<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[163595] trunk/Source/JavaScriptCore</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta">
<dt>Revision</dt> <dd><a href="http://trac.webkit.org/projects/webkit/changeset/163595">163595</a></dd>
<dt>Author</dt> <dd>msaboff@apple.com</dd>
<dt>Date</dt> <dd>2014-02-06 18:03:26 -0800 (Thu, 06 Feb 2014)</dd>
</dl>

<h3>Log Message</h3>
<pre>Workaround REGRESSION(<a href="http://trac.webkit.org/projects/webkit/changeset/163195">r163195</a>-<a href="http://trac.webkit.org/projects/webkit/changeset/163227">r163227</a>): Crash beneath NSErrorUserInfoFromJSException when installing AppleInternal.mpkg
https://bugs.webkit.org/show_bug.cgi?id=128347

Reviewed by Geoffrey Garen.

Added a flag to VM class called m_ignoreStackLimit that disables stack limit checks.
We set this flag in JSContextGroupCreate() and JSGlobalContextCreateInGroup().

Disabled stack overflow tests in testapi.js since it uses these paths.

THis patch will be reverted as part of a comprehensive solution to the problem.

* API/JSContextRef.cpp:
(JSContextGroupCreate):
(JSGlobalContextCreateInGroup):
* API/tests/testapi.js:
* runtime/VM.cpp:
(JSC::VM::VM):
(JSC::VM::updateStackLimitWithReservedZoneSize):
* runtime/VM.h:
(JSC::VM::ignoreStackLimit):</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#trunkSourceJavaScriptCoreAPIJSContextRefcpp">trunk/Source/JavaScriptCore/API/JSContextRef.cpp</a></li>
<li><a href="#trunkSourceJavaScriptCoreAPIteststestapijs">trunk/Source/JavaScriptCore/API/tests/testapi.js</a></li>
<li><a href="#trunkSourceJavaScriptCoreChangeLog">trunk/Source/JavaScriptCore/ChangeLog</a></li>
<li><a href="#trunkSourceJavaScriptCoreruntimeVMcpp">trunk/Source/JavaScriptCore/runtime/VM.cpp</a></li>
<li><a href="#trunkSourceJavaScriptCoreruntimeVMh">trunk/Source/JavaScriptCore/runtime/VM.h</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunkSourceJavaScriptCoreAPIJSContextRefcpp"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/API/JSContextRef.cpp (163594 => 163595)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/API/JSContextRef.cpp        2014-02-07 02:01:45 UTC (rev 163594)
+++ trunk/Source/JavaScriptCore/API/JSContextRef.cpp        2014-02-07 02:03:26 UTC (rev 163595)
</span><span class="lines">@@ -57,7 +57,9 @@
</span><span class="cx"> JSContextGroupRef JSContextGroupCreate()
</span><span class="cx"> {
</span><span class="cx">     initializeThreading();
</span><del>-    return toRef(VM::createContextGroup().leakRef());
</del><ins>+    VM* vm = VM::createContextGroup().leakRef();
+    vm-&gt;ignoreStackLimit();
+    return toRef(vm);
</ins><span class="cx"> }
</span><span class="cx"> 
</span><span class="cx"> JSContextGroupRef JSContextGroupRetain(JSContextGroupRef group)
</span><span class="lines">@@ -129,7 +131,13 @@
</span><span class="cx"> {
</span><span class="cx">     initializeThreading();
</span><span class="cx"> 
</span><del>-    RefPtr&lt;VM&gt; vm = group ? PassRefPtr&lt;VM&gt;(toJS(group)) : VM::createContextGroup();
</del><ins>+    RefPtr&lt;VM&gt; vm;
+    if (group)
+        vm = PassRefPtr&lt;VM&gt;(toJS(group));
+    else {
+        vm = VM::createContextGroup();
+        vm-&gt;ignoreStackLimit();
+    }
</ins><span class="cx"> 
</span><span class="cx">     APIEntryShim entryShim(vm.get(), false);
</span><span class="cx">     vm-&gt;makeUsableFromMultipleThreads();
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreAPIteststestapijs"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/API/tests/testapi.js (163594 => 163595)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/API/tests/testapi.js        2014-02-07 02:01:45 UTC (rev 163594)
+++ trunk/Source/JavaScriptCore/API/tests/testapi.js        2014-02-07 02:03:26 UTC (rev 163595)
</span><span class="lines">@@ -242,6 +242,7 @@
</span><span class="cx"> shouldBe('derivedOnlyDescriptor.enumerable', false);
</span><span class="cx"> 
</span><span class="cx"> shouldBe(&quot;undefined instanceof MyObject&quot;, false);
</span><ins>+/*
</ins><span class="cx"> EvilExceptionObject.hasInstance = function f() { return f(); };
</span><span class="cx"> EvilExceptionObject.__proto__ = undefined;
</span><span class="cx"> shouldThrow(&quot;undefined instanceof EvilExceptionObject&quot;);
</span><span class="lines">@@ -252,6 +253,7 @@
</span><span class="cx"> shouldThrow(&quot;EvilExceptionObject*5&quot;);
</span><span class="cx"> EvilExceptionObject.toStringExplicit = function f() { return f(); }
</span><span class="cx"> shouldThrow(&quot;String(EvilExceptionObject)&quot;);
</span><ins>+ */
</ins><span class="cx"> 
</span><span class="cx"> shouldBe(&quot;EmptyObject&quot;, &quot;[object CallbackObject]&quot;);
</span><span class="cx"> 
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreChangeLog"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/ChangeLog (163594 => 163595)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/ChangeLog        2014-02-07 02:01:45 UTC (rev 163594)
+++ trunk/Source/JavaScriptCore/ChangeLog        2014-02-07 02:03:26 UTC (rev 163595)
</span><span class="lines">@@ -1,3 +1,27 @@
</span><ins>+2014-02-06  Michael Saboff  &lt;msaboff@apple.com&gt;
+
+        Workaround REGRESSION(r163195-r163227): Crash beneath NSErrorUserInfoFromJSException when installing AppleInternal.mpkg
+        https://bugs.webkit.org/show_bug.cgi?id=128347
+
+        Reviewed by Geoffrey Garen.
+
+        Added a flag to VM class called m_ignoreStackLimit that disables stack limit checks.
+        We set this flag in JSContextGroupCreate() and JSGlobalContextCreateInGroup().
+
+        Disabled stack overflow tests in testapi.js since it uses these paths.
+
+        THis patch will be reverted as part of a comprehensive solution to the problem.
+
+        * API/JSContextRef.cpp:
+        (JSContextGroupCreate):
+        (JSGlobalContextCreateInGroup):
+        * API/tests/testapi.js:
+        * runtime/VM.cpp:
+        (JSC::VM::VM):
+        (JSC::VM::updateStackLimitWithReservedZoneSize):
+        * runtime/VM.h:
+        (JSC::VM::ignoreStackLimit):
+
</ins><span class="cx"> 2014-02-06  Mark Hahnenberg  &lt;mhahnenberg@apple.com&gt;
</span><span class="cx"> 
</span><span class="cx">         +[JSContext currentCallee] should return the currently executing JS function
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreruntimeVMcpp"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/runtime/VM.cpp (163594 => 163595)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/runtime/VM.cpp        2014-02-07 02:01:45 UTC (rev 163594)
+++ trunk/Source/JavaScriptCore/runtime/VM.cpp        2014-02-07 02:03:26 UTC (rev 163595)
</span><span class="lines">@@ -219,6 +219,7 @@
</span><span class="cx"> #if ENABLE(GC_VALIDATION)
</span><span class="cx">     , m_initializingObjectClass(0)
</span><span class="cx"> #endif
</span><ins>+    , m_ignoreStackLimit(false)
</ins><span class="cx">     , m_stackLimit(0)
</span><span class="cx"> #if ENABLE(LLINT_C_LOOP)
</span><span class="cx">     , m_jsStackLimit(0)
</span><span class="lines">@@ -738,6 +739,11 @@
</span><span class="cx"> 
</span><span class="cx"> size_t VM::updateStackLimitWithReservedZoneSize(size_t reservedZoneSize)
</span><span class="cx"> {
</span><ins>+    if (m_ignoreStackLimit) {
+        setStackLimit(0);
+        return 0;
+    }
+
</ins><span class="cx">     size_t oldReservedZoneSize = m_reservedZoneSize;
</span><span class="cx">     m_reservedZoneSize = reservedZoneSize;
</span><span class="cx"> 
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreruntimeVMh"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/runtime/VM.h (163594 => 163595)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/runtime/VM.h        2014-02-07 02:01:45 UTC (rev 163594)
+++ trunk/Source/JavaScriptCore/runtime/VM.h        2014-02-07 02:03:26 UTC (rev 163595)
</span><span class="lines">@@ -387,6 +387,8 @@
</span><span class="cx"> #endif
</span><span class="cx">         void* stackLimit() { return m_stackLimit; }
</span><span class="cx"> 
</span><ins>+        void ignoreStackLimit() { m_ignoreStackLimit = true; }
+
</ins><span class="cx">         bool isSafeToRecurse(size_t neededStackInBytes = 0) const
</span><span class="cx">         {
</span><span class="cx">             ASSERT(wtfThreadData().stack().isGrowingDownward());
</span><span class="lines">@@ -521,6 +523,7 @@
</span><span class="cx"> #if ENABLE(GC_VALIDATION)
</span><span class="cx">         const ClassInfo* m_initializingObjectClass;
</span><span class="cx"> #endif
</span><ins>+        bool m_ignoreStackLimit;
</ins><span class="cx">         size_t m_reservedZoneSize;
</span><span class="cx"> #if ENABLE(LLINT_C_LOOP)
</span><span class="cx">         struct {
</span></span></pre>
</div>
</div>

</body>
</html>