Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(124)

Side by Side Diff: src/builtins/builtins-sharedarraybuffer-gen.cc

Issue 2814753003: [SAB] Validate index before value conversion (Closed)
Patch Set: use byte temp register only for int8/uint8 Created 3 years, 8 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 // Copyright 2017 the V8 project authors. All rights reserved. 1 // Copyright 2017 the V8 project authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 #include "src/builtins/builtins-utils-gen.h" 5 #include "src/builtins/builtins-utils-gen.h"
6 #include "src/builtins/builtins.h" 6 #include "src/builtins/builtins.h"
7 #include "src/code-stub-assembler.h" 7 #include "src/code-stub-assembler.h"
8 #include "src/objects.h" 8 #include "src/objects.h"
9 9
10 namespace v8 { 10 namespace v8 {
11 namespace internal { 11 namespace internal {
12 12
13 using compiler::Node; 13 using compiler::Node;
14 14
15 class SharedArrayBufferBuiltinsAssembler : public CodeStubAssembler { 15 class SharedArrayBufferBuiltinsAssembler : public CodeStubAssembler {
16 public: 16 public:
17 explicit SharedArrayBufferBuiltinsAssembler( 17 explicit SharedArrayBufferBuiltinsAssembler(
18 compiler::CodeAssemblerState* state) 18 compiler::CodeAssemblerState* state)
19 : CodeStubAssembler(state) {} 19 : CodeStubAssembler(state) {}
20 20
21 protected: 21 protected:
22 typedef Node* (CodeAssembler::*AssemblerFunction)(MachineType type, 22 typedef Node* (CodeAssembler::*AssemblerFunction)(MachineType type,
23 Node* base, Node* offset, 23 Node* base, Node* offset,
24 Node* value); 24 Node* value);
25 void ValidateSharedTypedArray(Node* tagged, Node* context, 25 void ValidateSharedTypedArray(Node* tagged, Node* context,
26 Node** out_instance_type, 26 Node** out_instance_type,
27 Node** out_backing_store); 27 Node** out_backing_store);
28 Node* ConvertTaggedAtomicIndexToWord32(Node* tagged, Node* context, 28 Node* ConvertTaggedAtomicIndexToWord32(Node* tagged, Node* context,
29 Node** number_index); 29 Node** number_index);
30 void ValidateAtomicIndex(Node* index_word, Node* array_length_word, 30 void ValidateAtomicIndex(Node* array, Node* index_word, Node* context);
31 Node* context);
32 void AtomicBinopBuiltinCommon(Node* array, Node* index, Node* value, 31 void AtomicBinopBuiltinCommon(Node* array, Node* index, Node* value,
33 Node* context, AssemblerFunction function, 32 Node* context, AssemblerFunction function,
34 Runtime::FunctionId runtime_function); 33 Runtime::FunctionId runtime_function);
35 }; 34 };
36 35
37 void SharedArrayBufferBuiltinsAssembler::ValidateSharedTypedArray( 36 void SharedArrayBufferBuiltinsAssembler::ValidateSharedTypedArray(
38 Node* tagged, Node* context, Node** out_instance_type, 37 Node* tagged, Node* context, Node** out_instance_type,
39 Node** out_backing_store) { 38 Node** out_backing_store) {
40 Label not_float_or_clamped(this), invalid(this); 39 Label not_float_or_clamped(this), invalid(this);
41 40
(...skipping 39 matching lines...) Expand 10 before | Expand all | Expand 10 after
81 Node* byte_offset = ChangeUint32ToWord(TruncateTaggedToWord32( 80 Node* byte_offset = ChangeUint32ToWord(TruncateTaggedToWord32(
82 context, LoadObjectField(tagged, JSArrayBufferView::kByteOffsetOffset))); 81 context, LoadObjectField(tagged, JSArrayBufferView::kByteOffsetOffset)));
83 *out_backing_store = 82 *out_backing_store =
84 IntPtrAdd(BitcastTaggedToWord(backing_store), byte_offset); 83 IntPtrAdd(BitcastTaggedToWord(backing_store), byte_offset);
85 } 84 }
86 85
87 // https://tc39.github.io/ecmascript_sharedmem/shmem.html#Atomics.ValidateAtomic Access 86 // https://tc39.github.io/ecmascript_sharedmem/shmem.html#Atomics.ValidateAtomic Access
88 Node* SharedArrayBufferBuiltinsAssembler::ConvertTaggedAtomicIndexToWord32( 87 Node* SharedArrayBufferBuiltinsAssembler::ConvertTaggedAtomicIndexToWord32(
89 Node* tagged, Node* context, Node** number_index) { 88 Node* tagged, Node* context, Node** number_index) {
90 VARIABLE(var_result, MachineRepresentation::kWord32); 89 VARIABLE(var_result, MachineRepresentation::kWord32);
90 Label done(this), range_error(this);
91 91
92 // TODO(jkummerow): Skip ToNumber call when |tagged| is a number already. 92 // Returns word32 since index cannot be longer than a TypedArray length,
93 // Maybe this can be unified with other tagged-to-index conversions? 93 // which has a uint32 maximum.
94 // Why does this return an int32, and not an intptr? 94 // The |number_index| output parameter is used only for architectures that
95 // Why is there the additional |number_index| output parameter? 95 // don't currently have a TF implementation and forward to runtime functions
96 Callable to_number = CodeFactory::ToNumber(isolate()); 96 // instead; they expect the value has already been coerced to an integer.
97 *number_index = CallStub(to_number, context, tagged); 97 *number_index = ToSmiIndex(tagged, context, &range_error);
98 Label done(this, &var_result); 98 var_result.Bind(SmiToWord32(*number_index));
99 Goto(&done);
99 100
100 Label if_numberissmi(this), if_numberisnotsmi(this); 101 BIND(&range_error);
101 Branch(TaggedIsSmi(*number_index), &if_numberissmi, &if_numberisnotsmi);
102
103 BIND(&if_numberissmi);
104 { 102 {
105 var_result.Bind(SmiToWord32(*number_index)); 103 CallRuntime(Runtime::kThrowInvalidAtomicAccessIndexError, context);
106 Goto(&done); 104 Unreachable();
107 }
108
109 BIND(&if_numberisnotsmi);
110 {
111 Node* number_index_value = LoadHeapNumberValue(*number_index);
112 Node* access_index = TruncateFloat64ToWord32(number_index_value);
113 Node* test_index = ChangeInt32ToFloat64(access_index);
114
115 Label if_indexesareequal(this), if_indexesarenotequal(this);
116 Branch(Float64Equal(number_index_value, test_index), &if_indexesareequal,
117 &if_indexesarenotequal);
118
119 BIND(&if_indexesareequal);
120 {
121 var_result.Bind(access_index);
122 Goto(&done);
123 }
124
125 BIND(&if_indexesarenotequal);
126 {
127 CallRuntime(Runtime::kThrowInvalidAtomicAccessIndexError, context);
128 Unreachable();
129 }
130 } 105 }
131 106
132 BIND(&done); 107 BIND(&done);
133 return var_result.value(); 108 return var_result.value();
134 } 109 }
135 110
136 void SharedArrayBufferBuiltinsAssembler::ValidateAtomicIndex( 111 void SharedArrayBufferBuiltinsAssembler::ValidateAtomicIndex(Node* array,
137 Node* index_word, Node* array_length_word, Node* context) { 112 Node* index_word,
113 Node* context) {
138 // Check if the index is in bounds. If not, throw RangeError. 114 // Check if the index is in bounds. If not, throw RangeError.
139 Label check_passed(this); 115 Label check_passed(this);
140 GotoIf(Uint32LessThan(index_word, array_length_word), &check_passed); 116 Node* array_length_word32 = TruncateTaggedToWord32(
117 context, LoadObjectField(array, JSTypedArray::kLengthOffset));
118 GotoIf(Uint32LessThan(index_word, array_length_word32), &check_passed);
141 119
142 CallRuntime(Runtime::kThrowInvalidAtomicAccessIndexError, context); 120 CallRuntime(Runtime::kThrowInvalidAtomicAccessIndexError, context);
143 Unreachable(); 121 Unreachable();
144 122
145 BIND(&check_passed); 123 BIND(&check_passed);
146 } 124 }
147 125
148 TF_BUILTIN(AtomicsLoad, SharedArrayBufferBuiltinsAssembler) { 126 TF_BUILTIN(AtomicsLoad, SharedArrayBufferBuiltinsAssembler) {
149 Node* array = Parameter(Descriptor::kArray); 127 Node* array = Parameter(Descriptor::kArray);
150 Node* index = Parameter(Descriptor::kIndex); 128 Node* index = Parameter(Descriptor::kIndex);
151 Node* context = Parameter(Descriptor::kContext); 129 Node* context = Parameter(Descriptor::kContext);
152 130
153 Node* index_integer;
154 Node* index_word32 =
155 ConvertTaggedAtomicIndexToWord32(index, context, &index_integer);
156
157 Node* instance_type; 131 Node* instance_type;
158 Node* backing_store; 132 Node* backing_store;
159 ValidateSharedTypedArray(array, context, &instance_type, &backing_store); 133 ValidateSharedTypedArray(array, context, &instance_type, &backing_store);
160 134
161 Node* array_length_word32 = TruncateTaggedToWord32( 135 Node* index_integer;
162 context, LoadObjectField(array, JSTypedArray::kLengthOffset)); 136 Node* index_word32 =
163 ValidateAtomicIndex(index_word32, array_length_word32, context); 137 ConvertTaggedAtomicIndexToWord32(index, context, &index_integer);
138 ValidateAtomicIndex(array, index_word32, context);
164 Node* index_word = ChangeUint32ToWord(index_word32); 139 Node* index_word = ChangeUint32ToWord(index_word32);
165 140
166 Label i8(this), u8(this), i16(this), u16(this), i32(this), u32(this), 141 Label i8(this), u8(this), i16(this), u16(this), i32(this), u32(this),
167 other(this); 142 other(this);
168 int32_t case_values[] = { 143 int32_t case_values[] = {
169 FIXED_INT8_ARRAY_TYPE, FIXED_UINT8_ARRAY_TYPE, FIXED_INT16_ARRAY_TYPE, 144 FIXED_INT8_ARRAY_TYPE, FIXED_UINT8_ARRAY_TYPE, FIXED_INT16_ARRAY_TYPE,
170 FIXED_UINT16_ARRAY_TYPE, FIXED_INT32_ARRAY_TYPE, FIXED_UINT32_ARRAY_TYPE, 145 FIXED_UINT16_ARRAY_TYPE, FIXED_INT32_ARRAY_TYPE, FIXED_UINT32_ARRAY_TYPE,
171 }; 146 };
172 Label* case_labels[] = { 147 Label* case_labels[] = {
173 &i8, &u8, &i16, &u16, &i32, &u32, 148 &i8, &u8, &i16, &u16, &i32, &u32,
(...skipping 29 matching lines...) Expand all
203 BIND(&other); 178 BIND(&other);
204 Unreachable(); 179 Unreachable();
205 } 180 }
206 181
207 TF_BUILTIN(AtomicsStore, SharedArrayBufferBuiltinsAssembler) { 182 TF_BUILTIN(AtomicsStore, SharedArrayBufferBuiltinsAssembler) {
208 Node* array = Parameter(Descriptor::kArray); 183 Node* array = Parameter(Descriptor::kArray);
209 Node* index = Parameter(Descriptor::kIndex); 184 Node* index = Parameter(Descriptor::kIndex);
210 Node* value = Parameter(Descriptor::kValue); 185 Node* value = Parameter(Descriptor::kValue);
211 Node* context = Parameter(Descriptor::kContext); 186 Node* context = Parameter(Descriptor::kContext);
212 187
213 // The value_integer needs to be computed before the validations as the
214 // ToInteger function can be potentially modified in JS to invalidate the
215 // conditions. This is just a no-cost safety measure as SABs can't be neutered
216 // or shrunk.
