore/JavaScriptCore/jit/ExecutableAllocator.h:258 #2 create (n=<optimized out>) at ../3rdparty/javascriptcore/JavaScriptCore/jit/ExecutableAllocator.h:97 #3 ExecutableAllocator (this=0x7fffdddf29c8) at ../3rdparty/javascriptcore/JavaScriptCore/jit/ExecutableAllocator.h:150 #4 QTJSC::JSGlobalData::JSGlobalData (this=0x7fffdddf1800, isShared=<optimized out>) at ../3rdparty/javascriptcore/JavaScriptCore/runtime/JSGlobalData.cpp:146 #5 0x00007ffff65e9b1c in QTJSC::JSGlobalData::create () at ../3rdparty/javascriptcore/JavaScriptCore/runtime/JSGlobalData.cpp:205 #6 0x00007ffff6686821 in QScriptEnginePrivate::QScriptEnginePrivate (this=0x9309d0) at api/qscriptengine.cpp:973 #7 0x00007ffff6687786 in QScriptEngine::QScriptEngine (this=0x7fffffffe5c0) at api/qscriptengine.cpp:1958 #8 0x00007ffff7b9566d in ?? () from /usr/lib/kde4/libkdeinit/libkdeinit4_kwin.so #9 0x00007ffff7b054e5 in kdemain () from /usr/lib/kde4/libkdeinit/libkdeinit4_kwin.so #10 0x00007ffff7743ead in __libc_start_main () from /lib/x86_64-linux-gnu/libc.so.6 #11 0x00000000004006b1 in _start () Above is a backtrace of a kwin SEGV which shows where the problem is. Is JavaScript really required for KDE operation? If not can it be an option to disable it? If it is required can kwin be made to fallback to interpreting the code if it can't precompile it?
forwarded 647470 https://bugreports.qt-project.org/browse/QTBUG-32460 thanks There are actually 2 embedded copies of JavascriptCore in Qt, and one of them allows disabling the JIT via an env var. Unfortunately not the one used by KWin and libqt4-script. I've filed a bug upstream about this: https://bugreports.qt-project.org/browse/QTBUG-32460 It should be a matter of backporting the env var from one javascriptcore to the other (or better yet get rid of the double-embedded code).
Upstream has replied in [0]: This is rather low priority for us right now, but I'd be happy to review a patch to fix it. [0] <https://bugreports.qt-project.org/browse/QTBUG-32460?focusedCommentId=210848&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#comment-210848> I definetely don't have the time to make a patch for this, so... patches welcomed :) Preferably directly upstream, as we will ask upstream in the end if they ACK it.
Upstream has replied in [0]: This is rather low priority for us right now, but I'd be happy to review a patch to fix it. [0] <https://bugreports.qt-project.org/browse/QTBUG-32460?focusedCommentId=210848&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#comment-210848> I definetely don't have the time to make a patch for this, so... patches welcomed :) Preferably directly upstream, as we will ask upstream in the end if they ACK it.
-- Greeting, I have access to very vital information that can be used to move huge amounts of money. If it was possible for me to do it alone I would not have bothered contacting you. Ultimately I need you to play an important role in the completion of this business transaction. Regards, Mr Alexander Bulyanda