Title: [295181] branches/safari-613-branch/Source/_javascript_Core
- Revision
- 295181
- Author
- [email protected]
- Date
- 2022-06-02 23:45:22 -0700 (Thu, 02 Jun 2022)
Log Message
Cherry-pick 1d5e3b70369b. rdar://problem/93369102
[JSC] Always have non nullptr for WebAssembly.Memory buffer
https://bugs.webkit.org/show_bug.cgi?id=240510
Reviewed by Mark Lam.
This patch adds CagedUniquePtr to allocate a pointer for that.
* Source/_javascript_Core/runtime/ArrayBuffer.cpp:
(JSC::ArrayBuffer::makeShared):
* Source/_javascript_Core/wasm/js/JSWebAssemblyMemory.cpp:
(JSC::JSWebAssemblyMemory::buffer):
Canonical link: https://commits.webkit.org/250639@main
git-svn-id: https://svn.webkit.org/repository/webkit/trunk@294319 268f45cc-cd09-0410-ab3c-d52691b4dbfc
Modified Paths
Diff
Modified: branches/safari-613-branch/Source/_javascript_Core/runtime/ArrayBuffer.cpp (295180 => 295181)
--- branches/safari-613-branch/Source/_javascript_Core/runtime/ArrayBuffer.cpp 2022-06-03 06:45:19 UTC (rev 295180)
+++ branches/safari-613-branch/Source/_javascript_Core/runtime/ArrayBuffer.cpp 2022-06-03 06:45:22 UTC (rev 295181)
@@ -332,6 +332,7 @@
{
m_contents.makeShared();
m_locked = true;
+ ASSERT(!isDetached());
}
void ArrayBuffer::makeWasmMemory()
Modified: branches/safari-613-branch/Source/_javascript_Core/wasm/js/JSWebAssemblyMemory.cpp (295180 => 295181)
--- branches/safari-613-branch/Source/_javascript_Core/wasm/js/JSWebAssemblyMemory.cpp 2022-06-03 06:45:19 UTC (rev 295180)
+++ branches/safari-613-branch/Source/_javascript_Core/wasm/js/JSWebAssemblyMemory.cpp 2022-06-03 06:45:22 UTC (rev 295181)
@@ -90,8 +90,23 @@
}
Ref<Wasm::MemoryHandle> protectedHandle = m_memory->handle();
- auto destructor = createSharedTask<void(void*)>([protectedHandle = WTFMove(protectedHandle)] (void*) { });
- m_buffer = ArrayBuffer::createFromBytes(m_memory->memory(), m_memory->size(), WTFMove(destructor));
+ CagedUniquePtr<Gigacage::Primitive, uint8_t> pointerForEmpty;
+
+ void* memory = m_memory->memory();
+ size_t size = m_memory->size();
+ if (!memory) {
+ ASSERT(!size);
+ constexpr unsigned allocationSize = 1;
+ pointerForEmpty = CagedUniquePtr<Gigacage::Primitive, uint8_t>::tryCreate(allocationSize);
+ if (!pointerForEmpty) {
+ throwOutOfMemoryError(globalObject, throwScope);
+ return nullptr;
+ }
+ memory = pointerForEmpty.get(allocationSize);
+ }
+ ASSERT(memory);
+ auto destructor = createSharedTask<void(void*)>([protectedHandle = WTFMove(protectedHandle), pointerForEmpty = WTFMove(pointerForEmpty)] (void*) { });
+ m_buffer = ArrayBuffer::createFromBytes(memory, size, WTFMove(destructor));
m_buffer->makeWasmMemory();
if (m_memory->sharingMode() == Wasm::MemorySharingMode::Shared)
m_buffer->makeShared();
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes