WebAssemblyObject.cpp 21 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475
  1. /*
  2. * Copyright (c) 2021, Ali Mohammad Pur <mpfard@serenityos.org>
  3. *
  4. * SPDX-License-Identifier: BSD-2-Clause
  5. */
  6. #include "WebAssemblyInstanceObject.h"
  7. #include "WebAssemblyMemoryPrototype.h"
  8. #include "WebAssemblyModuleConstructor.h"
  9. #include "WebAssemblyModuleObject.h"
  10. #include "WebAssemblyModulePrototype.h"
  11. #include "WebAssemblyTableObject.h"
  12. #include "WebAssemblyTablePrototype.h"
  13. #include <AK/MemoryStream.h>
  14. #include <AK/ScopeGuard.h>
  15. #include <LibJS/Runtime/Array.h>
  16. #include <LibJS/Runtime/ArrayBuffer.h>
  17. #include <LibJS/Runtime/BigInt.h>
  18. #include <LibJS/Runtime/DataView.h>
  19. #include <LibJS/Runtime/TypedArray.h>
  20. #include <LibWasm/AbstractMachine/Interpreter.h>
  21. #include <LibWasm/AbstractMachine/Validator.h>
  22. #include <LibWeb/Bindings/Intrinsics.h>
  23. #include <LibWeb/WebAssembly/WebAssemblyInstanceConstructor.h>
  24. #include <LibWeb/WebAssembly/WebAssemblyObject.h>
  25. namespace Web::Bindings {
  26. WebAssemblyObject::WebAssemblyObject(JS::Realm& realm)
  27. : Object(ConstructWithPrototypeTag::Tag, *realm.intrinsics().object_prototype())
  28. {
  29. s_abstract_machine.enable_instruction_count_limit();
  30. }
  31. JS::ThrowCompletionOr<void> WebAssemblyObject::initialize(JS::Realm& realm)
  32. {
  33. MUST_OR_THROW_OOM(Object::initialize(realm));
  34. u8 attr = JS::Attribute::Configurable | JS::Attribute::Writable | JS::Attribute::Enumerable;
  35. define_native_function(realm, "validate", validate, 1, attr);
  36. define_native_function(realm, "compile", compile, 1, attr);
  37. define_native_function(realm, "instantiate", instantiate, 1, attr);
  38. auto& memory_constructor = Bindings::ensure_web_constructor<WebAssemblyMemoryPrototype>(realm, "WebAssembly.Memory"sv);
  39. define_direct_property("Memory", &memory_constructor, JS::Attribute::Writable | JS::Attribute::Configurable);
  40. auto& instance_constructor = Bindings::ensure_web_constructor<WebAssemblyInstancePrototype>(realm, "WebAssembly.Instance"sv);
  41. define_direct_property("Instance", &instance_constructor, JS::Attribute::Writable | JS::Attribute::Configurable);
  42. auto& module_constructor = Bindings::ensure_web_constructor<WebAssemblyModulePrototype>(realm, "WebAssembly.Module"sv);
  43. define_direct_property("Module", &module_constructor, JS::Attribute::Writable | JS::Attribute::Configurable);
  44. auto& table_constructor = Bindings::ensure_web_constructor<WebAssemblyTablePrototype>(realm, "WebAssembly.Table"sv);
  45. define_direct_property("Table", &table_constructor, JS::Attribute::Writable | JS::Attribute::Configurable);
  46. return {};
  47. }
  48. NonnullOwnPtrVector<WebAssemblyObject::CompiledWebAssemblyModule> WebAssemblyObject::s_compiled_modules;
  49. NonnullOwnPtrVector<Wasm::ModuleInstance> WebAssemblyObject::s_instantiated_modules;
  50. Vector<WebAssemblyObject::ModuleCache> WebAssemblyObject::s_module_caches;
  51. WebAssemblyObject::GlobalModuleCache WebAssemblyObject::s_global_cache;
  52. Wasm::AbstractMachine WebAssemblyObject::s_abstract_machine;
  53. void WebAssemblyObject::visit_edges(Visitor& visitor)
  54. {
  55. Base::visit_edges(visitor);
  56. for (auto& entry : s_global_cache.function_instances)
  57. visitor.visit(entry.value);
  58. for (auto& module_cache : s_module_caches) {
  59. for (auto& entry : module_cache.function_instances)
  60. visitor.visit(entry.value);
  61. for (auto& entry : module_cache.memory_instances)
  62. visitor.visit(entry.value);
  63. for (auto& entry : module_cache.table_instances)
  64. visitor.visit(entry.value);
  65. }
  66. }
  67. JS_DEFINE_NATIVE_FUNCTION(WebAssemblyObject::validate)
  68. {
  69. // 1. Let stableBytes be a copy of the bytes held by the buffer bytes.
  70. // Note: There's no need to copy the bytes here as the buffer data cannot change while we're compiling the module.
  71. auto buffer = TRY(vm.argument(0).to_object(vm));
  72. // 2. Compile stableBytes as a WebAssembly module and store the results as module.
  73. auto maybe_module = parse_module(vm, buffer);
  74. // 3. If module is error, return false.
  75. if (maybe_module.is_error())
  76. return JS::Value(false);
  77. // Drop the module from the cache, we're never going to refer to it.
  78. ScopeGuard drop_from_cache {
  79. [&] {
  80. (void)s_compiled_modules.take_last();
  81. }
  82. };
  83. // 3 continued - our "compile" step is lazy with validation, explicitly do the validation.
  84. if (s_abstract_machine.validate(s_compiled_modules[maybe_module.value()].module).is_error())
  85. return JS::Value(false);
  86. // 4. Return true.
  87. return JS::Value(true);
  88. }
  89. JS::ThrowCompletionOr<size_t> parse_module(JS::VM& vm, JS::Object* buffer_object)
  90. {
  91. ReadonlyBytes data;
  92. if (is<JS::ArrayBuffer>(buffer_object)) {
  93. auto& buffer = static_cast<JS::ArrayBuffer&>(*buffer_object);
  94. data = buffer.buffer();
  95. } else if (is<JS::TypedArrayBase>(buffer_object)) {
  96. auto& buffer = static_cast<JS::TypedArrayBase&>(*buffer_object);
  97. data = buffer.viewed_array_buffer()->buffer().span().slice(buffer.byte_offset(), buffer.byte_length());
  98. } else if (is<JS::DataView>(buffer_object)) {
  99. auto& buffer = static_cast<JS::DataView&>(*buffer_object);
  100. data = buffer.viewed_array_buffer()->buffer().span().slice(buffer.byte_offset(), buffer.byte_length());
  101. } else {
  102. return vm.throw_completion<JS::TypeError>("Not a BufferSource");
  103. }
  104. FixedMemoryStream stream { data };
  105. auto module_result = Wasm::Module::parse(stream);
  106. if (module_result.is_error()) {
  107. // FIXME: Throw CompileError instead.
  108. return vm.throw_completion<JS::TypeError>(Wasm::parse_error_to_deprecated_string(module_result.error()));
  109. }
  110. if (auto validation_result = WebAssemblyObject::s_abstract_machine.validate(module_result.value()); validation_result.is_error()) {
  111. // FIXME: Throw CompileError instead.
  112. return vm.throw_completion<JS::TypeError>(validation_result.error().error_string);
  113. }
  114. WebAssemblyObject::s_compiled_modules.append(make<WebAssemblyObject::CompiledWebAssemblyModule>(module_result.release_value()));
  115. return WebAssemblyObject::s_compiled_modules.size() - 1;
  116. }
  117. JS_DEFINE_NATIVE_FUNCTION(WebAssemblyObject::compile)
  118. {
  119. auto& realm = *vm.current_realm();
  120. // FIXME: This shouldn't block!
  121. auto buffer_or_error = vm.argument(0).to_object(vm);
  122. JS::Value rejection_value;
  123. if (buffer_or_error.is_error())
  124. rejection_value = *buffer_or_error.throw_completion().value();
  125. auto promise = JS::Promise::create(realm);
  126. if (!rejection_value.is_empty()) {
  127. promise->reject(rejection_value);
  128. return promise;
  129. }
  130. auto* buffer = buffer_or_error.release_value();
  131. auto result = parse_module(vm, buffer);
  132. if (result.is_error())
  133. promise->reject(*result.release_error().value());
  134. else
  135. promise->fulfill(MUST_OR_THROW_OOM(vm.heap().allocate<WebAssemblyModuleObject>(realm, realm, result.release_value())));
  136. return promise;
  137. }
  138. JS::ThrowCompletionOr<size_t> WebAssemblyObject::instantiate_module(JS::VM& vm, Wasm::Module const& module)
  139. {
  140. Wasm::Linker linker { module };
  141. HashMap<Wasm::Linker::Name, Wasm::ExternValue> resolved_imports;
  142. auto import_argument = vm.argument(1);
  143. if (!import_argument.is_undefined()) {
  144. auto* import_object = TRY(import_argument.to_object(vm));
  145. dbgln("Trying to resolve stuff because import object was specified");
  146. for (Wasm::Linker::Name const& import_name : linker.unresolved_imports()) {
  147. dbgln("Trying to resolve {}::{}", import_name.module, import_name.name);
  148. auto value_or_error = import_object->get(import_name.module);
  149. if (value_or_error.is_error())
  150. break;
  151. auto value = value_or_error.release_value();
  152. auto object_or_error = value.to_object(vm);
  153. if (object_or_error.is_error())
  154. break;
  155. auto* object = object_or_error.release_value();
  156. auto import_or_error = object->get(import_name.name);
  157. if (import_or_error.is_error())
  158. break;
  159. auto import_ = import_or_error.release_value();
  160. TRY(import_name.type.visit(
  161. [&](Wasm::TypeIndex index) -> JS::ThrowCompletionOr<void> {
  162. dbgln("Trying to resolve a function {}::{}, type index {}", import_name.module, import_name.name, index.value());
  163. auto& type = module.type(index);
  164. // FIXME: IsCallable()
  165. if (!import_.is_function())
  166. return {};
  167. auto& function = import_.as_function();
  168. // FIXME: If this is a function created by create_native_function(),
  169. // just extract its address and resolve to that.
  170. Wasm::HostFunction host_function {
  171. [&](auto&, auto& arguments) -> Wasm::Result {
  172. JS::MarkedVector<JS::Value> argument_values { vm.heap() };
  173. for (auto& entry : arguments)
  174. argument_values.append(to_js_value(vm, entry));
  175. auto result_or_error = JS::call(vm, function, JS::js_undefined(), move(argument_values));
  176. if (result_or_error.is_error()) {
  177. return Wasm::Trap();
  178. }
  179. if (type.results().is_empty())
  180. return Wasm::Result { Vector<Wasm::Value> {} };
  181. if (type.results().size() == 1) {
  182. auto value_or_error = to_webassembly_value(vm, result_or_error.release_value(), type.results().first());
  183. if (value_or_error.is_error())
  184. return Wasm::Trap {};
  185. return Wasm::Result { Vector<Wasm::Value> { value_or_error.release_value() } };
  186. }
  187. // FIXME: Multiple returns
  188. TODO();
  189. },
  190. type
  191. };
  192. auto address = s_abstract_machine.store().allocate(move(host_function));
  193. dbgln("Resolved to {}", address->value());
  194. // FIXME: LinkError instead.
  195. VERIFY(address.has_value());
  196. resolved_imports.set(import_name, Wasm::ExternValue { Wasm::FunctionAddress { *address } });
  197. return {};
  198. },
  199. [&](Wasm::GlobalType const& type) -> JS::ThrowCompletionOr<void> {
  200. Optional<Wasm::GlobalAddress> address;
  201. // https://webassembly.github.io/spec/js-api/#read-the-imports step 5.1
  202. if (import_.is_number() || import_.is_bigint()) {
  203. if (import_.is_number() && type.type().kind() == Wasm::ValueType::I64) {
  204. // FIXME: Throw a LinkError instead.
  205. return vm.throw_completion<JS::TypeError>("LinkError: Import resolution attempted to cast a Number to a BigInteger");
  206. }
  207. if (import_.is_bigint() && type.type().kind() != Wasm::ValueType::I64) {
  208. // FIXME: Throw a LinkError instead.
  209. return vm.throw_completion<JS::TypeError>("LinkError: Import resolution attempted to cast a BigInteger to a Number");
  210. }
  211. auto cast_value = TRY(to_webassembly_value(vm, import_, type.type()));
  212. address = s_abstract_machine.store().allocate({ type.type(), false }, cast_value);
  213. } else {
  214. // FIXME: https://webassembly.github.io/spec/js-api/#read-the-imports step 5.2
  215. // if v implements Global
  216. // let globaladdr be v.[[Global]]
  217. // FIXME: Throw a LinkError instead
  218. return vm.throw_completion<JS::TypeError>("LinkError: Invalid value for global type");
  219. }
  220. resolved_imports.set(import_name, Wasm::ExternValue { *address });
  221. return {};
  222. },
  223. [&](Wasm::MemoryType const&) -> JS::ThrowCompletionOr<void> {
  224. if (!import_.is_object() || !is<WebAssemblyMemoryObject>(import_.as_object())) {
  225. // FIXME: Throw a LinkError instead
  226. return vm.throw_completion<JS::TypeError>("LinkError: Expected an instance of WebAssembly.Memory for a memory import");
  227. }
  228. auto address = static_cast<WebAssemblyMemoryObject const&>(import_.as_object()).address();
  229. resolved_imports.set(import_name, Wasm::ExternValue { address });
  230. return {};
  231. },
  232. [&](Wasm::TableType const&) -> JS::ThrowCompletionOr<void> {
  233. if (!import_.is_object() || !is<WebAssemblyTableObject>(import_.as_object())) {
  234. // FIXME: Throw a LinkError instead
  235. return vm.throw_completion<JS::TypeError>("LinkError: Expected an instance of WebAssembly.Table for a table import");
  236. }
  237. auto address = static_cast<WebAssemblyTableObject const&>(import_.as_object()).address();
  238. resolved_imports.set(import_name, Wasm::ExternValue { address });
  239. return {};
  240. },
  241. [&](auto const&) -> JS::ThrowCompletionOr<void> {
  242. // FIXME: Implement these.
  243. dbgln("Unimplemented import of non-function attempted");
  244. return vm.throw_completion<JS::TypeError>("LinkError: Not Implemented");
  245. }));
  246. }
  247. }
  248. linker.link(resolved_imports);
  249. auto link_result = linker.finish();
  250. if (link_result.is_error()) {
  251. // FIXME: Throw a LinkError.
  252. StringBuilder builder;
  253. builder.append("LinkError: Missing "sv);
  254. builder.join(' ', link_result.error().missing_imports);
  255. return vm.throw_completion<JS::TypeError>(builder.to_deprecated_string());
  256. }
  257. auto instance_result = s_abstract_machine.instantiate(module, link_result.release_value());
  258. if (instance_result.is_error()) {
  259. // FIXME: Throw a LinkError instead.
  260. return vm.throw_completion<JS::TypeError>(instance_result.error().error);
  261. }
  262. s_instantiated_modules.append(instance_result.release_value());
  263. s_module_caches.empend();
  264. return s_instantiated_modules.size() - 1;
  265. }
  266. JS_DEFINE_NATIVE_FUNCTION(WebAssemblyObject::instantiate)
  267. {
  268. auto& realm = *vm.current_realm();
  269. // FIXME: This shouldn't block!
