<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[243925] trunk</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta">
<dt>Revision</dt> <dd><a href="http://trac.webkit.org/projects/webkit/changeset/243925">243925</a></dd>
<dt>Author</dt> <dd>ysuzuki@apple.com</dd>
<dt>Date</dt> <dd>2019-04-04 21:17:44 -0700 (Thu, 04 Apr 2019)</dd>
</dl>

<h3>Log Message</h3>
<pre>[JSC] makeBoundFunction should not assume incoming "length" value is Int32 because it performs some calculation in bytecode
https://bugs.webkit.org/show_bug.cgi?id=196631

Reviewed by Saam Barati.

JSTests:

* stress/make-bound-function-should-not-assume-int32-length.js: Added.
(assert):
(test):
(foo):

Source/JavaScriptCore:

makeBoundFunction assumes that "length" argument is always Int32. But this should not be done since this "length" value is calculated in builtin JS code.
DFG may store this value in Double format so that we should not rely on that this value is Int32. This patch fixes makeBoundFunction function to perform
toInt32 operation. We also insert a missing exception check for `JSString::value(ExecState*)` in makeBoundFunction.

* JavaScriptCore.xcodeproj/project.pbxproj:
* Sources.txt:
* interpreter/CallFrameInlines.h:
* runtime/DoublePredictionFuzzerAgent.cpp: Copied from Source/JavaScriptCore/interpreter/CallFrameInlines.h.
(JSC::DoublePredictionFuzzerAgent::DoublePredictionFuzzerAgent):
(JSC::DoublePredictionFuzzerAgent::getPrediction):
* runtime/DoublePredictionFuzzerAgent.h: Copied from Source/JavaScriptCore/interpreter/CallFrameInlines.h.
* runtime/JSGlobalObject.cpp:
(JSC::makeBoundFunction):
* runtime/Options.h:
* runtime/VM.cpp:
(JSC::VM::VM):</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#trunkJSTestsChangeLog">trunk/JSTests/ChangeLog</a></li>
<li><a href="#trunkSourceJavaScriptCoreChangeLog">trunk/Source/JavaScriptCore/ChangeLog</a></li>
<li><a href="#trunkSourceJavaScriptCoreJavaScriptCorexcodeprojprojectpbxproj">trunk/Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj</a></li>
<li><a href="#trunkSourceJavaScriptCoreSourcestxt">trunk/Source/JavaScriptCore/Sources.txt</a></li>
<li><a href="#trunkSourceJavaScriptCoreinterpreterCallFrameInlinesh">trunk/Source/JavaScriptCore/interpreter/CallFrameInlines.h</a></li>
<li><a href="#trunkSourceJavaScriptCoreruntimeJSGlobalObjectcpp">trunk/Source/JavaScriptCore/runtime/JSGlobalObject.cpp</a></li>
<li><a href="#trunkSourceJavaScriptCoreruntimeOptionsh">trunk/Source/JavaScriptCore/runtime/Options.h</a></li>
<li><a href="#trunkSourceJavaScriptCoreruntimeVMcpp">trunk/Source/JavaScriptCore/runtime/VM.cpp</a></li>
</ul>

<h3>Added Paths</h3>
<ul>
<li><a href="#trunkJSTestsstressmakeboundfunctionshouldnotassumeint32lengthjs">trunk/JSTests/stress/make-bound-function-should-not-assume-int32-length.js</a></li>
<li><a href="#trunkSourceJavaScriptCoreruntimeDoublePredictionFuzzerAgentcpp">trunk/Source/JavaScriptCore/runtime/DoublePredictionFuzzerAgent.cpp</a></li>
<li><a href="#trunkSourceJavaScriptCoreruntimeDoublePredictionFuzzerAgenth">trunk/Source/JavaScriptCore/runtime/DoublePredictionFuzzerAgent.h</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunkJSTestsChangeLog"></a>
<div class="modfile"><h4>Modified: trunk/JSTests/ChangeLog (243924 => 243925)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/JSTests/ChangeLog  2019-04-05 01:45:12 UTC (rev 243924)
+++ trunk/JSTests/ChangeLog     2019-04-05 04:17:44 UTC (rev 243925)
</span><span class="lines">@@ -1,3 +1,15 @@
</span><ins>+2019-04-04  Yusuke Suzuki  <ysuzuki@apple.com>
+
+        [JSC] makeBoundFunction should not assume incoming "length" value is Int32 because it performs some calculation in bytecode
+        https://bugs.webkit.org/show_bug.cgi?id=196631
+
+        Reviewed by Saam Barati.
+
+        * stress/make-bound-function-should-not-assume-int32-length.js: Added.
+        (assert):
+        (test):
+        (foo):
+
</ins><span class="cx"> 2019-04-04  Saam Barati  <sbarati@apple.com>
</span><span class="cx"> 
</span><span class="cx">         Unreviewed. Make the test from r243906 catch the thrown exceptions.
</span></span></pre></div>
<a id="trunkJSTestsstressmakeboundfunctionshouldnotassumeint32lengthjs"></a>
<div class="addfile"><h4>Added: trunk/JSTests/stress/make-bound-function-should-not-assume-int32-length.js (0 => 243925)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/JSTests/stress/make-bound-function-should-not-assume-int32-length.js                               (rev 0)
+++ trunk/JSTests/stress/make-bound-function-should-not-assume-int32-length.js  2019-04-05 04:17:44 UTC (rev 243925)
</span><span class="lines">@@ -0,0 +1,18 @@
</span><ins>+//@ runDefault("--useDoublePredictionFuzzerAgent=1", "--useConcurrentJIT=0")
+// This test should not crash.
+function assert(b) {
+    if (!b)
+        throw new Error("Bad")
+}
+noInline(assert);
+
+function test(f, v, c, d) {
+    return f.bind(v, c, d);
+}
+
+function foo(a,b,c,d,e,f) { return this; }
+let thisValue = {};
+for (let i = 0; i < 10000; i++) {
+    let f = test(foo, thisValue, 20, 30);
+    assert(f(foo, thisValue, 20, 30) === thisValue);
+}
</ins></span></pre></div>
<a id="trunkSourceJavaScriptCoreChangeLog"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/ChangeLog (243924 => 243925)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/ChangeLog    2019-04-05 01:45:12 UTC (rev 243924)
+++ trunk/Source/JavaScriptCore/ChangeLog       2019-04-05 04:17:44 UTC (rev 243925)
</span><span class="lines">@@ -1,3 +1,27 @@
</span><ins>+2019-04-04  Yusuke Suzuki  <ysuzuki@apple.com>
+
+        [JSC] makeBoundFunction should not assume incoming "length" value is Int32 because it performs some calculation in bytecode
+        https://bugs.webkit.org/show_bug.cgi?id=196631
+
+        Reviewed by Saam Barati.
+
+        makeBoundFunction assumes that "length" argument is always Int32. But this should not be done since this "length" value is calculated in builtin JS code.
+        DFG may store this value in Double format so that we should not rely on that this value is Int32. This patch fixes makeBoundFunction function to perform
+        toInt32 operation. We also insert a missing exception check for `JSString::value(ExecState*)` in makeBoundFunction.
+
+        * JavaScriptCore.xcodeproj/project.pbxproj:
+        * Sources.txt:
+        * interpreter/CallFrameInlines.h:
+        * runtime/DoublePredictionFuzzerAgent.cpp: Copied from Source/JavaScriptCore/interpreter/CallFrameInlines.h.
+        (JSC::DoublePredictionFuzzerAgent::DoublePredictionFuzzerAgent):
+        (JSC::DoublePredictionFuzzerAgent::getPrediction):
+        * runtime/DoublePredictionFuzzerAgent.h: Copied from Source/JavaScriptCore/interpreter/CallFrameInlines.h.
