Skip to content

Skip flatbuffer verification in some cases - #730

Merged
atuchin-m merged 3 commits into
masterfrom
optionally-skip-flatbuffer-verification-2
Sep 29, 2026
Merged

atuchin-m merged 3 commits into
masterfrom
optionally-skip-flatbuffer-verification-2

Conversation

@atuchin-m

@atuchin-m atuchin-m commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Replaces #728

The idea is to provide ability to skip flatbuffer verification for the browser startup when we load/create a DAT file with the same version the engine version + DAT seahash matches.
It technically allows to create a memory corruption for attacker with a write access, but it's out of the Chromium threat model:

We consider these attacks outside Chrome's threat model, because there is no way for Chrome (or any application) to defend against a malicious user who has managed to log into your device as you, or who can run software with the privileges of your operating system user account.

link

@atuchin-m atuchin-m self-assigned this Sep 24, 2026

@github-actions github-actions Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rust Benchmark

Details
Benchmark suite Current: eb8bb64 Previous: 1c0740d Ratio
rule-match-browserlike/brave-list 1913704476 ns/iter (± 7176275) 1924967612 ns/iter (± 7805929) 0.99
rule-match-first-request/brave-list 1366356 ns/iter (± 17578) 1345618 ns/iter (± 43788) 1.02
blocker_new/brave-list 111387021 ns/iter (± 251095) 111587961 ns/iter (± 336549) 1.00
blocker_new/brave-list-deserialize 1987937 ns/iter (± 7625) 31531323 ns/iter (± 2045870) 0.06304641895298843
memory-usage-final/brave-list-initial 9671732 B/iter (± 0) 9671732 B/iter (± 0) 1
memory-usage-final/brave-list-1000-requests 3215263 B/iter (± 0) 3215263 B/iter (± 0) 1
memory-usage-max/brave-list-initial/max 32237425 B/iter (± 0) 32237425 B/iter (± 0) 1
memory-usage-alloc-count/brave-list-initial/alloc-count 287123 allocs/iter (± 0) 287123 allocs/iter (± 0) 1
memory-usage-alloc-count/brave-list-1000-requests/alloc-count 81427 allocs/iter (± 0) 81427 allocs/iter (± 0) 1
url_cosmetic_resources/brave-list 185646 ns/iter (± 2284) 187013 ns/iter (± 766) 0.99
cosmetic-class-id-match/brave-list 3263172 ns/iter (± 892942) 3336389 ns/iter (± 836749) 0.98

This comment was automatically generated by workflow using github-action-benchmark.

@atuchin-m
atuchin-m marked this pull request as ready for review September 25, 2026 19:52
Comment thread tests/unit/engine.rs
Comment on lines 264 to 268
let expected_hash: u64 = if cfg!(feature = "css-validation") {
4595639195770030762
17765782844446154098
} else {
12609292311627976202
7585209289575817889
};

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

it would be good to have a way to override the crate versions used in these expected_hash tests. As it stands they will now need to be updated for every new version bump.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've updated these tests to verify hash without the header.
Now we don't need to update the values when we do a bump.

Comment thread src/engine.rs Outdated
@atuchin-m
atuchin-m enabled auto-merge (squash) September 29, 2026 17:17
@atuchin-m
atuchin-m merged commit 6028a6d into master Sep 29, 2026
11 checks passed
@atuchin-m
atuchin-m deleted the optionally-skip-flatbuffer-verification-2 branch September 29, 2026 17:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants