Title: [290269] trunk
Revision
290269
Author
ysuz...@apple.com
Date
2022-02-21 14:06:36 -0800 (Mon, 21 Feb 2022)

Log Message

[JSC] ShadowRealm wrapArgument should check exceptions
https://bugs.webkit.org/show_bug.cgi?id=236984
JSTests:

Reviewed by Alexey Shvayka.

* stress/exception-in-wrap-argument-for-shadow-realm.js: Added.
(shouldThrow):

Source/_javascript_Core:

rdar://89226554

Reviewed by Alexey Shvayka.

We should check exceptions after wrapArgument.

* runtime/JSRemoteFunction.cpp:
(JSC::JSC_DEFINE_HOST_FUNCTION):

Modified Paths

Added Paths

Diff

Modified: trunk/JSTests/ChangeLog (290268 => 290269)


--- trunk/JSTests/ChangeLog	2022-02-21 22:00:19 UTC (rev 290268)
+++ trunk/JSTests/ChangeLog	2022-02-21 22:06:36 UTC (rev 290269)
@@ -1,5 +1,15 @@
 2022-02-21  Yusuke Suzuki  <ysuz...@apple.com>
 
+        [JSC] ShadowRealm wrapArgument should check exceptions
+        https://bugs.webkit.org/show_bug.cgi?id=236984
+
+        Reviewed by Alexey Shvayka.
+
+        * stress/exception-in-wrap-argument-for-shadow-realm.js: Added.
+        (shouldThrow):
+
+2022-02-21  Yusuke Suzuki  <ysuz...@apple.com>
+
         [JSC] Update test262
         https://bugs.webkit.org/show_bug.cgi?id=236990
 

Added: trunk/JSTests/stress/exception-in-wrap-argument-for-shadow-realm.js (0 => 290269)


--- trunk/JSTests/stress/exception-in-wrap-argument-for-shadow-realm.js	                        (rev 0)
+++ trunk/JSTests/stress/exception-in-wrap-argument-for-shadow-realm.js	2022-02-21 22:06:36 UTC (rev 290269)
@@ -0,0 +1,20 @@
+function shouldThrow(func, errorMessage) {
+    var errorThrown = false;
+    var error = null;
+    try {
+        func();
+    } catch (e) {
+        errorThrown = true;
+        error = e;
+    }
+    if (!errorThrown)
+        throw new Error('not thrown');
+    if (String(error) !== errorMessage)
+        throw new Error(`bad error: ${String(error)}`);
+}
+
+shouldThrow(() => {
+    let realm = new ShadowRealm();
+    let f = realm.evaluate(`new Proxy(()=>{}, {});`);
+    f({});
+}, `TypeError: value passing between realms must be callable or primitive`);

Modified: trunk/Source/_javascript_Core/ChangeLog (290268 => 290269)


--- trunk/Source/_javascript_Core/ChangeLog	2022-02-21 22:00:19 UTC (rev 290268)
+++ trunk/Source/_javascript_Core/ChangeLog	2022-02-21 22:06:36 UTC (rev 290269)
@@ -1,5 +1,18 @@
 2022-02-21  Yusuke Suzuki  <ysuz...@apple.com>
 
+        [JSC] ShadowRealm wrapArgument should check exceptions
+        https://bugs.webkit.org/show_bug.cgi?id=236984
+        rdar://89226554
+
+        Reviewed by Alexey Shvayka.
+
+        We should check exceptions after wrapArgument.
+
+        * runtime/JSRemoteFunction.cpp:
+        (JSC::JSC_DEFINE_HOST_FUNCTION):
+
+2022-02-21  Yusuke Suzuki  <ysuz...@apple.com>
+
         [JSC] Add explicit exception check after appendWithoutSideEffects
         https://bugs.webkit.org/show_bug.cgi?id=236986
         rdar://88258776

Modified: trunk/Source/_javascript_Core/runtime/JSRemoteFunction.cpp (290268 => 290269)


--- trunk/Source/_javascript_Core/runtime/JSRemoteFunction.cpp	2022-02-21 22:00:19 UTC (rev 290268)
+++ trunk/Source/_javascript_Core/runtime/JSRemoteFunction.cpp	2022-02-21 22:06:36 UTC (rev 290269)
@@ -126,6 +126,7 @@
     MarkedArgumentBuffer args;
     for (unsigned i = 0; i < callFrame->argumentCount(); ++i) {
         JSValue wrappedValue = wrapArgument(globalObject, targetGlobalObject, callFrame->uncheckedArgument(i));
+        RETURN_IF_EXCEPTION(scope, { });
         args.append(wrappedValue);
     }
     if (UNLIKELY(args.hasOverflowed())) {
_______________________________________________
webkit-changes mailing list
webkit-changes@lists.webkit.org
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to