⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 287626 in webkit


Ignore:
Timestamp:
Jan 5, 2022, 10:20:59 AM (5 years ago)
Author:
Russell Epstein
Message:

Cherry-pick r286283. rdar://problem/87125362

[JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt
​https://bugs.webkit.org/show_bug.cgi?id=233610
rdar://85820476

Reviewed by Saam Barati.

JSTests:

  • stress/anyint-index.js: Added. (foo):

Source/JavaScriptCore:

Since we are using isAnyInt, then we should use asAnyInt. asUInt32 will crash
if the value is double AnyInt etc.

  • dfg/DFGSpeculativeJIT.cpp: (JSC::DFG::SpeculativeJIT::jumpForTypedArrayOutOfBounds):

git-svn-id: ​https://svn.webkit.org/repository/webkit/trunk@286283 268f45cc-cd09-0410-ab3c-d52691b4dbfc

Location:
branches/safari-612-branch
Files:
1 added
3 edited

Legend:

Unmodified
Added
Removed
  • branches/safari-612-branch/JSTests/ChangeLog

    r287625 r287626  
     12022-01-05  Russell Epstein  <repstein@apple.com>
     2
     3        Cherry-pick r286283. rdar://problem/87125362
     4
     5    [JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt
     6    https://bugs.webkit.org/show_bug.cgi?id=233610
     7    rdar://85820476
     8   
     9    Reviewed by Saam Barati.
     10   
     11    JSTests:
     12   
     13    * stress/anyint-index.js: Added.
     14    (foo):
     15   
     16    Source/JavaScriptCore:
     17   
     18    Since we are using isAnyInt, then we should use asAnyInt. asUInt32 will crash
     19    if the value is double AnyInt etc.
     20   
     21    * dfg/DFGSpeculativeJIT.cpp:
     22    (JSC::DFG::SpeculativeJIT::jumpForTypedArrayOutOfBounds):
     23   
     24    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286283 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     25
     26    2021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
     27
     28            [JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt
     29            https://bugs.webkit.org/show_bug.cgi?id=233610
     30            rdar://85820476
     31
     32            Reviewed by Saam Barati.
     33
     34            * stress/anyint-index.js: Added.
     35            (foo):
     36
    1372022-01-05  Russell Epstein  <repstein@apple.com>
    238
  • branches/safari-612-branch/Source/JavaScriptCore/ChangeLog

    r287625 r287626  
     12022-01-05  Russell Epstein  <repstein@apple.com>
     2
     3        Cherry-pick r286283. rdar://problem/87125362
     4
     5    [JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt
     6    https://bugs.webkit.org/show_bug.cgi?id=233610
     7    rdar://85820476
     8   
     9    Reviewed by Saam Barati.
     10   
     11    JSTests:
     12   
     13    * stress/anyint-index.js: Added.
     14    (foo):
     15   
     16    Source/JavaScriptCore:
     17   
     18    Since we are using isAnyInt, then we should use asAnyInt. asUInt32 will crash
     19    if the value is double AnyInt etc.
     20   
     21    * dfg/DFGSpeculativeJIT.cpp:
     22    (JSC::DFG::SpeculativeJIT::jumpForTypedArrayOutOfBounds):
     23   
     24    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@286283 268f45cc-cd09-0410-ab3c-d52691b4dbfc
     25
     26    2021-11-29  Yusuke Suzuki  <ysuzuki@apple.com>
     27
     28            [JSC] jumpForTypedArrayOutOfBounds should use asAnyInt since it uses isAnyInt
     29            https://bugs.webkit.org/show_bug.cgi?id=233610
     30            rdar://85820476
     31
     32            Reviewed by Saam Barati.
     33
     34            Since we are using isAnyInt, then we should use asAnyInt. asUInt32 will crash
     35            if the value is double AnyInt etc.
     36
     37            * dfg/DFGSpeculativeJIT.cpp:
     38            (JSC::DFG::SpeculativeJIT::jumpForTypedArrayOutOfBounds):
     39
    1402022-01-05  Russell Epstein  <repstein@apple.com>
    241
  • branches/safari-612-branch/Source/JavaScriptCore/dfg/DFGSpeculativeJIT.cpp

    r287621 r287626  
    32483248        size_t length = view->length();
    32493249        Node* indexNode = m_jit.graph().child(node, 1).node();
    3250         if (indexNode->isAnyIntConstant() && indexNode->asUInt32() < length)
     3250        if (indexNode->isAnyIntConstant() && static_cast<uint64_t>(indexNode->asAnyInt()) < length)
    32513251            return JITCompiler::Jump();
    32523252#if USE(LARGE_TYPED_ARRAYS)
Note: See TracChangeset for help on using the changeset viewer.