Changeset 286275 in webkit
- Timestamp:
- Nov 29, 2021, 5:20:43 PM (5 years ago)
- Location:
- trunk
- Files:
-
- 1 added
- 3 edited
-
JSTests/ChangeLog (modified) (1 diff)
-
JSTests/stress/slice-termination-exception.js (added)
-
Source/JavaScriptCore/ChangeLog (modified) (1 diff)
-
Source/JavaScriptCore/runtime/ArrayPrototype.cpp (modified) (4 diffs)
Legend:
- Unmodified
- Added
- Removed
-
trunk/JSTests/ChangeLog
r286255 r286275 1 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 2 3 [JSC] slice should be aware of TerminationException 4 https://bugs.webkit.org/show_bug.cgi?id=233593 5 rdar://85823844 6 7 Reviewed by Mark Lam. 8 9 * stress/slice-termination-exception.js: Added. 10 (async infiniteLoop): 11 1 12 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 2 13 -
trunk/Source/JavaScriptCore/ChangeLog
r286255 r286275 1 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 2 3 [JSC] slice should be aware of TerminationException 4 https://bugs.webkit.org/show_bug.cgi?id=233593 5 rdar://85823844 6 7 Reviewed by Mark Lam. 8 9 Since termination exception can happen at any time, assertNoException is wrong. 10 11 * runtime/ArrayPrototype.cpp: 12 (JSC::JSC_DEFINE_HOST_FUNCTION): 13 1 14 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 2 15 -
trunk/Source/JavaScriptCore/runtime/ArrayPrototype.cpp
r285730 r286275 209 209 auto scope = DECLARE_THROW_SCOPE(vm); 210 210 211 auto exceptionResult = [] () { 212 return std::make_pair(SpeciesConstructResult::Exception, nullptr); 213 }; 211 constexpr std::pair<SpeciesConstructResult, JSObject*> exceptionResult { SpeciesConstructResult::Exception, nullptr }; 214 212 215 213 // ECMA 9.4.2.3: https://tc39.github.io/ecma262/#sec-arrayspeciescreate 216 214 JSValue constructor = jsUndefined(); 217 215 bool thisIsArray = isArray(globalObject, thisObject); 218 RETURN_IF_EXCEPTION(scope, exceptionResult ());216 RETURN_IF_EXCEPTION(scope, exceptionResult); 219 217 if (LIKELY(thisIsArray)) { 220 218 // Fast path in the normal case where the user has not set an own constructor and the Array.prototype.constructor is normal. 221 219 // We need prototype check for subclasses of Array, which are Array objects but have a different prototype by default. 222 220 bool isValid = speciesWatchpointIsValid(vm, thisObject); 223 scope.assertNoException();221 RETURN_IF_EXCEPTION(scope, exceptionResult); 224 222 if (LIKELY(isValid)) 225 return std:: make_pair(SpeciesConstructResult::FastPath, nullptr);223 return std::pair { SpeciesConstructResult::FastPath, nullptr }; 226 224 227 225 constructor = thisObject->get(globalObject, vm.propertyNames->constructor); 228 RETURN_IF_EXCEPTION(scope, exceptionResult ());226 RETURN_IF_EXCEPTION(scope, exceptionResult); 229 227 if (constructor.isConstructor(vm)) { 230 228 JSObject* constructorObject = jsCast<JSObject*>(constructor); … … 232 230 && constructorObject->inherits<ArrayConstructor>(vm); 233 231 if (isArrayConstructorFromAnotherRealm) 234 return std:: make_pair(SpeciesConstructResult::FastPath, nullptr);232 return std::pair { SpeciesConstructResult::FastPath, nullptr }; 235 233 } 236 234 if (constructor.isObject()) { 237 235 constructor = constructor.get(globalObject, vm.propertyNames->speciesSymbol); 238 RETURN_IF_EXCEPTION(scope, exceptionResult ());236 RETURN_IF_EXCEPTION(scope, exceptionResult); 239 237 if (constructor.isNull()) 240 return std:: make_pair(SpeciesConstructResult::FastPath, nullptr);238 return std::pair { SpeciesConstructResult::FastPath, nullptr }; 241 239 } 242 240 } else { 243 241 // If isArray is false, return ? ArrayCreate(length). 244 return std:: make_pair(SpeciesConstructResult::FastPath, nullptr);242 return std::pair { SpeciesConstructResult::FastPath, nullptr }; 245 243 } 246 244 247 245 if (constructor.isUndefined()) 248 return std:: make_pair(SpeciesConstructResult::FastPath, nullptr);246 return std::pair { SpeciesConstructResult::FastPath, nullptr }; 249 247 250 248 MarkedArgumentBuffer args; … … 252 250 ASSERT(!args.hasOverflowed()); 253 251 JSObject* newObject = construct(globalObject, constructor, args, "Species construction did not get a valid constructor"); 254 RETURN_IF_EXCEPTION(scope, exceptionResult ());255 return std:: make_pair(SpeciesConstructResult::CreatedObject, newObject);252 RETURN_IF_EXCEPTION(scope, exceptionResult); 253 return std::pair { SpeciesConstructResult::CreatedObject, newObject }; 256 254 } 257 255 … … 1563 1561 // We need to check the species constructor here since checking it in the JS wrapper is too expensive for the non-optimizing tiers. 1564 1562 bool isValid = speciesWatchpointIsValid(vm, firstArray); 1565 scope.assertNoException();1563 RETURN_IF_EXCEPTION(scope, { }); 1566 1564 if (UNLIKELY(!isValid)) 1567 1565 return JSValue::encode(jsNull());
Note:
See TracChangeset
for help on using the changeset viewer.