Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(1294)

Unified Diff: src/wasm/wasm-module.cc

Issue 2416393002: Revert of [wasm] Fix bounds check for zero initial memory. (Closed)
Patch Set: Created 4 years, 2 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « src/wasm/wasm-module.h ('k') | test/mjsunit/wasm/grow-memory.js » ('j') | no next file with comments »
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: src/wasm/wasm-module.cc
diff --git a/src/wasm/wasm-module.cc b/src/wasm/wasm-module.cc
index c0432179dcceba28fb9f341cf4792fd57a2eeb42..abbc2ba85d90d2486ec6ca836465315f023759d8 100644
--- a/src/wasm/wasm-module.cc
+++ b/src/wasm/wasm-module.cc
@@ -2056,6 +2056,38 @@
return new_info;
}
+bool wasm::UpdateWasmModuleMemory(Handle<JSObject> object, Address old_start,
+ Address new_start, uint32_t old_size,
+ uint32_t new_size) {
+ DisallowHeapAllocation no_allocation;
+ if (!IsWasmObject(*object)) {
+ return false;
+ }
+
+ // Get code table associated with the module js_object
+ Object* obj = object->GetInternalField(kWasmModuleCodeTable);
+ Handle<FixedArray> code_table(FixedArray::cast(obj));
+
+ // Iterate through the code objects in the code table and update relocation
+ // information
+ for (int i = 0; i < code_table->length(); ++i) {
+ obj = code_table->get(i);
+ Handle<Code> code(Code::cast(obj));
+
+ int mode_mask = RelocInfo::ModeMask(RelocInfo::WASM_MEMORY_REFERENCE) |
+ RelocInfo::ModeMask(RelocInfo::WASM_MEMORY_SIZE_REFERENCE);
+ for (RelocIterator it(*code, mode_mask); !it.done(); it.next()) {
+ RelocInfo::Mode mode = it.rinfo()->rmode();
+ if (RelocInfo::IsWasmMemoryReference(mode) ||
+ RelocInfo::IsWasmMemorySizeReference(mode)) {
+ it.rinfo()->update_wasm_memory_reference(old_start, new_start, old_size,
+ new_size);
+ }
+ }
+ }
+ return true;
+}
+
Handle<FixedArray> wasm::BuildFunctionTable(Isolate* isolate, uint32_t index,
const WasmModule* module) {
const WasmIndirectFunctionTable* table = &module->function_tables[index];
@@ -2207,9 +2239,9 @@
int32_t wasm::GrowInstanceMemory(Isolate* isolate, Handle<JSObject> instance,
uint32_t pages) {
- if (!IsWasmObject(*instance)) return false;
- if (pages == 0) return GetInstanceMemorySize(isolate, instance);
-
+ if (pages == 0) {
+ return GetInstanceMemorySize(isolate, instance);
+ }
Address old_mem_start = nullptr;
uint32_t old_size = 0, new_size = 0;
@@ -2246,8 +2278,10 @@
memcpy(new_mem_start, old_mem_start, old_size);
}
SetInstanceMemory(instance, *buffer);
- RelocateInstanceCode(instance, old_mem_start, new_mem_start, old_size,
- new_size);
+ if (!UpdateWasmModuleMemory(instance, old_mem_start, new_mem_start, old_size,
+ new_size)) {
+ return -1;
+ }
DCHECK(old_size % WasmModule::kPageSize == 0);
return (old_size / WasmModule::kPageSize);
}
« no previous file with comments | « src/wasm/wasm-module.h ('k') | test/mjsunit/wasm/grow-memory.js » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698