Changeset 287625 in webkit
- Timestamp:
- Jan 5, 2022, 10:20:56 AM (5 years ago)
- Location:
- branches/safari-612-branch
- Files:
-
- 1 added
- 3 edited
-
JSTests/ChangeLog (modified) (1 diff)
-
JSTests/stress/slice-termination-exception.js (added)
-
Source/JavaScriptCore/ChangeLog (modified) (1 diff)
-
Source/JavaScriptCore/runtime/ArrayPrototype.cpp (modified) (4 diffs)
Legend:
- Unmodified
- Added
- Removed
-
branches/safari-612-branch/JSTests/ChangeLog
r287624 r287625 1 2022-01-05 Russell Epstein <repstein@apple.com> 2 3 Cherry-pick r286275. rdar://problem/87125258 4 5 [JSC] slice should be aware of TerminationException 6 https://bugs.webkit.org/show_bug.cgi?id=233593 7 rdar://85823844 8 9 Reviewed by Mark Lam. 10 11 JSTests: 12 13 * stress/slice-termination-exception.js: Added. 14 (async infiniteLoop): 15 16 Source/JavaScriptCore: 17 18 Since termination exception can happen at any time, assertNoException is wrong. 19 20 * runtime/ArrayPrototype.cpp: 21 (JSC::JSC_DEFINE_HOST_FUNCTION): 22 23 git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286275 268f45cc-cd09-0410-ab3c-d52691b4dbfc 24 25 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 26 27 [JSC] slice should be aware of TerminationException 28 https://bugs.webkit.org/show_bug.cgi?id=233593 29 rdar://85823844 30 31 Reviewed by Mark Lam. 32 33 * stress/slice-termination-exception.js: Added. 34 (async infiniteLoop): 35 1 36 2022-01-05 Russell Epstein <repstein@apple.com> 2 37 -
branches/safari-612-branch/Source/JavaScriptCore/ChangeLog
r287624 r287625 1 2022-01-05 Russell Epstein <repstein@apple.com> 2 3 Cherry-pick r286275. rdar://problem/87125258 4 5 [JSC] slice should be aware of TerminationException 6 https://bugs.webkit.org/show_bug.cgi?id=233593 7 rdar://85823844 8 9 Reviewed by Mark Lam. 10 11 JSTests: 12 13 * stress/slice-termination-exception.js: Added. 14 (async infiniteLoop): 15 16 Source/JavaScriptCore: 17 18 Since termination exception can happen at any time, assertNoException is wrong. 19 20 * runtime/ArrayPrototype.cpp: 21 (JSC::JSC_DEFINE_HOST_FUNCTION): 22 23 git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286275 268f45cc-cd09-0410-ab3c-d52691b4dbfc 24 25 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 26 27 [JSC] slice should be aware of TerminationException 28 https://bugs.webkit.org/show_bug.cgi?id=233593 29 rdar://85823844 30 31 Reviewed by Mark Lam. 32 33 Since termination exception can happen at any time, assertNoException is wrong. 34 35 * runtime/ArrayPrototype.cpp: 36 (JSC::JSC_DEFINE_HOST_FUNCTION): 37 1 38 2022-01-05 Russell Epstein <repstein@apple.com> 2 39 -
branches/safari-612-branch/Source/JavaScriptCore/runtime/ArrayPrototype.cpp
r280761 r287625 210 210 auto scope = DECLARE_THROW_SCOPE(vm); 211 211 212 auto exceptionResult = [] () { 213 return std::make_pair(SpeciesConstructResult::Exception, nullptr); 214 }; 212 constexpr std::pair<SpeciesConstructResult, JSObject*> exceptionResult { SpeciesConstructResult::Exception, nullptr }; 215 213 216 214 // ECMA 9.4.2.3: https://tc39.github.io/ecma262/#sec-arrayspeciescreate 217 215 JSValue constructor = jsUndefined(); 218 216 bool thisIsArray = isArray(globalObject, thisObject); 219 RETURN_IF_EXCEPTION(scope, exceptionResult ());217 RETURN_IF_EXCEPTION(scope, exceptionResult); 220 218 if (LIKELY(thisIsArray)) { 221 219 // Fast path in the normal case where the user has not set an own constructor and the Array.prototype.constructor is normal. 222 220 // We need prototype check for subclasses of Array, which are Array objects but have a different prototype by default. 223 221 bool isValid = speciesWatchpointIsValid(vm, thisObject); 224 scope.assertNoException();222 RETURN_IF_EXCEPTION(scope, exceptionResult); 225 223 if (LIKELY(isValid)) 226 return std:: make_pair(SpeciesConstructResult::FastPath, nullptr);224 return std::pair { SpeciesConstructResult::FastPath, nullptr }; 227 225 228 226 constructor = thisObject->get(globalObject, vm.propertyNames->constructor); 229 RETURN_IF_EXCEPTION(scope, exceptionResult ());227 RETURN_IF_EXCEPTION(scope, exceptionResult); 230 228 if (constructor.isConstructor(vm)) { 231 229 JSObject* constructorObject = jsCast<JSObject*>(constructor); … … 233 231 && constructorObject->inherits<ArrayConstructor>(vm); 234 232 if (isArrayConstructorFromAnotherRealm) 235 return std:: make_pair(SpeciesConstructResult::FastPath, nullptr);233 return std::pair { SpeciesConstructResult::FastPath, nullptr }; 236 234 } 237 235 if (constructor.isObject()) { 238 236 constructor = constructor.get(globalObject, vm.propertyNames->speciesSymbol); 239 RETURN_IF_EXCEPTION(scope, exceptionResult ());237 RETURN_IF_EXCEPTION(scope, exceptionResult); 240 238 if (constructor.isNull()) 241 return std:: make_pair(SpeciesConstructResult::FastPath, nullptr);239 return std::pair { SpeciesConstructResult::FastPath, nullptr }; 242 240 } 243 241 } else { 244 242 // If isArray is false, return ? ArrayCreate(length). 245 return std:: make_pair(SpeciesConstructResult::FastPath, nullptr);243 return std::pair { SpeciesConstructResult::FastPath, nullptr }; 246 244 } 247 245 248 246 if (constructor.isUndefined()) 249 return std:: make_pair(SpeciesConstructResult::FastPath, nullptr);247 return std::pair { SpeciesConstructResult::FastPath, nullptr }; 250 248 251 249 MarkedArgumentBuffer args; … … 253 251 ASSERT(!args.hasOverflowed()); 254 252 JSObject* newObject = construct(globalObject, constructor, args, "Species construction did not get a valid constructor"); 255 RETURN_IF_EXCEPTION(scope, exceptionResult ());256 return std:: make_pair(SpeciesConstructResult::CreatedObject, newObject);253 RETURN_IF_EXCEPTION(scope, exceptionResult); 254 return std::pair { SpeciesConstructResult::CreatedObject, newObject }; 257 255 } 258 256 … … 1564 1562 // We need to check the species constructor here since checking it in the JS wrapper is too expensive for the non-optimizing tiers. 1565 1563 bool isValid = speciesWatchpointIsValid(vm, firstArray); 1566 scope.assertNoException();1564 RETURN_IF_EXCEPTION(scope, { }); 1567 1565 if (UNLIKELY(!isValid)) 1568 1566 return JSValue::encode(jsNull());
Note:
See TracChangeset
for help on using the changeset viewer.