Truly independent web browser
Find a file
Luke Wilde 454bf0b7cd LibWeb/WebGL: Use robust versions of API calls provided by ANGLE
The primary purpose of these is to add bounds checking to older OpenGL
API calls that take arbitrarily sized buffers, but don't know the size
of the buffer and thus rely on the application being certain the buffer
is large enough.

Since these API calls are exposed to arbitrary JS which can make
arbitrarily sized buffers, it is not safe to use the non-robust
variants, as we cannot know the size of the buffer ahead of time, nor
the amount of data required by the API call.

The robust variants provided by ANGLE adds a buffer size parameter,
where it'll calculate the amount of data it needs for that API call
for us and return an error if it's bigger than the given buffer size.

Credit to https://github.com/s41nt0l3xus for finding this during a CTF
and providing a write up that exploits this.
See: 92efbaed6c/gpnctf-2025/WebGL-bird
2025-06-30 11:54:23 -06:00
.devcontainer Meta: Switch to different source for pre-commit feature in dev-container 2025-06-21 20:18:23 +02:00
.github CI: Make Windows CI label name consistent with the preset name 2025-06-25 10:12:34 -06:00
AK AK: Copy escape char when forking SourceGenerator 2025-06-30 11:39:16 -06:00
Base/res LibWebView+RequestSever: Wire up a validate-DNSSEC setting option to RS 2025-06-11 18:16:29 +02:00
Documentation LibWeb: Map logical aliases at cascade time 2025-06-23 15:19:07 +01:00
Libraries LibIDL: Save parsed stringifier_extended_attributes 2025-06-30 11:39:16 -06:00
Meta LibWeb/WebGL: Use robust versions of API calls provided by ANGLE 2025-06-30 11:54:23 -06:00
Services LibGfx: Use NonnullRefPtr<Bitmap> for frame descriptors 2025-06-25 22:54:48 +12:00
Tests IDLGenerators: Fix Exposed extended attribute codegen 2025-06-30 11:39:16 -06:00
Toolchain Meta: Add SPDX license identifier to ladybird.py and BuildVcpkg.py 2025-05-29 16:24:17 -04:00
UI LibWebView: Defer creating services until after application init 2025-06-11 08:26:29 -04:00
Utilities LibGfx: Use NonnullRefPtr<Bitmap> for frame descriptors 2025-06-25 22:54:48 +12:00
.clang-format Meta: Enforce newlines around namespaces 2025-05-14 02:01:59 -06:00
.clang-tidy Meta: Disable clang-tidy “implicit-bool-conversion” check 2025-01-24 09:25:37 +01:00
.clangd Meta: Change the default build directories to exclude "ladybird" prefix 2024-11-06 10:38:57 -07:00
.editorconfig Meta: Add .editorconfig 2022-09-10 17:32:55 +01:00
.gitattributes LibGfx: Remove support for the various "portable" image formats 2024-06-17 21:57:35 +02:00
.gitignore Meta: Record desired swift toolchain version in .swift-version 2025-06-11 11:54:52 -06:00
.gn Meta: Automatically generate a compilation database for clangd 2023-11-14 14:29:35 -05:00
.mailmap Meta: Update my e-mail address everywhere 2024-10-04 13:19:50 +02:00
.pre-commit-config.yaml Meta: Replace deprecated pre-commit stage name 2024-10-18 09:40:59 +02:00
.prettierignore Meta: Don't lint imported WPT crash tests with prettier 2025-06-22 23:51:34 +02:00
.prettierrc Meta: Move prettier config files to the root of the repository 2020-08-24 18:21:33 +02:00
.swift-format Meta: Add swift-format configuration 2024-07-30 18:38:02 -06:00
.swift-version Meta: Record desired swift toolchain version in .swift-version 2025-06-11 11:54:52 -06:00
.ycm_extra_conf.py Meta: Sort all python imports 2025-06-09 11:25:14 -04:00
CMakeLists.txt CMake: Allow Windows to build Lib/Test GUI targets 2025-06-26 19:35:14 -06:00
CMakePresets.json CMake: Allow Windows to build Lib/Test GUI targets 2025-06-26 19:35:14 -06:00
CODE_OF_CONDUCT.md Meta: Add code of conduct (from the Ruby community) 2024-10-02 09:49:52 +02:00
CONTRIBUTING.md Documentation: Fix Ladybird's documentation url 2025-05-20 15:53:48 -04:00
ISSUES.md Everywhere: Document use of ladybird.py over ladybird.sh 2025-05-29 16:24:17 -04:00
LICENSE Meta: Update license year 2025-02-10 11:40:57 +00:00
pyproject.toml Meta: Use "extend-select" to enable non-default python linters 2025-06-09 17:49:35 -04:00
README.md Libraries: Remove LibArchive 2024-11-25 13:37:45 +01:00
SECURITY.md Documentation: Make updates to align better with new issue template 2024-10-31 09:18:08 +01:00
vcpkg-configuration.json Meta: Add overlay port for vulkan-loader 2024-07-07 15:56:59 +02:00
vcpkg.json Meta: Update ANGLE to chromium/7258 2025-06-30 11:54:23 -06:00

Ladybird

Ladybird is a truly independent web browser, using a novel engine based on web standards.

Important

Ladybird is in a pre-alpha state, and only suitable for use by developers

Features

We aim to build a complete, usable browser for the modern web.

Ladybird uses a multi-process architecture with a main UI process, several WebContent renderer processes, an ImageDecoder process, and a RequestServer process.

Image decoding and network connections are done out of process to be more robust against malicious content. Each tab has its own renderer process, which is sandboxed from the rest of the system.

At the moment, many core library support components are inherited from SerenityOS:

  • LibWeb: Web rendering engine
  • LibJS: JavaScript engine
  • LibWasm: WebAssembly implementation
  • LibCrypto/LibTLS: Cryptography primitives and Transport Layer Security
  • LibHTTP: HTTP/1.1 client
  • LibGfx: 2D Graphics Library, Image Decoding and Rendering
  • LibUnicode: Unicode and locale support
  • LibMedia: Audio and video playback
  • LibCore: Event loop, OS abstraction layer
  • LibIPC: Inter-process communication

How do I build and run this?

See build instructions for information on how to build Ladybird.

Ladybird runs on Linux, macOS, Windows (with WSL2), and many other *Nixes.

How do I read the documentation?

Code-related documentation can be found in the documentation folder.

Get in touch and participate!

Join our Discord server to participate in development discussion.

Please read Getting started contributing if you plan to contribute to Ladybird for the first time.

Before opening an issue, please see the issue policy and the detailed issue-reporting guidelines.

The full contribution guidelines can be found in CONTRIBUTING.md.

License

Ladybird is licensed under a 2-clause BSD license.