+        * runtime/JSGlobalObject.cpp:
+        (JSC::makeBoundFunction):
+        * runtime/Options.h:
+        * runtime/VM.cpp:
+        (JSC::VM::VM):
+
</ins><span class="cx"> 2019-04-04  Robin Morisset  <rmorisset@apple.com>
</span><span class="cx"> 
</span><span class="cx">         B3ReduceStrength should know that Mul distributes over Add and Sub
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreJavaScriptCorexcodeprojprojectpbxproj"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj (243924 => 243925)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj     2019-04-05 01:45:12 UTC (rev 243924)
+++ trunk/Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj        2019-04-05 04:17:44 UTC (rev 243925)
</span><span class="lines">@@ -4793,6 +4793,8 @@
</span><span class="cx">          E3F23A7C1ECF13E500978D99 /* SnippetParams.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = SnippetParams.h; sourceTree = "<group>"; };
</span><span class="cx">          E3F23A7D1ECF13E500978D99 /* SnippetReg.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = SnippetReg.h; sourceTree = "<group>"; };
</span><span class="cx">          E3F23A7E1ECF13E500978D99 /* SnippetSlowPathCalls.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = SnippetSlowPathCalls.h; sourceTree = "<group>"; };
</span><ins>+               E3FC25102256ECF400583518 /* DoublePredictionFuzzerAgent.cpp */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.cpp.cpp; path = DoublePredictionFuzzerAgent.cpp; sourceTree = "<group>"; };
+               E3FC25112256ECF400583518 /* DoublePredictionFuzzerAgent.h */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.c.h; path = DoublePredictionFuzzerAgent.h; sourceTree = "<group>"; };
</ins><span class="cx">           E3FF752F1D9CEA1200C7E16D /* DOMJITGetterSetter.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = DOMJITGetterSetter.h; sourceTree = "<group>"; };
</span><span class="cx">          E49DC14912EF261A00184A1F /* SourceProviderCacheItem.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = SourceProviderCacheItem.h; sourceTree = "<group>"; };
</span><span class="cx">          E49DC15112EF272200184A1F /* SourceProviderCache.h */ = {isa = PBXFileReference; fileEncoding = 4; lastKnownFileType = sourcecode.c.h; path = SourceProviderCache.h; sourceTree = "<group>"; };
</span><span class="lines">@@ -6772,6 +6774,8 @@
</span><span class="cx">                          E31618101EC5FE080006A218 /* DOMAnnotation.h */,
</span><span class="cx">                          E31618111EC5FE080006A218 /* DOMAttributeGetterSetter.cpp */,
</span><span class="cx">                          E31618121EC5FE080006A218 /* DOMAttributeGetterSetter.h */,
</span><ins>+                               E3FC25102256ECF400583518 /* DoublePredictionFuzzerAgent.cpp */,
+                               E3FC25112256ECF400583518 /* DoublePredictionFuzzerAgent.h */,
</ins><span class="cx">                           A70447EB17A0BD7000F5898E /* DumpContext.cpp */,
</span><span class="cx">                          A70447EC17A0BD7000F5898E /* DumpContext.h */,
</span><span class="cx">                          FE318FDD1CAC8C5300DFCC54 /* ECMAScriptSpecInternalFunctions.cpp */,
</span><span class="lines">@@ -8305,10 +8309,10 @@
</span><span class="cx">                          AD2FCBB31DB58DA400B3E736 /* WebAssemblyCompileErrorPrototype.h */,
</span><span class="cx">                          AD4937C91DDD27340077C807 /* WebAssemblyFunction.cpp */,
</span><span class="cx">                          AD4937CA1DDD27340077C807 /* WebAssemblyFunction.h */,
</span><ins>+                               521322431ECBCE8200F65615 /* WebAssemblyFunctionBase.cpp */,
+                               521322441ECBCE8200F65615 /* WebAssemblyFunctionBase.h */,
</ins><span class="cx">                           523FD88D225566C4003B3DCC /* WebAssemblyFunctionHeapCellType.cpp */,
</span><span class="cx">                          523FD88C225566C3003B3DCC /* WebAssemblyFunctionHeapCellType.h */,
</span><del>-                               521322431ECBCE8200F65615 /* WebAssemblyFunctionBase.cpp */,
-                               521322441ECBCE8200F65615 /* WebAssemblyFunctionBase.h */,
</del><span class="cx">                           AD2FCBB41DB58DA400B3E736 /* WebAssemblyInstanceConstructor.cpp */,
</span><span class="cx">                          AD2FCBB51DB58DA400B3E736 /* WebAssemblyInstanceConstructor.h */,
</span><span class="cx">                          AD2FCBB61DB58DA400B3E736 /* WebAssemblyInstancePrototype.cpp */,
</span><span class="lines">@@ -8611,6 +8615,7 @@
</span><span class="cx">                          0F6B8AD91C4EDDA200969052 /* B3DuplicateTails.h in Headers */,
</span><span class="cx">                          0FEC85C11BE167A00080FF74 /* B3Effects.h in Headers */,
</span><span class="cx">                          0F725CA81C503DED00AD943A /* B3EliminateCommonSubexpressions.h in Headers */,
</span><ins>+                               3395C70722555F6D00BDBFAD /* B3EliminateDeadCode.h in Headers */,
</ins><span class="cx">                           0F5BF1711F23A5A10029D91D /* B3EnsureLoopPreHeaders.h in Headers */,
</span><span class="cx">                          0F6971EA1D92F42400BA02A5 /* B3FenceValue.h in Headers */,
</span><span class="cx">                          0F6B8AE51C4EFE1700969052 /* B3FixSSA.h in Headers */,
</span><span class="lines">@@ -8624,7 +8629,6 @@
</span><span class="cx">                          0F5BF1641F2317120029D91D /* B3HoistLoopInvariantValues.h in Headers */,
</span><span class="cx">                          DC69B99D1D15F914002E3C00 /* B3InferSwitches.h in Headers */,
</span><span class="cx">                          0FEC85BA1BE1462F0080FF74 /* B3InsertionSet.h in Headers */,
</span><del>-                               523FD88E225566C9003B3DCC /* WebAssemblyFunctionHeapCellType.h in Headers */,
</del><span class="cx">                           0FEC85BB1BE1462F0080FF74 /* B3InsertionSetInlines.h in Headers */,
</span><span class="cx">                          0FDF67D21D9C6D27001B9825 /* B3Kind.h in Headers */,
</span><span class="cx">                          436E54531C468E7400B5AF73 /* B3LegalizeMemoryOffsets.h in Headers */,
</span><span class="lines">@@ -8817,7 +8821,6 @@
</span><span class="cx">                          473DA4A4764C45FE871B0485 /* DefinePropertyAttributes.h in Headers */,
</span><span class="cx">                          0FBB73BB1DEF8645002C009E /* DeleteAllCodeEffort.h in Headers */,
</span><span class="cx">                          0F96303C1D4192CD005609D9 /* DestructionMode.h in Headers */,
</span><del>-                               527CE35422555FE500C6F382 /* JSToWasmICCallee.h in Headers */,
</del><span class="cx">                           A77A423E17A0BBFD00A8DB81 /* DFGAbstractHeap.h in Headers */,
</span><span class="cx">                          A704D90317A0BAA8006BA554 /* DFGAbstractInterpreter.h in Headers */,
</span><span class="cx">                          0F5E0FD8207C72730097F0DE /* DFGAbstractInterpreterClobberState.h in Headers */,
</span><span class="lines">@@ -9091,7 +9094,6 @@
</span><span class="cx">                          0F48532A187DFDEC0083B687 /* FTLRecoveryOpcode.h in Headers */,
</span><span class="cx">                          0FCEFAAC1804C13E00472CE4 /* FTLSaveRestore.h in Headers */,
</span><span class="cx">                          0F25F1B2181635F300522F39 /* FTLSlowPathCall.h in Headers */,
</span><del>-                               3395C70722555F6D00BDBFAD /* B3EliminateDeadCode.h in Headers */,
</del><span class="cx">                           0F25F1B4181635F300522F39 /* FTLSlowPathCallKey.h in Headers */,
</span><span class="cx">                          E322E5A71DA644A8006E7709 /* FTLSnippetParams.h in Headers */,
</span><span class="cx">                          0F235BD717178E1C00690C7F /* FTLStackmapArgumentList.h in Headers */,
</span><span class="lines">@@ -9460,6 +9462,7 @@
</span><span class="cx">                          0F919D0D157EE0A2004A4E7D /* JSSymbolTableObject.h in Headers */,
</span><span class="cx">                          70ECA6061AFDBEA200449739 /* JSTemplateObjectDescriptor.h in Headers */,
</span><span class="cx">                          AD5C36EA1F75AD6A000BCAAF /* JSToWasm.h in Headers */,
</span><ins>+                               527CE35422555FE500C6F382 /* JSToWasmICCallee.h in Headers */,
</ins><span class="cx">                           BC18C42A0E16F5CD00B34460 /* JSType.h in Headers */,
</span><span class="cx">                          53486BB71C1795C300F6F3AF /* JSTypedArray.h in Headers */,
</span><span class="cx">                          0F2B66FB17B6B5AB00A7AE3F /* JSTypedArrayConstructors.h in Headers */,
</span><span class="lines">@@ -9936,6 +9939,7 @@
</span><span class="cx">                          AD2FCC171DB59CB200B3E736 /* WebAssemblyCompileErrorPrototype.lut.h in Headers */,
</span><span class="cx">                          AD4937D41DDD27DE0077C807 /* WebAssemblyFunction.h in Headers */,
</span><span class="cx">                          521322461ECBCE8200F65615 /* WebAssemblyFunctionBase.h in Headers */,
</span><ins>+                               523FD88E225566C9003B3DCC /* WebAssemblyFunctionHeapCellType.h in Headers */,
</ins><span class="cx">                           AD2FCBF11DB58DAD00B3E736 /* WebAssemblyInstanceConstructor.h in Headers */,
</span><span class="cx">                          AD2FCC181DB59CB200B3E736 /* WebAssemblyInstanceConstructor.lut.h in Headers */,
</span><span class="cx">                          AD2FCBF31DB58DAD00B3E736 /* WebAssemblyInstancePrototype.h in Headers */,
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreSourcestxt"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/Sources.txt (243924 => 243925)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/Sources.txt  2019-04-05 01:45:12 UTC (rev 243924)
+++ trunk/Source/JavaScriptCore/Sources.txt     2019-04-05 04:17:44 UTC (rev 243925)
</span><span class="lines">@@ -745,6 +745,7 @@
</span><span class="cx"> runtime/DirectArgumentsOffset.cpp
</span><span class="cx"> runtime/DirectEvalExecutable.cpp
</span><span class="cx"> runtime/DisallowVMReentry.cpp
</span><ins>+runtime/DoublePredictionFuzzerAgent.cpp
</ins><span class="cx"> runtime/DumpContext.cpp
</span><span class="cx"> runtime/ECMAScriptSpecInternalFunctions.cpp
</span><span class="cx"> runtime/Error.cpp
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreinterpreterCallFrameInlinesh"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/interpreter/CallFrameInlines.h (243924 => 243925)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/interpreter/CallFrameInlines.h       2019-04-05 01:45:12 UTC (rev 243924)
+++ trunk/Source/JavaScriptCore/interpreter/CallFrameInlines.h  2019-04-05 04:17:44 UTC (rev 243925)
</span><span class="lines">@@ -26,6 +26,8 @@
</span><span class="cx"> #pragma once
</span><span class="cx"> 
</span><span class="cx"> #include "CallFrame.h"
</span><ins>+#include "JSCallee.h"
+#include "JSGlobalObject.h"
</ins><span class="cx"> 
</span><span class="cx"> namespace JSC {
</span><span class="cx"> 
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreruntimeDoublePredictionFuzzerAgentcppfromrev243924trunkSourceJavaScriptCoreinterpreterCallFrameInlinesh"></a>
<div class="copfile"><h4>Copied: trunk/Source/JavaScriptCore/runtime/DoublePredictionFuzzerAgent.cpp (from rev 243924, trunk/Source/JavaScriptCore/interpreter/CallFrameInlines.h) (0 => 243925)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/runtime/DoublePredictionFuzzerAgent.cpp                              (rev 0)
+++ trunk/Source/JavaScriptCore/runtime/DoublePredictionFuzzerAgent.cpp 2019-04-05 04:17:44 UTC (rev 243925)
</span><span class="lines">@@ -0,0 +1,42 @@
</span><ins>+/*
+ * Copyright (C) 2019 Apple Inc. All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ *    notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ *    notice, this list of conditions and the following disclaimer in the
+ *    documentation and/or other materials provided with the distribution.
