Disable potentially unsafe attempts at recovering JIT operations.

This commit is contained in:
Moonchild 2025-03-05 18:05:04 +01:00 • committed by roytam1
commit 43a2299480
3 changed files with 2 additions and 40 deletions

View file

@ -7064,10 +7064,8 @@ class MRegExpMatcher
TRIVIAL_NEW_WRAPPERS TRIVIAL_NEW_WRAPPERS
NAMED_OPERANDS((0, regexp), (1, string), (2, lastIndex)) NAMED_OPERANDS((0, regexp), (1, string), (2, lastIndex))
MOZ_MUST_USE bool writeRecoverData(CompactBufferWriter& writer) const override;
bool canRecoverOnBailout() const override { bool canRecoverOnBailout() const override {
return true; return false;
} }
bool possiblyCalls() const override { bool possiblyCalls() const override {
@ -7102,7 +7100,7 @@ class MRegExpSearcher
MOZ_MUST_USE bool writeRecoverData(CompactBufferWriter& writer) const override; MOZ_MUST_USE bool writeRecoverData(CompactBufferWriter& writer) const override;
bool canRecoverOnBailout() const override { bool canRecoverOnBailout() const override {
return true; return false;
} }
bool possiblyCalls() const override { bool possiblyCalls() const override {

View file

@ -13,7 +13,6 @@
#include "jsobj.h" #include "jsobj.h"
#include "jsstr.h" #include "jsstr.h"
#include "builtin/RegExp.h"
#include "builtin/TypedObject.h" #include "builtin/TypedObject.h"
#include "gc/Heap.h" #include "gc/Heap.h"
@ -1082,32 +1081,6 @@ RNaNToZero::recover(JSContext* cx, SnapshotIterator& iter) const
return true; return true;
} }
bool
MRegExpMatcher::writeRecoverData(CompactBufferWriter& writer) const
{
MOZ_ASSERT(canRecoverOnBailout());
writer.writeUnsigned(uint32_t(RInstruction::Recover_RegExpMatcher));
return true;
}
RRegExpMatcher::RRegExpMatcher(CompactBufferReader& reader)
{}
bool
RRegExpMatcher::recover(JSContext* cx, SnapshotIterator& iter) const
{
RootedObject regexp(cx, &iter.read().toObject());
RootedString input(cx, iter.read().toString());
int32_t lastIndex = iter.read().toInt32();
RootedValue result(cx);
if (!RegExpMatcherRaw(cx, regexp, input, lastIndex, nullptr, &result))
return false;
iter.storeInstructionResult(result);
return true;
}
bool bool
MRegExpSearcher::writeRecoverData(CompactBufferWriter& writer) const MRegExpSearcher::writeRecoverData(CompactBufferWriter& writer) const
{ {

View file

@ -90,7 +90,6 @@ namespace jit {
_(Random) \ _(Random) \
_(StringSplit) \ _(StringSplit) \
_(NaNToZero) \ _(NaNToZero) \
_(RegExpMatcher) \
_(RegExpSearcher) \ _(RegExpSearcher) \
_(RegExpTester) \ _(RegExpTester) \
_(StringReplace) \ _(StringReplace) \
@ -486,14 +485,6 @@ class RNaNToZero final : public RInstruction
bool recover(JSContext* cx, SnapshotIterator& iter) const; bool recover(JSContext* cx, SnapshotIterator& iter) const;
}; };
class RRegExpMatcher final : public RInstruction
{
public:
RINSTRUCTION_HEADER_NUM_OP_(RegExpMatcher, 3)
MOZ_MUST_USE bool recover(JSContext* cx, SnapshotIterator& iter) const;
};
class RRegExpSearcher final : public RInstruction class RRegExpSearcher final : public RInstruction
{ {
public: public: