Issue #3049 - Harden loongarch64 Ion call and environment paths

This commit is contained in:
Basilisk-Dev 2026-04-24 19:04:48 -04:00 • committed by wuggy
commit 70d8824b1d
2 changed files with 29 additions and 0 deletions

View file

@ -6939,6 +6939,18 @@ ICCall_Native::Compiler::generateStubCode(MacroAssembler& masm)
Register callee = masm.extractObject(R1, ExtractTemp0);
Address expectedCallee(ICStubReg, ICCall_Native::offsetOfCallee());
masm.branchPtr(Assembler::NotEqual, expectedCallee, callee, &failure);
#ifdef JS_CODEGEN_LOONGARCH64
// The loongarch64 Ion/baseline call IC interaction is still being
// stabilized. If a scripted function ever reaches this native-call stub,
// JSFunction::nativeOrScript contains script data instead of a callable
// native pointer, so fail back instead of branching into garbage.
MOZ_ASSERT(JSFunction::offsetOfFlags() == JSFunction::offsetOfNargs() + 2);
Address flagsAddr(callee, JSFunction::offsetOfNargs());
int32_t scriptedBits =
IMM32_16ADJ(JSFunction::INTERPRETED | JSFunction::INTERPRETED_LAZY);
masm.branchTest32(Assembler::NonZero, flagsAddr, Imm32(scriptedBits),
&failure);
#endif
regs.add(R1);
regs.takeUnchecked(callee);

View file

@ -1245,6 +1245,17 @@ IonBuilder::initEnvironmentChain(MDefinition* callee)
// them, so just use a constant undefined value.
if (JSFunction* fun = info().funMaybeLazy()) {
#ifdef JS_CODEGEN_LOONGARCH64
if (info().analysisMode() != Analysis_ArgumentsUsage &&
(analysis().usesEnvironmentChain() || info().needsArgsObj()))
{
// The loongarch64 Ion function-environment path is not stable yet.
// We can still run Ion for simpler scripts, but scripts that need a
// function environment currently mis-handle environment objects and
// later crash in shared property IC paths.
return abort("Function environment unsupported on loongarch64");
}
#endif
if (!callee) {
MCallee* calleeIns = MCallee::New(alloc());
current->add(calleeIns);
@ -1271,6 +1282,12 @@ IonBuilder::initEnvironmentChain(MDefinition* callee)
return abort("Extra var environment unsupported");
if (fun->needsCallObject()) {
#ifdef JS_CODEGEN_LOONGARCH64
// The loongarch64 Ion environment-object path is not stable yet:
// inline CallObject setup can corrupt the enclosing environment
// reserved slot and later crash during nursery collection.
return abort("CallObject environment unsupported on loongarch64");
#endif
env = createCallObject(callee, env);
if (!env)
return false;