Bug 153897

Summary: REGRESSION(192409): Cannot rely on add32() to zero-extend
Product: WebKit Reporter: Filip Pizlo <fpizlo>
Component: JavaScriptCoreAssignee: Nobody <webkit-unassigned>
Severity: Normal    
Priority: P2    
Version: WebKit Nightly Build   
Hardware: All   
OS: All   

Description Filip Pizlo 2016-02-04 15:05:07 PST
Callers of add32() and other 32-bit arithmetic ops rely on the fact that the destination register is zero-extended.  The optimizations in r192409 broke this feature, and this causes crashes on some obscure code.
Comment 1 Filip Pizlo 2016-02-04 15:16:34 PST
Comment 2 Filip Pizlo 2016-02-04 15:20:26 PST
I tried writing a test, but actually hitting this issue is sooooper hard.
Comment 3 Filip Pizlo 2016-02-04 15:23:58 PST
Landed in http://trac.webkit.org/changeset/196152