The Mysterious Realm of JavaScriptCore (2021)
Posted by program 5 days ago
Comments
Comment by pizlonator 6 hours ago
A lot more details here: https://webkit.org/blog/10308/speculation-in-javascriptcore/
Comment by epolanski 5 days ago
I've often thought about the possibility of implementing a language that can compile directly to optimized byte code (either for V8 or JSC), in order to get "hot code" that does not need runtime optimization, has anybody explored this idea?
Comment by astrange 1 hour ago
That's WebAssembly / asm.js. Well, that's the target, you could still design a language for it.
Comment by pizlonator 6 hours ago
That won't work for JS because you need runtime profiling to be able to do any meaningful optimizations
Comment by N_Lens 7 hours ago
Author used CodeQL to rediscover a CVE in JSC that was exploited by Pwn2Own in 2018. Very interesting. I guess now with increasing automation we'll see more CVE discovery through such tools.
Comment by gsf_emergency_6 7 hours ago
Author's talk from around that time (Apr 2021)
[Finding] JS bugs in JSC with CodeQL