1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
use *;
/// Cached table of JS batched DOM-op helpers.
///
/// Resolved lazily on first patch via [`ensure_dom_op_table`]. The
/// functions accept parallel arrays / op-tuples so a single JS-side
/// loop replaces N individual `setAttribute` / `removeAttribute` /
/// `insertBefore` / `appendChild` / `removeChild` crossings.
pub
thread_local!
/// The per-load set of names the batched DOM-op helpers are published under.
///
/// Every name is `__euv_<role>_<encoded suffix>`: the prefix makes the
/// injection identifiable, the role says which helper it is, and the suffix
/// is what makes the full name unguessable. The suffix is derived once per
/// page load from a microsecond clock and encoded through
/// `bin-encode-decode`, so an attacker who ships a payload knowing only the
/// crate version cannot pre-compute the name it needs to overwrite.
///
/// The three helper names and the table name share one suffix rather than
/// drawing independent ones, so the whole set is still a single random draw
/// and the four names stay visibly related when inspecting `globalThis`.
///
/// Constructed once and cached in [`DOM_OP_NAMES`]; read through
/// [`DomOpNames::get`].
pub