Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: 94de22268a7e3bdb387acaa5f6de0130d027bdc3
https://github.com/WebKit/WebKit/commit/94de22268a7e3bdb387acaa5f6de0130d027bdc3
Author: Shu-yu Guo <[email protected]>
Date: 2026-10-02 (Fri, 02 Oct 2026)
Changed paths:
A JSTests/stress/new-shared-array-buffer-cross-realm.js
M Source/JavaScriptCore/dfg/DFGOperations.cpp
M Source/JavaScriptCore/runtime/JSArrayBufferConstructor.cpp
M Source/JavaScriptCore/runtime/JSArrayBufferConstructor.h
Log Message:
-----------
[JSC] Use the right realm in ArrayBuffer constructor in DFG
https://bugs.webkit.org/show_bug.cgi?id=326133
rdar://188994606
Reviewed by Dan Hecht.
Builtin constructors like ArrayBuffer need to run in the realm in which they
were created. DFG speculatively bakes in the right structure on the fast path,
so take the realm from that structure instead of the caller, which may be
different.
Test: JSTests/stress/new-shared-array-buffer-cross-realm.js
* Source/JavaScriptCore/dfg/DFGOperations.cpp:
(JSC::DFG::JSC_DEFINE_JIT_OPERATION):
* Source/JavaScriptCore/runtime/JSArrayBufferConstructor.cpp:
(JSC::constructArrayBufferWithSize):
* Source/JavaScriptCore/runtime/JSArrayBufferConstructor.h:
* JSTests/stress/new-shared-array-buffer-cross-realm.js: Added.
(newInt32):
(newUntyped):
Canonical link: https://commits.webkit.org/322572@main
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications