⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 286283 in webkit


Ignore:
Timestamp:
Nov 29, 2021, 8:43:51 PM (5 years ago)
Author:
ysuzuki@apple.com
Message:

[JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt
​https://bugs.webkit.org/show_bug.cgi?id=233610
rdar://85820476

Reviewed by Saam Barati.

JSTests:

  • stress/anyint-index.js: Added.

(foo):

Source/JavaScriptCore:

Since we are using isAnyInt, then we should use asAnyInt. asUInt32 will crash
if the value is double AnyInt etc.

  • dfg/DFGSpeculativeJIT.cpp:

(JSC::DFG::SpeculativeJIT::jumpForTypedArrayOutOfBounds):

Location:
trunk
Files:
1 added
3 edited

Legend:

Unmodified
Added
Removed
  • trunk/JSTests/ChangeLog

    r286278 r286283  
     12021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
     2
     3        [JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt
     4        https://bugs.webkit.org/show_bug.cgi?id=233610
     5        rdar://85820476
     6
     7        Reviewed by Saam Barati.
     8
     9        * stress/anyint-index.js: Added.
     10        (foo):
     11
    1122021-11-29  Saam Barati  <sbarati@apple.com>
    213
  • trunk/Source/JavaScriptCore/ChangeLog

    r286278 r286283  
     12021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
     2
     3        [JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt
     4        https://bugs.webkit.org/show_bug.cgi?id=233610
     5        rdar://85820476
     6
     7        Reviewed by Saam Barati.
     8
     9        Since we are using isAnyInt, then we should use asAnyInt. asUInt32 will crash
     10        if the value is double AnyInt etc.
     11
     12        * dfg/DFGSpeculativeJIT.cpp:
     13        (JSC::DFG::SpeculativeJIT::jumpForTypedArrayOutOfBounds):
     14
    1152021-11-29  Saam Barati  <sbarati@apple.com>
    216
  • trunk/Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp

    r285978 r286283  
    35383538        size_t length = view->length();
    35393539        Node* indexNode = m_jit.graph().child(node, 1).node();
    3540         if (indexNode->isAnyIntConstant() && indexNode->asUInt32() < length)
     3540        if (indexNode->isAnyIntConstant() && static_cast<uint64_t>(indexNode->asAnyInt()) < length)
    35413541            return JITCompiler::Jump();
    35423542#if USE(LARGE_TYPED_ARRAYS)
Note: See TracChangeset for help on using the changeset viewer.