217 Node* value_integer = ToInteger(context, value);
218 Node* value_word32 = TruncateTaggedToWord32(context, value_integer);
219
220 Node* index_integer;
221 Node* index_word32 =
222 ConvertTaggedAtomicIndexToWord32(index, context, &index_integer);
223
224 Node* instance_type; 188 Node* instance_type;
225 Node* backing_store; 189 Node* backing_store;
226 ValidateSharedTypedArray(array, context, &instance_type, &backing_store); 190 ValidateSharedTypedArray(array, context, &instance_type, &backing_store);
227 191
228 Node* array_length_word32 = TruncateTaggedToWord32( 192 Node* index_integer;
229 context, LoadObjectField(array, JSTypedArray::kLengthOffset)); 193 Node* index_word32 =
230 ValidateAtomicIndex(index_word32, array_length_word32, context); 194 ConvertTaggedAtomicIndexToWord32(index, context, &index_integer);
195 ValidateAtomicIndex(array, index_word32, context);
231 Node* index_word = ChangeUint32ToWord(index_word32); 196 Node* index_word = ChangeUint32ToWord(index_word32);
232 197
198 Node* value_integer = ToInteger(context, value);
199 Node* value_word32 = TruncateTaggedToWord32(context, value_integer);
200
201 #if DEBUG
Jakob Kummerow 2017/04/12 11:47:33 This sounds like a use case for CSA_ASSERT. If the
binji 2017/04/12 18:43:44 Done, thanks! Didn't know about CSA_ASSERT.
202 // In Debug mode, we re-validate the index as a sanity check because
203 // ToInteger above calls out to JavaScript. A SharedArrayBuffer can't be
204 // neutered and the TypedArray length can't change either, so skipping this
205 // check in Release mode is safe.
206 ValidateAtomicIndex(array, index_word32, context);
207 #endif
208
233 Label u8(this), u16(this), u32(this), other(this); 209 Label u8(this), u16(this), u32(this), other(this);
234 int32_t case_values[] = { 210 int32_t case_values[] = {
235 FIXED_INT8_ARRAY_TYPE, FIXED_UINT8_ARRAY_TYPE, FIXED_INT16_ARRAY_TYPE, 211 FIXED_INT8_ARRAY_TYPE, FIXED_UINT8_ARRAY_TYPE, FIXED_INT16_ARRAY_TYPE,
236 FIXED_UINT16_ARRAY_TYPE, FIXED_INT32_ARRAY_TYPE, FIXED_UINT32_ARRAY_TYPE, 212 FIXED_UINT16_ARRAY_TYPE, FIXED_INT32_ARRAY_TYPE, FIXED_UINT32_ARRAY_TYPE,
237 }; 213 };
238 Label* case_labels[] = { 214 Label* case_labels[] = {
239 &u8, &u8, &u16, &u16, &u32, &u32, 215 &u8, &u8, &u16, &u16, &u32, &u32,
240 }; 216 };
241 Switch(instance_type, &other, case_values, case_labels, 217 Switch(instance_type, &other, case_values, case_labels,
242 arraysize(case_labels)); 218 arraysize(case_labels));
(...skipping 17 matching lines...) Expand all
260 BIND(&other); 236 BIND(&other);
261 Unreachable(); 237 Unreachable();
262 } 238 }
263 239
264 TF_BUILTIN(AtomicsExchange, SharedArrayBufferBuiltinsAssembler) { 240 TF_BUILTIN(AtomicsExchange, SharedArrayBufferBuiltinsAssembler) {
265 Node* array = Parameter(Descriptor::kArray); 241 Node* array = Parameter(Descriptor::kArray);
266 Node* index = Parameter(Descriptor::kIndex); 242 Node* index = Parameter(Descriptor::kIndex);
267 Node* value = Parameter(Descriptor::kValue); 243 Node* value = Parameter(Descriptor::kValue);
268 Node* context = Parameter(Descriptor::kContext); 244 Node* context = Parameter(Descriptor::kContext);
269 245
270 // The value_integer needs to be computed before the validations as the
271 // ToInteger function can be potentially modified in JS to invalidate the
272 // conditions. This is just a no-cost safety measure as SABs can't be neutered
273 // or shrunk.
