Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(22)

Unified Diff: Source/core/html/canvas/WebGL2RenderingContextBase.cpp

Issue 1205573003: WebGL 2: validate read buffer attachment when reading from FBO (Closed) Base URL: https://chromium.googlesource.com/chromium/blink.git@master
Patch Set: Created 5 years, 6 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: Source/core/html/canvas/WebGL2RenderingContextBase.cpp
diff --git a/Source/core/html/canvas/WebGL2RenderingContextBase.cpp b/Source/core/html/canvas/WebGL2RenderingContextBase.cpp
index 73963ac03302f8ecfec4700282f78e7884e43238..a7d1fbd74a057aaf4c78be61d89ed3d5d3a13332 100644
--- a/Source/core/html/canvas/WebGL2RenderingContextBase.cpp
+++ b/Source/core/html/canvas/WebGL2RenderingContextBase.cpp
@@ -168,6 +168,33 @@ void WebGL2RenderingContextBase::readBuffer(GLenum mode)
if (isContextLost())
return;
+ switch (mode) {
+ case GL_BACK:
+ case GL_NONE:
+ case GL_COLOR_ATTACHMENT0:
+ break;
+ default:
+ if (attachment > GL_COLOR_ATTACHMENT0
+ && attachment < static_cast<GLenum>(GL_COLOR_ATTACHMENT0 + maxColorAttachments()))
+ break;
+ synthesizeGLError(GL_INVALID_ENUM, "readBuffer", "invalid read buffer");
+ return;
+ }
+
+ WebGLFramebuffer* readFramebufferBinding = getFramebufferBinding(GL_READ_FRAMEBUFFER);
+ if (!readFramebufferBinding) {
+ ASSERT(drawingBuffer());
+ if (mode != GL_BACK || mode != GL_NONE) {
+ synthesizeGLError(GL_INVALID_OPERATION, "readBuffer", "invalid read buffer");
+ return;
+ }
+ } else {
+ if (mode == GL_BACK) {
+ synthesizeGLError(GL_INVALID_OPERATION, "readBuffer", "invalid read buffer");
+ return;
+ }
+ m_readbufferOfFBO = mode;
+ }
webContext()->readBuffer(mode);
}

Powered by Google App Engine
This is Rietveld 408576698