⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 287625 in webkit


Ignore:
Timestamp:
Jan 5, 2022, 10:20:56 AM (5 years ago)
Author:
Russell Epstein
Message:

Cherry-pick r286275. rdar://problem/87125258

[JSC] slice should be aware of TerminationException
​https://bugs.webkit.org/show_bug.cgi?id=233593
rdar://85823844

Reviewed by Mark Lam.

JSTests:

  • stress/slice-termination-exception.js: Added. (async infiniteLoop):

Source/JavaScriptCore:

Since termination exception can happen at any time, assertNoException is wrong.

  • runtime/ArrayPrototype.cpp: (JSC::JSC_DEFINE_HOST_FUNCTION):

git-svn-id: ​https://svn.webkit.org/repository/webkit/trunk@286275 268f45cc-cd09-0410-ab3c-d52691b4dbfc

Location:
branches/safari-612-branch
Files:
1 added
3 edited

Legend:

Unmodified
Added
Removed
  • branches/safari-612-branch/JSTests/ChangeLog

    r287624 r287625  
     12022-01-05  Russell Epstein  <repstein@apple.com>
     2
     3        Cherry-pick r286275. rdar://problem/87125258
     4
     5    [JSC] slice should be aware of TerminationException
     6    https://bugs.webkit.org/show_bug.cgi?id=233593
     7    rdar://85823844
     8   
     9    Reviewed by Mark Lam.
     10   
     11    JSTests:
     12   
     13    * stress/slice-termination-exception.js: Added.
     14    (async infiniteLoop):
     15   
     16    Source/JavaScriptCore:
     17   
     18    Since termination exception can happen at any time, assertNoException is wrong.
     19   
     20    * runtime/ArrayPrototype.cpp:
     21    (JSC::JSC_DEFINE_HOST_FUNCTION):
     22   
     23    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286275 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     24
     25    2021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
     26
     27            [JSC] slice should be aware of TerminationException
     28            https://bugs.webkit.org/show_bug.cgi?id=233593
     29            rdar://85823844
     30
     31            Reviewed by Mark Lam.
     32
     33            * stress/slice-termination-exception.js: Added.
     34            (async infiniteLoop):
     35
    1362022-01-05  Russell Epstein  <repstein@apple.com>
    237
  • branches/safari-612-branch/Source/JavaScriptCore/ChangeLog

    r287624 r287625  
     12022-01-05  Russell Epstein  <repstein@apple.com>
     2
     3        Cherry-pick r286275. rdar://problem/87125258
     4
     5    [JSC] slice should be aware of TerminationException
     6    https://bugs.webkit.org/show_bug.cgi?id=233593
     7    rdar://85823844
     8   
     9    Reviewed by Mark Lam.
     10   
     11    JSTests:
     12   
     13    * stress/slice-termination-exception.js: Added.
     14    (async infiniteLoop):
     15   
     16    Source/JavaScriptCore:
     17   
     18    Since termination exception can happen at any time, assertNoException is wrong.
     19   
     20    * runtime/ArrayPrototype.cpp:
     21    (JSC::JSC_DEFINE_HOST_FUNCTION):
     22   
     23    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286275 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     24
     25    2021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
     26
     27            [JSC] slice should be aware of TerminationException
     28            https://bugs.webkit.org/show_bug.cgi?id=233593
     29            rdar://85823844
     30
     31            Reviewed by Mark Lam.
     32
     33            Since termination exception can happen at any time, assertNoException is wrong.
     34
     35            * runtime/ArrayPrototype.cpp:
     36            (JSC::JSC_DEFINE_HOST_FUNCTION):
     37
    1382022-01-05  Russell Epstein  <repstein@apple.com>
    239
  • branches/safari-612-branch/Source/JavaScriptCore/runtime/ArrayPrototype.cpp

    r280761 r287625  
    210210    auto scope = DECLARE_THROW_SCOPE(vm);
    211211
    212     auto exceptionResult = [] () {
    213         return std::make_pair(SpeciesConstructResult::Exception, nullptr);
    214     };
     212    constexpr std::pair<SpeciesConstructResult, JSObject*> exceptionResult { SpeciesConstructResult::Exception, nullptr };
    215213
    216214    // ECMA 9.4.2.3: https://tc39.github.io/ecma262/#sec-arrayspeciescreate
    217215    JSValue constructor = jsUndefined();
    218216    bool thisIsArray = isArray(globalObject, thisObject);
    219     RETURN_IF_EXCEPTION(scope, exceptionResult());
     217    RETURN_IF_EXCEPTION(scope, exceptionResult);
    220218    if (LIKELY(thisIsArray)) {
    221219        // Fast path in the normal case where the user has not set an own constructor and the Array.prototype.constructor is normal.
    222220        // We need prototype check for subclasses of Array, which are Array objects but have a different prototype by default.
    223221        bool isValid = speciesWatchpointIsValid(vm, thisObject);
    224         scope.assertNoException();
     222        RETURN_IF_EXCEPTION(scope, exceptionResult);
    225223        if (LIKELY(isValid))
    226             return std::make_pair(SpeciesConstructResult::FastPath, nullptr);
     224            return std::pair { SpeciesConstructResult::FastPath, nullptr };
    227225
    228226        constructor = thisObject->get(globalObject, vm.propertyNames->constructor);
    229         RETURN_IF_EXCEPTION(scope, exceptionResult());
     227        RETURN_IF_EXCEPTION(scope, exceptionResult);
    230228        if (constructor.isConstructor(vm)) {
    231229            JSObject* constructorObject = jsCast<JSObject*>(constructor);
    … …  
    233231                && constructorObject->inherits<ArrayConstructor>(vm);
    234232            if (isArrayConstructorFromAnotherRealm)
    235                 return std::make_pair(SpeciesConstructResult::FastPath, nullptr);
     233                return std::pair { SpeciesConstructResult::FastPath, nullptr };
    236234        }
    237235        if (constructor.isObject()) {
    238236            constructor = constructor.get(globalObject, vm.propertyNames->speciesSymbol);
    239             RETURN_IF_EXCEPTION(scope, exceptionResult());
     237            RETURN_IF_EXCEPTION(scope, exceptionResult);
    240238            if (constructor.isNull())
    241                 return std::make_pair(SpeciesConstructResult::FastPath, nullptr);
     239                return std::pair { SpeciesConstructResult::FastPath, nullptr };
    242240        }
    243241    } else {
    244242        // If isArray is false, return ? ArrayCreate(length).
    245         return std::make_pair(SpeciesConstructResult::FastPath, nullptr);
     243        return std::pair { SpeciesConstructResult::FastPath, nullptr };
    246244    }
    247245
    248246    if (constructor.isUndefined())
    249         return std::make_pair(SpeciesConstructResult::FastPath, nullptr);
     247        return std::pair { SpeciesConstructResult::FastPath, nullptr };
    250248
    251249    MarkedArgumentBuffer args;
    … …  
    253251    ASSERT(!args.hasOverflowed());
    254252    JSObject* newObject = construct(globalObject, constructor, args, "Species construction did not get a valid constructor");
    255     RETURN_IF_EXCEPTION(scope, exceptionResult());
    256     return std::make_pair(SpeciesConstructResult::CreatedObject, newObject);
     253    RETURN_IF_EXCEPTION(scope, exceptionResult);
     254    return std::pair { SpeciesConstructResult::CreatedObject, newObject };
    257255}
    258256
    … …  
    15641562    // We need to check the species constructor here since checking it in the JS wrapper is too expensive for the non-optimizing tiers.
    15651563    bool isValid = speciesWatchpointIsValid(vm, firstArray);
    1566     scope.assertNoException();
     1564    RETURN_IF_EXCEPTION(scope, { });
    15671565    if (UNLIKELY(!isValid))
    15681566        return JSValue::encode(jsNull());
Note: See TracChangeset for help on using the changeset viewer.