274 Node* value_integer = ToInteger(context, value);
275
276 Node* index_integer;
277 Node* index_word32 =
278 ConvertTaggedAtomicIndexToWord32(index, context, &index_integer);
279
280 Node* instance_type; 246 Node* instance_type;
281 Node* backing_store; 247 Node* backing_store;
282 ValidateSharedTypedArray(array, context, &instance_type, &backing_store); 248 ValidateSharedTypedArray(array, context, &instance_type, &backing_store);
283 249
284 Node* array_length_word32 = TruncateTaggedToWord32( 250 Node* index_integer;
285 context, LoadObjectField(array, JSTypedArray::kLengthOffset)); 251 Node* index_word32 =
286 ValidateAtomicIndex(index_word32, array_length_word32, context); 252 ConvertTaggedAtomicIndexToWord32(index, context, &index_integer);
253 ValidateAtomicIndex(array, index_word32, context);
254
255 Node* value_integer = ToInteger(context, value);
256
257 #if DEBUG
258 // In Debug mode, we re-validate the index as a sanity check because
259 // ToInteger above calls out to JavaScript. A SharedArrayBuffer can't be
260 // neutered and the TypedArray length can't change either, so skipping this
261 // check in Release mode is safe.
262 ValidateAtomicIndex(array, index_word32, context);
263 #endif
287 264
288 #if V8_TARGET_ARCH_MIPS || V8_TARGET_ARCH_MIPS64 265 #if V8_TARGET_ARCH_MIPS || V8_TARGET_ARCH_MIPS64
289 Return(CallRuntime(Runtime::kAtomicsExchange, context, array, index_integer, 266 Return(CallRuntime(Runtime::kAtomicsExchange, context, array, index_integer,
290 value_integer)); 267 value_integer));
291 #else 268 #else
292 Node* index_word = ChangeUint32ToWord(index_word32); 269 Node* index_word = ChangeUint32ToWord(index_word32);
293 270
294 Node* value_word32 = TruncateTaggedToWord32(context, value_integer); 271 Node* value_word32 = TruncateTaggedToWord32(context, value_integer);
295 272
296 Label i8(this), u8(this), i16(this), u16(this), i32(this), u32(this), 273 Label i8(this), u8(this), i16(this), u16(this), i32(this), u32(this),
(...skipping 40 matching lines...) Expand 10 before | Expand all | Expand 10 after
337 #endif // V8_TARGET_ARCH_MIPS || V8_TARGET_ARCH_MIPS64 314 #endif // V8_TARGET_ARCH_MIPS || V8_TARGET_ARCH_MIPS64
338 } 315 }
339 316
340 TF_BUILTIN(AtomicsCompareExchange, SharedArrayBufferBuiltinsAssembler) { 317 TF_BUILTIN(AtomicsCompareExchange, SharedArrayBufferBuiltinsAssembler) {
341 Node* array = Parameter(Descriptor::kArray); 318 Node* array = Parameter(Descriptor::kArray);
342 Node* index = Parameter(Descriptor::kIndex); 319 Node* index = Parameter(Descriptor::kIndex);
343 Node* old_value = Parameter(Descriptor::kOldValue); 320 Node* old_value = Parameter(Descriptor::kOldValue);
344 Node* new_value = Parameter(Descriptor::kNewValue); 321 Node* new_value = Parameter(Descriptor::kNewValue);
345 Node* context = Parameter(Descriptor::kContext); 322 Node* context = Parameter(Descriptor::kContext);
346 323
347 // The value_integers needs to be computed before the validations as the
348 // ToInteger function can be potentially modified in JS to invalidate the
349 // conditions. This is just a no-cost safety measure as SABs can't be neutered
350 // or shrunk.