  270. auto buffer_or_error = vm.argument(0).to_object(vm);
  271. auto promise = JS::Promise::create(realm);
  272. bool should_return_module = false;
  273. if (buffer_or_error.is_error()) {
  274. auto rejection_value = *buffer_or_error.throw_completion().value();
  275. promise->reject(rejection_value);
  276. return promise;
  277. }
  278. auto* buffer = buffer_or_error.release_value();
  279. Wasm::Module const* module { nullptr };
  280. if (is<JS::ArrayBuffer>(buffer) || is<JS::TypedArrayBase>(buffer)) {
  281. auto result = parse_module(vm, buffer);
  282. if (result.is_error()) {
  283. promise->reject(*result.release_error().value());
  284. return promise;
  285. }
  286. module = &WebAssemblyObject::s_compiled_modules.at(result.release_value()).module;
  287. should_return_module = true;
  288. } else if (is<WebAssemblyModuleObject>(buffer)) {
  289. module = &static_cast<WebAssemblyModuleObject*>(buffer)->module();
  290. } else {
  291. auto error = JS::TypeError::create(realm, DeprecatedString::formatted("{} is not an ArrayBuffer or a Module", buffer->class_name()));
  292. promise->reject(error);
  293. return promise;
  294. }
  295. VERIFY(module);
  296. auto result = instantiate_module(vm, *module);
  297. if (result.is_error()) {
  298. promise->reject(*result.release_error().value());
  299. } else {
  300. auto instance_object = MUST_OR_THROW_OOM(vm.heap().allocate<WebAssemblyInstanceObject>(realm, realm, result.release_value()));
  301. if (should_return_module) {
  302. auto object = JS::Object::create(realm, nullptr);
  303. object->define_direct_property("module", MUST_OR_THROW_OOM(vm.heap().allocate<WebAssemblyModuleObject>(realm, realm, s_compiled_modules.size() - 1)), JS::default_attributes);
  304. object->define_direct_property("instance", instance_object, JS::default_attributes);
  305. promise->fulfill(object);
  306. } else {
  307. promise->fulfill(instance_object);
  308. }
  309. }
  310. return promise;
  311. }
  312. JS::Value to_js_value(JS::VM& vm, Wasm::Value& wasm_value)
  313. {
  314. auto& realm = *vm.current_realm();
  315. switch (wasm_value.type().kind()) {
  316. case Wasm::ValueType::I64:
  317. return realm.heap().allocate<JS::BigInt>(realm, ::Crypto::SignedBigInteger { wasm_value.to<i64>().value() }).release_allocated_value_but_fixme_should_propagate_errors();
  318. case Wasm::ValueType::I32:
  319. return JS::Value(wasm_value.to<i32>().value());
  320. case Wasm::ValueType::F64:
  321. return JS::Value(wasm_value.to<double>().value());
  322. case Wasm::ValueType::F32:
  323. return JS::Value(static_cast<double>(wasm_value.to<float>().value()));
  324. case Wasm::ValueType::FunctionReference:
  325. // FIXME: What's the name of a function reference that isn't exported?
