Bug 216904

Summary: %ArrayIteratorPrototype%.next must check for detached buffers
Product: WebKit Reporter: Ross Kirsling <ross.kirsling>
Component: New BugsAssignee: Ross Kirsling <ross.kirsling>
Status: RESOLVED FIXED    
Severity: Normal CC: ews-watchlist, joepeck, keith_miller, mark.lam, msaboff, saam, tzagallo, webkit-bug-importer, ysuzuki
Priority: P2 Keywords: InRadar
Version: WebKit Nightly Build   
Hardware: Unspecified   
OS: Unspecified   
Attachments:
Description Flags
Patch
none
Patch none

Ross Kirsling
Reported 2020-09-23 16:00:46 PDT
%ArrayIteratorPrototype%.next must check for detached buffers
Attachments
Patch (8.34 KB, patch)
2020-09-23 16:05 PDT, Ross Kirsling
no flags
Patch (8.93 KB, patch)
2020-09-23 18:47 PDT, Ross Kirsling
no flags
Ross Kirsling
Comment 1 2020-09-23 16:05:30 PDT
Yusuke Suzuki
Comment 2 2020-09-23 16:31:55 PDT
Comment on attachment 409513 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=409513&action=review > Source/JavaScriptCore/builtins/ArrayIteratorPrototype.js:37 > + if (@isTypedArrayView(array) && @isNeutered(array)) > + @throwTypeError("Underlying ArrayBuffer has been detached from the view"); > + JSC has fast path for array iteration in all tiers. Can you check whether this is correctly handled in this iteration protocol? For example, DFG has inlined DFG codes for this next function in DFGByteCodeParser.
Ross Kirsling
Comment 3 2020-09-23 18:47:04 PDT
Ross Kirsling
Comment 4 2020-09-23 18:48:12 PDT
(In reply to Yusuke Suzuki from comment #2) > Comment on attachment 409513 [details] > Patch > > View in context: > https://bugs.webkit.org/attachment.cgi?id=409513&action=review > > > Source/JavaScriptCore/builtins/ArrayIteratorPrototype.js:37 > > + if (@isTypedArrayView(array) && @isNeutered(array)) > > + @throwTypeError("Underlying ArrayBuffer has been detached from the view"); > > + > > JSC has fast path for array iteration in all tiers. Can you check whether > this is correctly handled in this iteration protocol? > For example, DFG has inlined DFG codes for this next function in > DFGByteCodeParser. Seems like this isn't an issue after all, but I've added a test to demonstrate / ensure it.
EWS
Comment 5 2020-09-23 23:15:40 PDT
Committed r267519: <https://trac.webkit.org/changeset/267519> All reviewed patches have been landed. Closing bug and clearing flags on attachment 409521 [details].
Radar WebKit Bug Importer
Comment 6 2020-09-23 23:16:19 PDT
Note You need to log in before you can comment on or make changes to this bug.