Changeset 282212 in webkit
- Timestamp:
- Sep 9, 2021, 8:30:01 AM (5 years ago)
- Location:
- trunk
- Files:
-
- 1 added
- 3 edited
-
JSTests/ChangeLog (modified) (1 diff)
-
JSTests/stress/Uint8ClampedArrayClampsInt52Positive.js (added)
-
Source/JavaScriptCore/ChangeLog (modified) (1 diff)
-
Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp (modified) (5 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/JSTests/ChangeLog
r282200 r282212 1 2021-09-09 Justin Michaud <justin_michaud@apple.com> 2 3 Differential testing: incorrect constant propagation around Uint8ClampedArray 4 https://bugs.webkit.org/show_bug.cgi?id=229869 5 6 Reviewed by Saam Barati. 7 8 * stress/Uint8ClampedArrayClampsInt52Positive.js: Added. 9 (let.x.123.test): 10 (noInline.test.int32pos1): 11 (255.int32pos2): 12 (1.int32neg1): 13 (0.int32neg2): 14 (0.int52pos1): 15 (255.int52pos2): 16 (255.int52neg1): 17 (0.int52neg2): 18 (0.int52neg3): 19 (0.int52pos3): 20 (255.int8): 21 1 22 2021-09-09 Robin Morisset <rmorisset@apple.com> 2 23 -
trunk/Source/JavaScriptCore/ChangeLog
r282200 r282212 1 2021-09-09 Justin Michaud <justin_michaud@apple.com> 2 3 Differential testing: incorrect constant propagation around Uint8ClampedArray 4 https://bugs.webkit.org/show_bug.cgi?id=229869 5 6 We casted int52 values to int32 before clamping, which caused any value with the 32nd bit 7 set to be interpreted as negative. The fix is to check the full-size value when deciding to clamp. 8 9 Reviewed by Saam Barati. 10 11 * ftl/FTLLowerDFGToB3.cpp: 12 (JSC::FTL::DFG::LowerDFGToB3::compileCompareStrictEq): 13 1 14 2021-09-09 Robin Morisset <rmorisset@apple.com> 2 15 -
trunk/Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp
r282200 r282212 17798 17798 LValue getIntTypedArrayStoreOperand(Edge edge, bool isClamped = false) 17799 17799 { 17800 LValue intValue; 17800 LValue valueAsInt32; 17801 LValue value; 17802 LValue zero; 17803 LValue byteMax; 17804 17801 17805 switch (edge.useKind()) { 17802 17806 case Int52RepUse: 17803 17807 case Int32Use: { 17804 if (edge.useKind() == Int32Use) 17805 intValue = lowInt32(edge); 17806 else 17807 intValue = m_out.castToInt32(lowStrictInt52(edge)); 17808 17808 if (edge.useKind() == Int32Use) { 17809 value = lowInt32(edge); 17810 valueAsInt32 = value; 17811 zero = m_out.int32Zero; 17812 byteMax = m_out.constInt32(255); 17813 } else { 17814 value = lowStrictInt52(edge); 17815 valueAsInt32 = m_out.castToInt32(value); 17816 zero = m_out.int64Zero; 17817 byteMax = m_out.constInt64(255); 17818 } 17819 17809 17820 if (isClamped) { 17810 17821 LBasicBlock atLeastZero = m_out.newBlock(); … … 17814 17825 intValues.append(m_out.anchor(m_out.int32Zero)); 17815 17826 m_out.branch( 17816 m_out.lessThan( intValue, m_out.int32Zero),17827 m_out.lessThan(value, zero), 17817 17828 unsure(continuation), unsure(atLeastZero)); 17818 17829 … … 17820 17831 17821 17832 intValues.append(m_out.anchor(m_out.select( 17822 m_out.greaterThan( intValue, m_out.constInt32(255)),17833 m_out.greaterThan(value, byteMax), 17823 17834 m_out.constInt32(255), 17824 intValue)));17835 valueAsInt32))); 17825 17836 m_out.jump(continuation); 17826 17837 17827 17838 m_out.appendTo(continuation, lastNext); 17828 intValue= m_out.phi(Int32, intValues);17839 valueAsInt32 = m_out.phi(Int32, intValues); 17829 17840 } 17830 17841 break; … … 17856 17867 17857 17868 m_out.appendTo(continuation, lastNext); 17858 intValue= m_out.phi(Int32, intValues);17869 valueAsInt32 = m_out.phi(Int32, intValues); 17859 17870 } else 17860 intValue= doubleToInt32(doubleValue);17871 valueAsInt32 = doubleToInt32(doubleValue); 17861 17872 break; 17862 17873 } … … 17866 17877 } 17867 17878 17868 return intValue;17879 return valueAsInt32; 17869 17880 } 17870 17881
Note:
See TracChangeset
for help on using the changeset viewer.