Changeset 287626 in webkit
- Timestamp:
- Jan 5, 2022, 10:20:59 AM (5 years ago)
- Location:
- branches/safari-612-branch
- Files:
-
- 1 added
- 3 edited
-
JSTests/ChangeLog (modified) (1 diff)
-
JSTests/stress/anyint-index.js (added)
-
Source/JavaScriptCore/ChangeLog (modified) (1 diff)
-
Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
-
branches/safari-612-branch/JSTests/ChangeLog
r287625 r287626 1 2022-01-05 Russell Epstein <repstein@apple.com> 2 3 Cherry-pick r286283. rdar://problem/87125362 4 5 [JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt 6 https://bugs.webkit.org/show_bug.cgi?id=233610 7 rdar://85820476 8 9 Reviewed by Saam Barati. 10 11 JSTests: 12 13 * stress/anyint-index.js: Added. 14 (foo): 15 16 Source/JavaScriptCore: 17 18 Since we are using isAnyInt, then we should use asAnyInt. asUInt32 will crash 19 if the value is double AnyInt etc. 20 21 * dfg/DFGSpeculativeJIT.cpp: 22 (JSC::DFG::SpeculativeJIT::jumpForTypedArrayOutOfBounds): 23 24 git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286283 268f45cc-cd09-0410-ab3c-d52691b4dbfc 25 26 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 27 28 [JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt 29 https://bugs.webkit.org/show_bug.cgi?id=233610 30 rdar://85820476 31 32 Reviewed by Saam Barati. 33 34 * stress/anyint-index.js: Added. 35 (foo): 36 1 37 2022-01-05 Russell Epstein <repstein@apple.com> 2 38 -
branches/safari-612-branch/Source/JavaScriptCore/ChangeLog
r287625 r287626 1 2022-01-05 Russell Epstein <repstein@apple.com> 2 3 Cherry-pick r286283. rdar://problem/87125362 4 5 [JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt 6 https://bugs.webkit.org/show_bug.cgi?id=233610 7 rdar://85820476 8 9 Reviewed by Saam Barati. 10 11 JSTests: 12 13 * stress/anyint-index.js: Added. 14 (foo): 15 16 Source/JavaScriptCore: 17 18 Since we are using isAnyInt, then we should use asAnyInt. asUInt32 will crash 19 if the value is double AnyInt etc. 20 21 * dfg/DFGSpeculativeJIT.cpp: 22 (JSC::DFG::SpeculativeJIT::jumpForTypedArrayOutOfBounds): 23 24 git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286283 268f45cc-cd09-0410-ab3c-d52691b4dbfc 25 26 2021-11-29 Yusuke Suzuki <ysuzuki@apple.com> 27 28 [JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt 29 https://bugs.webkit.org/show_bug.cgi?id=233610 30 rdar://85820476 31 32 Reviewed by Saam Barati. 33 34 Since we are using isAnyInt, then we should use asAnyInt. asUInt32 will crash 35 if the value is double AnyInt etc. 36 37 * dfg/DFGSpeculativeJIT.cpp: 38 (JSC::DFG::SpeculativeJIT::jumpForTypedArrayOutOfBounds): 39 1 40 2022-01-05 Russell Epstein <repstein@apple.com> 2 41 -
branches/safari-612-branch/Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp
r287621 r287626 3248 3248 size_t length = view->length(); 3249 3249 Node* indexNode = m_jit.graph().child(node, 1).node(); 3250 if (indexNode->isAnyIntConstant() && indexNode->asUInt32() < length)3250 if (indexNode->isAnyIntConstant() && static_cast<uint64_t>(indexNode->asAnyInt()) < length) 3251 3251 return JITCompiler::Jump(); 3252 3252 #if USE(LARGE_TYPED_ARRAYS)
Note:
See TracChangeset
for help on using the changeset viewer.