Summary: | [JSC] Use unalignedLoad for JSRopeString fiber accesses | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Yusuke Suzuki <ysuzuki> | ||||||
Component: | New Bugs | Assignee: | Yusuke Suzuki <ysuzuki> | ||||||
Status: | RESOLVED FIXED | ||||||||
Severity: | Normal | CC: | ews-watchlist, keith_miller, mark.lam, msaboff, saam, tzagallo, webkit-bug-importer | ||||||
Priority: | P2 | Keywords: | InRadar | ||||||
Version: | WebKit Nightly Build | ||||||||
Hardware: | Unspecified | ||||||||
OS: | Unspecified | ||||||||
Attachments: |
|
Description
Yusuke Suzuki
2019-07-25 18:46:59 PDT
Created attachment 374930 [details]
Patch
Created attachment 374934 [details]
Patch
Comment on attachment 374934 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=374934&action=review r=me > Source/JavaScriptCore/heap/MarkedBlock.h:305 > + // Some of JSCell types assume that the last JSCell in a MarkedBlock has a subsequent memory region (Footer) that can still safely accesible. /accesible/accessed/ > Source/JavaScriptCore/heap/MarkedBlock.h:306 > + // For example, JSRopeString assumes that it can safely access some subsquent bytes of JSRopeString cell. I suggest rephrasing "some subsquent bytes of JSRopeString cell" as "up to 2 bytes beyond the JSRopeString cell". Comment on attachment 374934 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=374934&action=review >> Source/JavaScriptCore/heap/MarkedBlock.h:305 >> + // Some of JSCell types assume that the last JSCell in a MarkedBlock has a subsequent memory region (Footer) that can still safely accesible. > > /accesible/accessed/ Fixed. >> Source/JavaScriptCore/heap/MarkedBlock.h:306 >> + // For example, JSRopeString assumes that it can safely access some subsquent bytes of JSRopeString cell. > > I suggest rephrasing "some subsquent bytes of JSRopeString cell" as "up to 2 bytes beyond the JSRopeString cell". Fixed. Committed r247854: <https://trac.webkit.org/changeset/247854> |