351 Node* old_value_integer = ToInteger(context, old_value);
352 Node* new_value_integer = ToInteger(context, new_value);
353
354 Node* index_integer;
355 Node* index_word32 =
356 ConvertTaggedAtomicIndexToWord32(index, context, &index_integer);
357
358 Node* instance_type; 324 Node* instance_type;
359 Node* backing_store; 325 Node* backing_store;
360 ValidateSharedTypedArray(array, context, &instance_type, &backing_store); 326 ValidateSharedTypedArray(array, context, &instance_type, &backing_store);
361 327
362 Node* array_length_word32 = TruncateTaggedToWord32( 328 Node* index_integer;
363 context, LoadObjectField(array, JSTypedArray::kLengthOffset)); 329 Node* index_word32 =
364 ValidateAtomicIndex(index_word32, array_length_word32, context); 330 ConvertTaggedAtomicIndexToWord32(index, context, &index_integer);
331 ValidateAtomicIndex(array, index_word32, context);
332
333 Node* old_value_integer = ToInteger(context, old_value);
334 Node* new_value_integer = ToInteger(context, new_value);
335
336 #if DEBUG
337 // In Debug mode, we re-validate the index as a sanity check because
338 // ToInteger above calls out to JavaScript. A SharedArrayBuffer can't be
339 // neutered and the TypedArray length can't change either, so skipping this
340 // check in Release mode is safe.
341 ValidateAtomicIndex(array, index_word32, context);
Jarin 2017/04/12 04:39:01 Nit: It would be even better if we could use here
binji 2017/04/12 18:43:44 Done.
342 #endif
365 343
366 #if V8_TARGET_ARCH_MIPS || V8_TARGET_ARCH_MIPS64 || V8_TARGET_ARCH_PPC64 || \ 344 #if V8_TARGET_ARCH_MIPS || V8_TARGET_ARCH_MIPS64 || V8_TARGET_ARCH_PPC64 || \
367 V8_TARGET_ARCH_PPC || V8_TARGET_ARCH_S390 || V8_TARGET_ARCH_S390X 345 V8_TARGET_ARCH_PPC || V8_TARGET_ARCH_S390 || V8_TARGET_ARCH_S390X
368 Return(CallRuntime(Runtime::kAtomicsCompareExchange, context, array, 346 Return(CallRuntime(Runtime::kAtomicsCompareExchange, context, array,
369 index_integer, old_value_integer, new_value_integer)); 347 index_integer, old_value_integer, new_value_integer));
370 #else 348 #else
371 Node* index_word = ChangeUint32ToWord(index_word32); 349 Node* index_word = ChangeUint32ToWord(index_word32);
372 350
373 Node* old_value_word32 = TruncateTaggedToWord32(context, old_value_integer); 351 Node* old_value_word32 = TruncateTaggedToWord32(context, old_value_integer);
374 352
(...skipping 61 matching lines...) Expand 10 before | Expand all | Expand 10 after
436 BINOP_BUILTIN(Add) 414 BINOP_BUILTIN(Add)
437 BINOP_BUILTIN(Sub) 415 BINOP_BUILTIN(Sub)
438 BINOP_BUILTIN(And) 416 BINOP_BUILTIN(And)
439 BINOP_BUILTIN(Or) 417 BINOP_BUILTIN(Or)
440 BINOP_BUILTIN(Xor) 418 BINOP_BUILTIN(Xor)
441 #undef BINOP_BUILTIN 419 #undef BINOP_BUILTIN
442 420
443 void SharedArrayBufferBuiltinsAssembler::AtomicBinopBuiltinCommon( 421 void SharedArrayBufferBuiltinsAssembler::AtomicBinopBuiltinCommon(
444 Node* array, Node* index, Node* value, Node* context, 422 Node* array, Node* index, Node* value, Node* context,
445 AssemblerFunction function, Runtime::FunctionId runtime_function) { 423 AssemblerFunction function, Runtime::FunctionId runtime_function) {
446 // The value_integer needs to be computed before the validations as the 424 Node* instance_type;
447 // ToInteger function can be potentially modified in JS to invalidate the 425 Node* backing_store;
448 // conditions. This is just a no-cost safety measure as SABs can't be neutered 426 ValidateSharedTypedArray(array, context, &instance_type, &backing_store);
449 // or shrunk.
