⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 282212 in webkit


Ignore:
Timestamp:
Sep 9, 2021, 8:30:01 AM (5 years ago)
Author:
Justin Michaud
Message:

Differential testing: incorrect constant propagation around Uint8ClampedArray
​https://bugs.webkit.org/show_bug.cgi?id=229869

JSTests:

Reviewed by Saam Barati.

  • stress/Uint8ClampedArrayClampsInt52Positive.js: Added.

(let.x.123.test):
(noInline.test.int32pos1):
(255.int32pos2):
(1.int32neg1):
(0.int32neg2):
(0.int52pos1):
(255.int52pos2):
(255.int52neg1):
(0.int52neg2):
(0.int52neg3):
(0.int52pos3):
(255.int8):

Source/JavaScriptCore:

We casted int52 values to int32 before clamping, which caused any value with the 32nd bit
set to be interpreted as negative. The fix is to check the full-size value when deciding to clamp.

Reviewed by Saam Barati.

  • ftl/FTLLowerDFGToB3.cpp:

(JSC::FTL::DFG::LowerDFGToB3::compileCompareStrictEq):

Location:
trunk
Files:
1 added
3 edited

Legend:

Unmodified
Added
Removed
  • trunk/JSTests/ChangeLog

    r282200 r282212  
     12021-09-09  Justin Michaud  <justin_michaud@apple.com>
     2
     3        Differential testing: incorrect constant propagation around Uint8ClampedArray
     4        https://bugs.webkit.org/show_bug.cgi?id=229869
     5
     6        Reviewed by Saam Barati.
     7
     8        * stress/Uint8ClampedArrayClampsInt52Positive.js: Added.
     9        (let.x.123.test):
     10        (noInline.test.int32pos1):
     11        (255.int32pos2):
     12        (1.int32neg1):
     13        (0.int32neg2):
     14        (0.int52pos1):
     15        (255.int52pos2):
     16        (255.int52neg1):
     17        (0.int52neg2):
     18        (0.int52neg3):
     19        (0.int52pos3):
     20        (255.int8):
     21
    1222021-09-09  Robin Morisset  <rmorisset@apple.com>
    223
  • trunk/Source/JavaScriptCore/ChangeLog

    r282200 r282212  
     12021-09-09  Justin Michaud  <justin_michaud@apple.com>
     2
     3        Differential testing: incorrect constant propagation around Uint8ClampedArray
     4        https://bugs.webkit.org/show_bug.cgi?id=229869
     5
     6        We casted int52 values to int32 before clamping, which caused any value with the 32nd bit
     7        set to be interpreted as negative. The fix is to check the full-size value when deciding to clamp.
     8
     9        Reviewed by Saam Barati.
     10
     11        * ftl/FTLLowerDFGToB3.cpp:
     12        (JSC::FTL::DFG::LowerDFGToB3::compileCompareStrictEq):
     13
    1142021-09-09  Robin Morisset  <rmorisset@apple.com>
    215
  • trunk/Source/JavaScriptCore/ftl/FTLLowerDFGToB3.cpp

    r282200 r282212  
    1779817798    LValue getIntTypedArrayStoreOperand(Edge edge, bool isClamped = false)
    1779917799    {
    17800         LValue intValue;
     17800        LValue valueAsInt32;
     17801        LValue value;
     17802        LValue zero;
     17803        LValue byteMax;
     17804       
    1780117805        switch (edge.useKind()) {
    1780217806        case Int52RepUse:
    1780317807        case Int32Use: {
    17804             if (edge.useKind() == Int32Use)
    17805                 intValue = lowInt32(edge);
    17806             else
    17807                 intValue = m_out.castToInt32(lowStrictInt52(edge));
    17808 
     17808            if (edge.useKind() == Int32Use) {
     17809                value = lowInt32(edge);
     17810                valueAsInt32 = value;
     17811                zero = m_out.int32Zero;
     17812                byteMax = m_out.constInt32(255);
     17813            } else {
     17814                value = lowStrictInt52(edge);
     17815                valueAsInt32 = m_out.castToInt32(value);
     17816                zero = m_out.int64Zero;
     17817                byteMax = m_out.constInt64(255);
     17818            }
     17819           
    1780917820            if (isClamped) {
    1781017821                LBasicBlock atLeastZero = m_out.newBlock();
    … …  
    1781417825                intValues.append(m_out.anchor(m_out.int32Zero));
    1781517826                m_out.branch(
    17816                     m_out.lessThan(intValue, m_out.int32Zero),
     17827                    m_out.lessThan(value, zero),
    1781717828                    unsure(continuation), unsure(atLeastZero));
    1781817829                           
    … …  
    1782017831                           
    1782117832                intValues.append(m_out.anchor(m_out.select(
    17822                     m_out.greaterThan(intValue, m_out.constInt32(255)),
     17833                    m_out.greaterThan(value, byteMax),
    1782317834                    m_out.constInt32(255),
    17824                     intValue)));
     17835                    valueAsInt32)));
    1782517836                m_out.jump(continuation);
    1782617837                           
    1782717838                m_out.appendTo(continuation, lastNext);
    17828                 intValue = m_out.phi(Int32, intValues);
     17839                valueAsInt32 = m_out.phi(Int32, intValues);
    1782917840            }
    1783017841            break;
    … …  
    1785617867                           
    1785717868                m_out.appendTo(continuation, lastNext);
    17858                 intValue = m_out.phi(Int32, intValues);
     17869                valueAsInt32 = m_out.phi(Int32, intValues);
    1785917870            } else
    17860                 intValue = doubleToInt32(doubleValue);
     17871                valueAsInt32 = doubleToInt32(doubleValue);
    1786117872            break;
    1786217873        }
    … …  
    1786617877        }
    1786717878       
    17868         return intValue;
     17879        return valueAsInt32;
    1786917880    }
    1787017881   
Note: See TracChangeset for help on using the changeset viewer.