+ *
+ * THIS SOFTWARE IS PROVIDED BY APPLE INC. ``AS IS'' AND ANY
+ * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
+ * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL APPLE INC. OR
+ * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
+ * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
+ * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
+ * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY
+ * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+
+#include "config.h"
+#include "DoublePredictionFuzzerAgent.h"
+
+namespace JSC {
+
+DoublePredictionFuzzerAgent::DoublePredictionFuzzerAgent(VM&)
+{
+}
+
+SpeculatedType DoublePredictionFuzzerAgent::getPrediction(CodeBlock*, const CodeOrigin&, SpeculatedType original)
+{
+    if (original && mergeSpeculations(original, SpecBytecodeNumber) == SpecBytecodeNumber)
+        return SpecBytecodeDouble;
+    return original;
+}
+
+} // namespace JSC
</ins></span></pre></div>
<a id="trunkSourceJavaScriptCoreruntimeDoublePredictionFuzzerAgenthfromrev243924trunkSourceJavaScriptCoreinterpreterCallFrameInlinesh"></a>
<div class="copfile"><h4>Copied: trunk/Source/JavaScriptCore/runtime/DoublePredictionFuzzerAgent.h (from rev 243924, trunk/Source/JavaScriptCore/interpreter/CallFrameInlines.h) (0 => 243925)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/runtime/DoublePredictionFuzzerAgent.h                                (rev 0)
+++ trunk/Source/JavaScriptCore/runtime/DoublePredictionFuzzerAgent.h   2019-04-05 04:17:44 UTC (rev 243925)
</span><span class="lines">@@ -0,0 +1,41 @@
</span><ins>+/*
+ * Copyright (C) 2019 Apple Inc. All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ *    notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ *    notice, this list of conditions and the following disclaimer in the
+ *    documentation and/or other materials provided with the distribution.
+ *
+ * THIS SOFTWARE IS PROVIDED BY APPLE INC. ``AS IS'' AND ANY
+ * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
+ * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL APPLE INC. OR
+ * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
+ * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
+ * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
+ * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY
+ * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+
+#pragma once
+
+#include "FuzzerAgent.h"
+
+namespace JSC {
+
+class VM;
+
+class DoublePredictionFuzzerAgent final : public FuzzerAgent {
+public:
+    DoublePredictionFuzzerAgent(VM&);
+
+    SpeculatedType getPrediction(CodeBlock*, const CodeOrigin&, SpeculatedType) override;
+};
+
+} // namespace JSC
</ins></span></pre></div>
<a id="trunkSourceJavaScriptCoreruntimeJSGlobalObjectcpp"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/runtime/JSGlobalObject.cpp (243924 => 243925)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/runtime/JSGlobalObject.cpp   2019-04-05 01:45:12 UTC (rev 243924)
+++ trunk/Source/JavaScriptCore/runtime/JSGlobalObject.cpp      2019-04-05 04:17:44 UTC (rev 243925)
</span><span class="lines">@@ -238,16 +238,26 @@
</span><span class="cx"> static EncodedJSValue JSC_HOST_CALL makeBoundFunction(ExecState* exec)
</span><span class="cx"> {
</span><span class="cx">     VM& vm = exec->vm();
</span><ins>+    auto scope = DECLARE_THROW_SCOPE(vm);
+
</ins><span class="cx">     JSGlobalObject* globalObject = exec->lexicalGlobalObject();
</span><span class="cx"> 
</span><span class="cx">     JSObject* target = asObject(exec->uncheckedArgument(0));
</span><span class="cx">     JSValue boundThis = exec->uncheckedArgument(1);
</span><span class="cx">     JSValue boundArgs = exec->uncheckedArgument(2);
</span><del>-    JSValue length = exec->uncheckedArgument(3);
-    JSString* name = asString(exec->uncheckedArgument(4));
</del><ins>+    JSValue lengthValue = exec->uncheckedArgument(3);
+    JSString* nameString = asString(exec->uncheckedArgument(4));
</ins><span class="cx"> 
</span><del>-    return JSValue::encode(JSBoundFunction::create(
-        vm, exec, globalObject, target, boundThis, boundArgs.isCell() ? jsCast<JSArray*>(boundArgs) : nullptr, length.asInt32(), name->value(exec)));
</del><ins>+    ASSERT(lengthValue.isAnyInt());
+    ASSERT(lengthValue.asAnyInt() <= INT32_MAX);
+    ASSERT(lengthValue.asAnyInt() >= INT32_MIN);
+    int32_t length = lengthValue.toInt32(exec);
+    scope.assertNoException();
+
+    String name = nameString->value(exec);
+    RETURN_IF_EXCEPTION(scope, { });
+
+    RELEASE_AND_RETURN(scope, JSValue::encode(JSBoundFunction::create(vm, exec, globalObject, target, boundThis, boundArgs.isCell() ? jsCast<JSArray*>(boundArgs) : nullptr, length, WTFMove(name))));
</ins><span class="cx"> }
</span><span class="cx"> 
</span><span class="cx"> static EncodedJSValue JSC_HOST_CALL hasOwnLengthProperty(ExecState* exec)
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreruntimeOptionsh"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/runtime/Options.h (243924 => 243925)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/runtime/Options.h    2019-04-05 01:45:12 UTC (rev 243924)
+++ trunk/Source/JavaScriptCore/runtime/Options.h       2019-04-05 04:17:44 UTC (rev 243925)
</span><span class="lines">@@ -437,6 +437,7 @@
</span><span class="cx">     v(bool, useRandomizingFuzzerAgent, false, Normal, nullptr) \
</span><span class="cx">     v(unsigned, seedOfRandomizingFuzzerAgent, 1, Normal, nullptr) \
</span><span class="cx">     v(bool, dumpRandomizingFuzzerAgentPredictions, false, Normal, nullptr) \
</span><ins>+    v(bool, useDoublePredictionFuzzerAgent, false, Normal, nullptr) \
</ins><span class="cx">     \
</span><span class="cx">     v(bool, logPhaseTimes, false, Normal, nullptr) \
</span><span class="cx">     v(double, rareBlockPenalty, 0.001, Normal, nullptr) \
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreruntimeVMcpp"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/runtime/VM.cpp (243924 => 243925)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/runtime/VM.cpp       2019-04-05 01:45:12 UTC (rev 243924)
+++ trunk/Source/JavaScriptCore/runtime/VM.cpp  2019-04-05 04:17:44 UTC (rev 243925)
</span><span class="lines">@@ -41,6 +41,7 @@
</span><span class="cx"> #include "DFGWorklist.h"
</span><span class="cx"> #include "DirectEvalExecutable.h"
</span><span class="cx"> #include "Disassembler.h"
</span><ins>+#include "DoublePredictionFuzzerAgent.h"
</ins><span class="cx"> #include "Error.h"
</span><span class="cx"> #include "ErrorConstructor.h"
</span><span class="cx"> #include "ErrorInstance.h"
</span><span class="lines">@@ -459,8 +460,11 @@
</span><span class="cx">         m_samplingProfiler->start();
</span><span class="cx">     }
</span><span class="cx"> #endif // ENABLE(SAMPLING_PROFILER)
</span><ins>+
</ins><span class="cx">     if (Options::useRandomizingFuzzerAgent())
</span><span class="cx">         setFuzzerAgent(std::make_unique<RandomizingFuzzerAgent>(*this));
</span><ins>+    else if (Options::useDoublePredictionFuzzerAgent())
+        setFuzzerAgent(std::make_unique<DoublePredictionFuzzerAgent>(*this));
</ins><span class="cx"> 
</span><span class="cx">     if (Options::alwaysGeneratePCToCodeOriginMap())
</span><span class="cx">         setShouldBuildPCToCodeOriginMapping();
</span></span></pre>
</div>
</div>

</body>
</html>