Changeset 286283 in webkit
- Timestamp:
- Nov 29, 2021, 8:43:51 PM (5 years ago)
- Location:
- trunk
- Files:
-
- 1 added
- 3 edited
-
JSTests/ChangeLog (modified) (1 diff)
-
JSTests/stress/anyint-index.js (added)
-
Source/JavaScriptCore/ChangeLog (modified) (1 diff)
-
Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
trunk/JSTests/ChangeLog
r286278 r286283 1 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 2 3 [JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt 4 https://bugs.webkit.org/show_bug.cgi?id=233610 5 rdar://85820476 6 7 Reviewed by Saam Barati. 8 9 * stress/anyint-index.js: Added. 10 (foo): 11 1 12 2021-11-29 Saam Barati <sbarati@apple.com> 2 13 -
trunk/Source/JavaScriptCore/ChangeLog
r286278 r286283 1 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 2 3 [JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt 4 https://bugs.webkit.org/show_bug.cgi?id=233610 5 rdar://85820476 6 7 Reviewed by Saam Barati. 8 9 Since we are using isAnyInt, then we should use asAnyInt. asUInt32 will crash 10 if the value is double AnyInt etc. 11 12 * dfg/DFGSpeculativeJIT.cpp: 13 (JSC::DFG::SpeculativeJIT::jumpForTypedArrayOutOfBounds): 14 1 15 2021-11-29 Saam Barati <sbarati@apple.com> 2 16 -
trunk/Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp
r285978 r286283 3538 3538 size_t length = view->length(); 3539 3539 Node* indexNode = m_jit.graph().child(node, 1).node(); 3540 if (indexNode->isAnyIntConstant() && indexNode->asUInt32() < length)3540 if (indexNode->isAnyIntConstant() && static_cast<uint64_t>(indexNode->asAnyInt()) < length) 3541 3541 return JITCompiler::Jump(); 3542 3542 #if USE(LARGE_TYPED_ARRAYS)
Note:
See TracChangeset
for help on using the changeset viewer.