mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-29 20:07:30 +09:00
Issue #3049 - Harden loongarch64 Ion call and environment paths
This commit is contained in:
parent
e17a8d2e3c
commit
70d8824b1d
2 changed files with 29 additions and 0 deletions
|
|
@ -6939,6 +6939,18 @@ ICCall_Native::Compiler::generateStubCode(MacroAssembler& masm)
|
|||
Register callee = masm.extractObject(R1, ExtractTemp0);
|
||||
Address expectedCallee(ICStubReg, ICCall_Native::offsetOfCallee());
|
||||
masm.branchPtr(Assembler::NotEqual, expectedCallee, callee, &failure);
|
||||
#ifdef JS_CODEGEN_LOONGARCH64
|
||||
// The loongarch64 Ion/baseline call IC interaction is still being
|
||||
// stabilized. If a scripted function ever reaches this native-call stub,
|
||||
// JSFunction::nativeOrScript contains script data instead of a callable
|
||||
// native pointer, so fail back instead of branching into garbage.
|
||||
MOZ_ASSERT(JSFunction::offsetOfFlags() == JSFunction::offsetOfNargs() + 2);
|
||||
Address flagsAddr(callee, JSFunction::offsetOfNargs());
|
||||
int32_t scriptedBits =
|
||||
IMM32_16ADJ(JSFunction::INTERPRETED | JSFunction::INTERPRETED_LAZY);
|
||||
masm.branchTest32(Assembler::NonZero, flagsAddr, Imm32(scriptedBits),
|
||||
&failure);
|
||||
#endif
|
||||
|
||||
regs.add(R1);
|
||||
regs.takeUnchecked(callee);
|
||||
|
|
|
|||
|
|
@ -1245,6 +1245,17 @@ IonBuilder::initEnvironmentChain(MDefinition* callee)
|
|||
// them, so just use a constant undefined value.
|
||||
|
||||
if (JSFunction* fun = info().funMaybeLazy()) {
|
||||
#ifdef JS_CODEGEN_LOONGARCH64
|
||||
if (info().analysisMode() != Analysis_ArgumentsUsage &&
|
||||
(analysis().usesEnvironmentChain() || info().needsArgsObj()))
|
||||
{
|
||||
// The loongarch64 Ion function-environment path is not stable yet.
|
||||
// We can still run Ion for simpler scripts, but scripts that need a
|
||||
// function environment currently mis-handle environment objects and
|
||||
// later crash in shared property IC paths.
|
||||
return abort("Function environment unsupported on loongarch64");
|
||||
}
|
||||
#endif
|
||||
if (!callee) {
|
||||
MCallee* calleeIns = MCallee::New(alloc());
|
||||
current->add(calleeIns);
|
||||
|
|
@ -1271,6 +1282,12 @@ IonBuilder::initEnvironmentChain(MDefinition* callee)
|
|||
return abort("Extra var environment unsupported");
|
||||
|
||||
if (fun->needsCallObject()) {
|
||||
#ifdef JS_CODEGEN_LOONGARCH64
|
||||
// The loongarch64 Ion environment-object path is not stable yet:
|
||||
// inline CallObject setup can corrupt the enclosing environment
|
||||
// reserved slot and later crash during nursery collection.
|
||||
return abort("CallObject environment unsupported on loongarch64");
|
||||
#endif
|
||||
env = createCallObject(callee, env);
|
||||
if (!env)
|
||||
return false;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue