⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 286275 in webkit


Ignore:
Timestamp:
Nov 29, 2021, 5:20:43 PM (5 years ago)
Author:
ysuzuki@apple.com
Message:

[JSC] slice should be aware of TerminationException
​https://bugs.webkit.org/show_bug.cgi?id=233593
rdar://85823844

Reviewed by Mark Lam.

JSTests:

  • stress/slice-termination-exception.js: Added.

(async infiniteLoop):

Source/JavaScriptCore:

Since termination exception can happen at any time, assertNoException is wrong.

  • runtime/ArrayPrototype.cpp:

(JSC::JSC_DEFINE_HOST_FUNCTION):

Location:
trunk
Files:
1 added
3 edited

Legend:

Unmodified
Added
Removed
  • trunk/JSTests/ChangeLog

    r286255 r286275  
     12021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
     2
     3        [JSC] slice should be aware of TerminationException
     4        https://bugs.webkit.org/show_bug.cgi?id=233593
     5        rdar://85823844
     6
     7        Reviewed by Mark Lam.
     8
     9        * stress/slice-termination-exception.js: Added.
     10        (async infiniteLoop):
     11
    1122021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
    213
  • trunk/Source/JavaScriptCore/ChangeLog

    r286255 r286275  
     12021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
     2
     3        [JSC] slice should be aware of TerminationException
     4        https://bugs.webkit.org/show_bug.cgi?id=233593
     5        rdar://85823844
     6
     7        Reviewed by Mark Lam.
     8
     9        Since termination exception can happen at any time, assertNoException is wrong.
     10
     11        * runtime/ArrayPrototype.cpp:
     12        (JSC::JSC_DEFINE_HOST_FUNCTION):
     13
    1142021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
    215
  • trunk/Source/JavaScriptCore/runtime/ArrayPrototype.cpp

    r285730 r286275  
    209209    auto scope = DECLARE_THROW_SCOPE(vm);
    210210
    211     auto exceptionResult = [] () {
    212         return std::make_pair(SpeciesConstructResult::Exception, nullptr);
    213     };
     211    constexpr std::pair<SpeciesConstructResult, JSObject*> exceptionResult { SpeciesConstructResult::Exception, nullptr };
    214212
    215213    // ECMA 9.4.2.3: https://tc39.github.io/ecma262/#sec-arrayspeciescreate
    216214    JSValue constructor = jsUndefined();
    217215    bool thisIsArray = isArray(globalObject, thisObject);
    218     RETURN_IF_EXCEPTION(scope, exceptionResult());
     216    RETURN_IF_EXCEPTION(scope, exceptionResult);
    219217    if (LIKELY(thisIsArray)) {
    220218        // Fast path in the normal case where the user has not set an own constructor and the Array.prototype.constructor is normal.
    221219        // We need prototype check for subclasses of Array, which are Array objects but have a different prototype by default.
    222220        bool isValid = speciesWatchpointIsValid(vm, thisObject);
    223         scope.assertNoException();
     221        RETURN_IF_EXCEPTION(scope, exceptionResult);
    224222        if (LIKELY(isValid))
    225             return std::make_pair(SpeciesConstructResult::FastPath, nullptr);
     223            return std::pair { SpeciesConstructResult::FastPath, nullptr };
    226224
    227225        constructor = thisObject->get(globalObject, vm.propertyNames->constructor);
    228         RETURN_IF_EXCEPTION(scope, exceptionResult());
     226        RETURN_IF_EXCEPTION(scope, exceptionResult);
    229227        if (constructor.isConstructor(vm)) {
    230228            JSObject* constructorObject = jsCast<JSObject*>(constructor);
    … …  
    232230                && constructorObject->inherits<ArrayConstructor>(vm);
    233231            if (isArrayConstructorFromAnotherRealm)
    234                 return std::make_pair(SpeciesConstructResult::FastPath, nullptr);
     232                return std::pair { SpeciesConstructResult::FastPath, nullptr };
    235233        }
    236234        if (constructor.isObject()) {
    237235            constructor = constructor.get(globalObject, vm.propertyNames->speciesSymbol);
    238             RETURN_IF_EXCEPTION(scope, exceptionResult());
     236            RETURN_IF_EXCEPTION(scope, exceptionResult);
    239237            if (constructor.isNull())
    240                 return std::make_pair(SpeciesConstructResult::FastPath, nullptr);
     238                return std::pair { SpeciesConstructResult::FastPath, nullptr };
    241239        }
    242240    } else {
    243241        // If isArray is false, return ? ArrayCreate(length).
    244         return std::make_pair(SpeciesConstructResult::FastPath, nullptr);
     242        return std::pair { SpeciesConstructResult::FastPath, nullptr };
    245243    }
    246244
    247245    if (constructor.isUndefined())
    248         return std::make_pair(SpeciesConstructResult::FastPath, nullptr);
     246        return std::pair { SpeciesConstructResult::FastPath, nullptr };
    249247
    250248    MarkedArgumentBuffer args;
    … …  
    252250    ASSERT(!args.hasOverflowed());
    253251    JSObject* newObject = construct(globalObject, constructor, args, "Species construction did not get a valid constructor");
    254     RETURN_IF_EXCEPTION(scope, exceptionResult());
    255     return std::make_pair(SpeciesConstructResult::CreatedObject, newObject);
     252    RETURN_IF_EXCEPTION(scope, exceptionResult);
     253    return std::pair { SpeciesConstructResult::CreatedObject, newObject };
    256254}
    257255
    … …  
    15631561    // We need to check the species constructor here since checking it in the JS wrapper is too expensive for the non-optimizing tiers.
    15641562    bool isValid = speciesWatchpointIsValid(vm, firstArray);
    1565     scope.assertNoException();
     1563    RETURN_IF_EXCEPTION(scope, { });
    15661564    if (UNLIKELY(!isValid))
    15671565        return JSValue::encode(jsNull());
Note: See TracChangeset for help on using the changeset viewer.