  326. return create_native_function(vm, wasm_value.to<Wasm::Reference::Func>().value().address, "FIXME_IHaveNoIdeaWhatThisShouldBeCalled");
  327. case Wasm::ValueType::NullFunctionReference:
  328. return JS::js_null();
  329. case Wasm::ValueType::ExternReference:
  330. case Wasm::ValueType::NullExternReference:
  331. TODO();
  332. }
  333. VERIFY_NOT_REACHED();
  334. }
  335. JS::ThrowCompletionOr<Wasm::Value> to_webassembly_value(JS::VM& vm, JS::Value value, Wasm::ValueType const& type)
  336. {
  337. static ::Crypto::SignedBigInteger two_64 = "1"_sbigint.shift_left(64);
  338. switch (type.kind()) {
  339. case Wasm::ValueType::I64: {
  340. auto bigint = TRY(value.to_bigint(vm));
  341. auto value = bigint->big_integer().divided_by(two_64).remainder;
  342. VERIFY(value.unsigned_value().trimmed_length() <= 2);
  343. i64 integer = static_cast<i64>(value.unsigned_value().to_u64());
  344. if (value.is_negative())
  345. integer = -integer;
  346. return Wasm::Value { integer };
  347. }
  348. case Wasm::ValueType::I32: {
  349. auto _i32 = TRY(value.to_i32(vm));
  350. return Wasm::Value { static_cast<i32>(_i32) };
  351. }
  352. case Wasm::ValueType::F64: {
  353. auto number = TRY(value.to_double(vm));
  354. return Wasm::Value { static_cast<double>(number) };
  355. }
  356. case Wasm::ValueType::F32: {
  357. auto number = TRY(value.to_double(vm));
  358. return Wasm::Value { static_cast<float>(number) };
  359. }
  360. case Wasm::ValueType::FunctionReference:
  361. case Wasm::ValueType::NullFunctionReference: {
  362. if (value.is_null())
  363. return Wasm::Value { Wasm::ValueType(Wasm::ValueType::NullExternReference), 0ull };
  364. if (value.is_function()) {
  365. auto& function = value.as_function();
  366. for (auto& entry : WebAssemblyObject::s_global_cache.function_instances) {
  367. if (entry.value == &function)
  368. return Wasm::Value { Wasm::Reference { Wasm::Reference::Func { entry.key } } };
  369. }
  370. }
  371. return vm.throw_completion<JS::TypeError>(JS::ErrorType::NotAnObjectOfType, "Exported function");
  372. }
  373. case Wasm::ValueType::ExternReference:
  374. case Wasm::ValueType::NullExternReference:
  375. TODO();
  376. }
  377. VERIFY_NOT_REACHED();
  378. }
  379. JS::NativeFunction* create_native_function(JS::VM& vm, Wasm::FunctionAddress address, DeprecatedString const& name)
  380. {
  381. auto& realm = *vm.current_realm();
  382. Optional<Wasm::FunctionType> type;
  383. WebAssemblyObject::s_abstract_machine.store().get(address)->visit([&](auto const& value) { type = value.type(); });
  384. if (auto entry = WebAssemblyObject::s_global_cache.function_instances.get(address); entry.has_value())
  385. return *entry;
  386. auto function = JS::NativeFunction::create(
  387. realm,
  388. name,
  389. [address, type = type.release_value()](JS::VM& vm) -> JS::ThrowCompletionOr<JS::Value> {
  390. auto& realm = *vm.current_realm();
  391. Vector<Wasm::Value> values;
  392. values.ensure_capacity(type.parameters().size());
  393. // Grab as many values as needed and convert them.
  394. size_t index = 0;
  395. for (auto& type : type.parameters())
  396. values.append(TRY(to_webassembly_value(vm, vm.argument(index++), type)));
  397. auto result = WebAssemblyObject::s_abstract_machine.invoke(address, move(values));
  398. // FIXME: Use the convoluted mapping of errors defined in the spec.
  399. if (result.is_trap())
  400. return vm.throw_completion<JS::TypeError>(DeprecatedString::formatted("Wasm execution trapped (WIP): {}", result.trap().reason));
  401. if (result.values().is_empty())
  402. return JS::js_undefined();
  403. if (result.values().size() == 1)
  404. return to_js_value(vm, result.values().first());
  405. Vector<JS::Value> result_values;
  406. for (auto& entry : result.values())
  407. result_values.append(to_js_value(vm, entry));
  408. return JS::Value(JS::Array::create_from(realm, result_values));
  409. });
  410. WebAssemblyObject::s_global_cache.function_instances.set(address, function);
  411. return function;
  412. }
  413. WebAssemblyMemoryObject::WebAssemblyMemoryObject(JS::Realm& realm, Wasm::MemoryAddress address)
  414. : Object(ConstructWithPrototypeTag::Tag, Bindings::ensure_web_prototype<WebAssemblyMemoryPrototype>(realm, "WebAssembly.Memory"))
  415. , m_address(address)
  416. {
  417. }
  418. }