450 Node* value_integer = ToInteger(context, value);
451 427
452 Node* index_integer; 428 Node* index_integer;
453 Node* index_word32 = 429 Node* index_word32 =
454 ConvertTaggedAtomicIndexToWord32(index, context, &index_integer); 430 ConvertTaggedAtomicIndexToWord32(index, context, &index_integer);
431 ValidateAtomicIndex(array, index_word32, context);
455 432
456 Node* instance_type; 433 Node* value_integer = ToInteger(context, value);
457 Node* backing_store;
458 ValidateSharedTypedArray(array, context, &instance_type, &backing_store);
459 434
460 Node* array_length_word32 = TruncateTaggedToWord32( 435 #if DEBUG
461 context, LoadObjectField(array, JSTypedArray::kLengthOffset)); 436 // In Debug mode, we re-validate the index as a sanity check because
462 ValidateAtomicIndex(index_word32, array_length_word32, context); 437 // ToInteger above calls out to JavaScript. A SharedArrayBuffer can't be
438 // neutered and the TypedArray length can't change either, so skipping this
439 // check in Release mode is safe.
440 ValidateAtomicIndex(array, index_word32, context);
441 #endif
463 442
464 #if V8_TARGET_ARCH_MIPS || V8_TARGET_ARCH_MIPS64 || V8_TARGET_ARCH_PPC64 || \ 443 #if V8_TARGET_ARCH_MIPS || V8_TARGET_ARCH_MIPS64 || V8_TARGET_ARCH_PPC64 || \
465 V8_TARGET_ARCH_PPC || V8_TARGET_ARCH_S390 || V8_TARGET_ARCH_S390X 444 V8_TARGET_ARCH_PPC || V8_TARGET_ARCH_S390 || V8_TARGET_ARCH_S390X
466 Return(CallRuntime(runtime_function, context, array, index_integer, 445 Return(CallRuntime(runtime_function, context, array, index_integer,
467 value_integer)); 446 value_integer));
468 #else 447 #else
469 Node* index_word = ChangeUint32ToWord(index_word32); 448 Node* index_word = ChangeUint32ToWord(index_word32);
470 449
471 Node* value_word32 = TruncateTaggedToWord32(context, value_integer); 450 Node* value_word32 = TruncateTaggedToWord32(context, value_integer);
472 451
(...skipping 39 matching lines...) Expand 10 before | Expand all | Expand 10 after
512 491
513 // This shouldn't happen, we've already validated the type. 492 // This shouldn't happen, we've already validated the type.
514 Bind(&other); 493 Bind(&other);
515 Unreachable(); 494 Unreachable();
516 #endif // V8_TARGET_ARCH_MIPS || V8_TARGET_ARCH_MIPS64 || V8_TARGET_ARCH_PPC64 495 #endif // V8_TARGET_ARCH_MIPS || V8_TARGET_ARCH_MIPS64 || V8_TARGET_ARCH_PPC64
517 // || V8_TARGET_ARCH_PPC || V8_TARGET_ARCH_S390 || V8_TARGET_ARCH_S390X 496 // || V8_TARGET_ARCH_PPC || V8_TARGET_ARCH_S390 || V8_TARGET_ARCH_S390X
518 } 497 }
519 498
520 } // namespace internal 499 } // namespace internal
521 } // namespace v8 500 } // namespace v8
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698