<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[210276] trunk</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta">
<dt>Revision</dt> <dd><a href="http://trac.webkit.org/projects/webkit/changeset/210276">210276</a></dd>
<dt>Author</dt> <dd>sbarati@apple.com</dd>
<dt>Date</dt> <dd>2017-01-04 11:11:23 -0800 (Wed, 04 Jan 2017)</dd>
</dl>

<h3>Log Message</h3>
<pre>We don't properly handle exceptions inside the nativeCallTrampoline macro in the LLInt
https://bugs.webkit.org/show_bug.cgi?id=163720

Reviewed by Mark Lam.

JSTests:

* stress/bound-function-tail-call-with-exception.js: Added.
(bar):
(foo):
(catch):

Source/JavaScriptCore:

In the LLInt, we were incorrectly doing the exception check after the call.
Before the exception check, we were unwinding to our caller's
frame under the assumption that our caller was always a JS frame.
This is incorrect, however, because our caller might be a C frame.
One way that it can be a C frame is when C calls to JS, and JS tail
calls to native. This patch fixes this bug by doing unwinding from
the native callee's frame instead of its callers.

* llint/LowLevelInterpreter32_64.asm:
* llint/LowLevelInterpreter64.asm:</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#trunkJSTestsChangeLog">trunk/JSTests/ChangeLog</a></li>
<li><a href="#trunkSourceJavaScriptCoreChangeLog">trunk/Source/JavaScriptCore/ChangeLog</a></li>
<li><a href="#trunkSourceJavaScriptCorellintLowLevelInterpreter32_64asm">trunk/Source/JavaScriptCore/llint/LowLevelInterpreter32_64.asm</a></li>
<li><a href="#trunkSourceJavaScriptCorellintLowLevelInterpreter64asm">trunk/Source/JavaScriptCore/llint/LowLevelInterpreter64.asm</a></li>
</ul>

<h3>Added Paths</h3>
<ul>
<li><a href="#trunkJSTestsstressboundfunctiontailcallwithexceptionjs">trunk/JSTests/stress/bound-function-tail-call-with-exception.js</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunkJSTestsChangeLog"></a>
<div class="modfile"><h4>Modified: trunk/JSTests/ChangeLog (210275 => 210276)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/JSTests/ChangeLog        2017-01-04 17:48:58 UTC (rev 210275)
+++ trunk/JSTests/ChangeLog        2017-01-04 19:11:23 UTC (rev 210276)
</span><span class="lines">@@ -1,3 +1,15 @@
</span><ins>+2017-01-04  Saam Barati  &lt;sbarati@apple.com&gt;
+
+        We don't properly handle exceptions inside the nativeCallTrampoline macro in the LLInt
+        https://bugs.webkit.org/show_bug.cgi?id=163720
+
+        Reviewed by Mark Lam.
+
+        * stress/bound-function-tail-call-with-exception.js: Added.
+        (bar):
+        (foo):
+        (catch):
+
</ins><span class="cx"> 2017-01-03  JF Bastien  &lt;jfbastien@apple.com&gt;
</span><span class="cx"> 
</span><span class="cx">         WebAssembly JS API: check and test in-call / out-call values
</span></span></pre></div>
<a id="trunkJSTestsstressboundfunctiontailcallwithexceptionjs"></a>
<div class="addfile"><h4>Added: trunk/JSTests/stress/bound-function-tail-call-with-exception.js (0 => 210276)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/JSTests/stress/bound-function-tail-call-with-exception.js                                (rev 0)
+++ trunk/JSTests/stress/bound-function-tail-call-with-exception.js        2017-01-04 19:11:23 UTC (rev 210276)
</span><span class="lines">@@ -0,0 +1,23 @@
</span><ins>+//@ runNoJIT
+
+function bar(a, idx)
+{
+    &quot;use strict&quot;;
+    if (idx &gt; 0)
+      throw &quot;Hello&quot;;
+    return a;
+}
+
+boundBar = bar.bind(null, 42);
+
+function foo(a, idx)
+{
+    &quot;use strict&quot;;
+    return boundBar(idx);
+}
+
+boundFoo = foo.bind(null, 41);
+
+try {
+    boundFoo(1);
+} catch(e) {}
</ins></span></pre></div>
<a id="trunkSourceJavaScriptCoreChangeLog"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/ChangeLog (210275 => 210276)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/ChangeLog        2017-01-04 17:48:58 UTC (rev 210275)
+++ trunk/Source/JavaScriptCore/ChangeLog        2017-01-04 19:11:23 UTC (rev 210276)
</span><span class="lines">@@ -1,3 +1,21 @@
</span><ins>+2017-01-04  Saam Barati  &lt;sbarati@apple.com&gt;
+
+        We don't properly handle exceptions inside the nativeCallTrampoline macro in the LLInt
+        https://bugs.webkit.org/show_bug.cgi?id=163720
+
+        Reviewed by Mark Lam.
+
+        In the LLInt, we were incorrectly doing the exception check after the call.
+        Before the exception check, we were unwinding to our caller's
+        frame under the assumption that our caller was always a JS frame.
+        This is incorrect, however, because our caller might be a C frame.
+        One way that it can be a C frame is when C calls to JS, and JS tail
+        calls to native. This patch fixes this bug by doing unwinding from
+        the native callee's frame instead of its callers.
+
+        * llint/LowLevelInterpreter32_64.asm:
+        * llint/LowLevelInterpreter64.asm:
+
</ins><span class="cx"> 2017-01-03  JF Bastien  &lt;jfbastien@apple.com&gt;
</span><span class="cx"> 
</span><span class="cx">         REGRESSION (r210244): Release JSC Stress test failure: wasm.yaml/wasm/js-api/wasm-to-wasm.js.default-wasm
</span></span></pre></div>
<a id="trunkSourceJavaScriptCorellintLowLevelInterpreter32_64asm"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/llint/LowLevelInterpreter32_64.asm (210275 => 210276)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/llint/LowLevelInterpreter32_64.asm        2017-01-04 17:48:58 UTC (rev 210275)
+++ trunk/Source/JavaScriptCore/llint/LowLevelInterpreter32_64.asm        2017-01-04 19:11:23 UTC (rev 210276)
</span><span class="lines">@@ -2068,13 +2068,13 @@
</span><span class="cx">         error
</span><span class="cx">     end
</span><span class="cx">     
</span><ins>+    btinz VM::m_exception[t3], .handleException
+
</ins><span class="cx">     functionEpilogue()
</span><del>-    btinz VM::m_exception[t3], .handleException
</del><span class="cx">     ret
</span><span class="cx"> 
</span><span class="cx"> .handleException:
</span><span class="cx">     storep cfr, VM::topCallFrame[t3]
</span><del>-    restoreStackPointerAfterCall()
</del><span class="cx">     jmp _llint_throw_from_slow_path_trampoline
</span><span class="cx"> end
</span><span class="cx"> 
</span></span></pre></div>
<a id="trunkSourceJavaScriptCorellintLowLevelInterpreter64asm"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/llint/LowLevelInterpreter64.asm (210275 => 210276)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/llint/LowLevelInterpreter64.asm        2017-01-04 17:48:58 UTC (rev 210275)
+++ trunk/Source/JavaScriptCore/llint/LowLevelInterpreter64.asm        2017-01-04 19:11:23 UTC (rev 210276)
</span><span class="lines">@@ -2021,18 +2021,18 @@
</span><span class="cx">             addp 32, sp
</span><span class="cx">         end
</span><span class="cx">     end
</span><ins>+
</ins><span class="cx">     loadp Callee[cfr], t3
</span><span class="cx">     andp MarkedBlockMask, t3
</span><span class="cx">     loadp MarkedBlock::m_vm[t3], t3
</span><span class="cx"> 
</span><ins>+    btqnz VM::m_exception[t3], .handleException
+
</ins><span class="cx">     functionEpilogue()
</span><del>-
-    btqnz VM::m_exception[t3], .handleException
</del><span class="cx">     ret
</span><span class="cx"> 
</span><span class="cx"> .handleException:
</span><span class="cx">     storep cfr, VM::topCallFrame[t3]
</span><del>-    restoreStackPointerAfterCall()
</del><span class="cx">     jmp _llint_throw_from_slow_path_trampoline
</span><span class="cx"> end
</span><span class="cx"> 
</span></span></pre>
</div>
</div>

</body>
</html>