mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-29 11:57:32 +09:00
Issue #3049 - Harden loongarch64 Ion call and environment paths
This commit is contained in:
parent
e17a8d2e3c
commit
70d8824b1d
2 changed files with 29 additions and 0 deletions
|
|
@ -6939,6 +6939,18 @@ ICCall_Native::Compiler::generateStubCode(MacroAssembler& masm)
|
||||||
Register callee = masm.extractObject(R1, ExtractTemp0);
|
Register callee = masm.extractObject(R1, ExtractTemp0);
|
||||||
Address expectedCallee(ICStubReg, ICCall_Native::offsetOfCallee());
|
Address expectedCallee(ICStubReg, ICCall_Native::offsetOfCallee());
|
||||||
masm.branchPtr(Assembler::NotEqual, expectedCallee, callee, &failure);
|
masm.branchPtr(Assembler::NotEqual, expectedCallee, callee, &failure);
|
||||||
|
#ifdef JS_CODEGEN_LOONGARCH64
|
||||||
|
// The loongarch64 Ion/baseline call IC interaction is still being
|
||||||
|
// stabilized. If a scripted function ever reaches this native-call stub,
|
||||||
|
// JSFunction::nativeOrScript contains script data instead of a callable
|
||||||
|
// native pointer, so fail back instead of branching into garbage.
|
||||||
|
MOZ_ASSERT(JSFunction::offsetOfFlags() == JSFunction::offsetOfNargs() + 2);
|
||||||
|
Address flagsAddr(callee, JSFunction::offsetOfNargs());
|
||||||
|
int32_t scriptedBits =
|
||||||
|
IMM32_16ADJ(JSFunction::INTERPRETED | JSFunction::INTERPRETED_LAZY);
|
||||||
|
masm.branchTest32(Assembler::NonZero, flagsAddr, Imm32(scriptedBits),
|
||||||
|
&failure);
|
||||||
|
#endif
|
||||||
|
|
||||||
regs.add(R1);
|
regs.add(R1);
|
||||||
regs.takeUnchecked(callee);
|
regs.takeUnchecked(callee);
|
||||||
|
|
|
||||||
|
|
@ -1245,6 +1245,17 @@ IonBuilder::initEnvironmentChain(MDefinition* callee)
|
||||||
// them, so just use a constant undefined value.
|
// them, so just use a constant undefined value.
|
||||||
|
|
||||||
if (JSFunction* fun = info().funMaybeLazy()) {
|
if (JSFunction* fun = info().funMaybeLazy()) {
|
||||||
|
#ifdef JS_CODEGEN_LOONGARCH64
|
||||||
|
if (info().analysisMode() != Analysis_ArgumentsUsage &&
|
||||||
|
(analysis().usesEnvironmentChain() || info().needsArgsObj()))
|
||||||
|
{
|
||||||
|
// The loongarch64 Ion function-environment path is not stable yet.
|
||||||
|
// We can still run Ion for simpler scripts, but scripts that need a
|
||||||
|
// function environment currently mis-handle environment objects and
|
||||||
|
// later crash in shared property IC paths.
|
||||||
|
return abort("Function environment unsupported on loongarch64");
|
||||||
|
}
|
||||||
|
#endif
|
||||||
if (!callee) {
|
if (!callee) {
|
||||||
MCallee* calleeIns = MCallee::New(alloc());
|
MCallee* calleeIns = MCallee::New(alloc());
|
||||||
current->add(calleeIns);
|
current->add(calleeIns);
|
||||||
|
|
@ -1271,6 +1282,12 @@ IonBuilder::initEnvironmentChain(MDefinition* callee)
|
||||||
return abort("Extra var environment unsupported");
|
return abort("Extra var environment unsupported");
|
||||||
|
|
||||||
if (fun->needsCallObject()) {
|
if (fun->needsCallObject()) {
|
||||||
|
#ifdef JS_CODEGEN_LOONGARCH64
|
||||||
|
// The loongarch64 Ion environment-object path is not stable yet:
|
||||||
|
// inline CallObject setup can corrupt the enclosing environment
|
||||||
|
// reserved slot and later crash during nursery collection.
|
||||||
|
return abort("CallObject environment unsupported on loongarch64");
|
||||||
|
#endif
|
||||||
env = createCallObject(callee, env);
|
env = createCallObject(callee, env);
|
||||||
if (!env)
|
if (!env)
|
||||||
return false;
|
return false;
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue