diff --git a/js/src/jit/BaselineIC.cpp b/js/src/jit/BaselineIC.cpp index adef1f46f9..1a4d9ece8c 100644 --- a/js/src/jit/BaselineIC.cpp +++ b/js/src/jit/BaselineIC.cpp @@ -6939,6 +6939,18 @@ ICCall_Native::Compiler::generateStubCode(MacroAssembler& masm) Register callee = masm.extractObject(R1, ExtractTemp0); Address expectedCallee(ICStubReg, ICCall_Native::offsetOfCallee()); masm.branchPtr(Assembler::NotEqual, expectedCallee, callee, &failure); +#ifdef JS_CODEGEN_LOONGARCH64 + // The loongarch64 Ion/baseline call IC interaction is still being + // stabilized. If a scripted function ever reaches this native-call stub, + // JSFunction::nativeOrScript contains script data instead of a callable + // native pointer, so fail back instead of branching into garbage. + MOZ_ASSERT(JSFunction::offsetOfFlags() == JSFunction::offsetOfNargs() + 2); + Address flagsAddr(callee, JSFunction::offsetOfNargs()); + int32_t scriptedBits = + IMM32_16ADJ(JSFunction::INTERPRETED | JSFunction::INTERPRETED_LAZY); + masm.branchTest32(Assembler::NonZero, flagsAddr, Imm32(scriptedBits), + &failure); +#endif regs.add(R1); regs.takeUnchecked(callee); diff --git a/js/src/jit/IonBuilder.cpp b/js/src/jit/IonBuilder.cpp index 90681c765a..ae31edc643 100644 --- a/js/src/jit/IonBuilder.cpp +++ b/js/src/jit/IonBuilder.cpp @@ -1245,6 +1245,17 @@ IonBuilder::initEnvironmentChain(MDefinition* callee) // them, so just use a constant undefined value. if (JSFunction* fun = info().funMaybeLazy()) { +#ifdef JS_CODEGEN_LOONGARCH64 + if (info().analysisMode() != Analysis_ArgumentsUsage && + (analysis().usesEnvironmentChain() || info().needsArgsObj())) + { + // The loongarch64 Ion function-environment path is not stable yet. + // We can still run Ion for simpler scripts, but scripts that need a + // function environment currently mis-handle environment objects and + // later crash in shared property IC paths. + return abort("Function environment unsupported on loongarch64"); + } +#endif if (!callee) { MCallee* calleeIns = MCallee::New(alloc()); current->add(calleeIns); @@ -1271,6 +1282,12 @@ IonBuilder::initEnvironmentChain(MDefinition* callee) return abort("Extra var environment unsupported"); if (fun->needsCallObject()) { +#ifdef JS_CODEGEN_LOONGARCH64 + // The loongarch64 Ion environment-object path is not stable yet: + // inline CallObject setup can corrupt the enclosing environment + // reserved slot and later crash during nursery collection. + return abort("CallObject environment unsupported on loongarch64"); +#endif env = createCallObject(callee, env); if (!env) return false;