Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 94de22268a7e3bdb387acaa5f6de0130d027bdc3
      
https://github.com/WebKit/WebKit/commit/94de22268a7e3bdb387acaa5f6de0130d027bdc3
  Author: Shu-yu Guo <[email protected]>
  Date:   2026-10-02 (Fri, 02 Oct 2026)

  Changed paths:
    A JSTests/stress/new-shared-array-buffer-cross-realm.js
    M Source/JavaScriptCore/dfg/DFGOperations.cpp
    M Source/JavaScriptCore/runtime/JSArrayBufferConstructor.cpp
    M Source/JavaScriptCore/runtime/JSArrayBufferConstructor.h

  Log Message:
  -----------
  [JSC] Use the right realm in ArrayBuffer constructor in DFG
https://bugs.webkit.org/show_bug.cgi?id=326133
rdar://188994606

Reviewed by Dan Hecht.

Builtin constructors like ArrayBuffer need to run in the realm in which they
were created. DFG speculatively bakes in the right structure on the fast path,
so take the realm from that structure instead of the caller, which may be
different.

Test: JSTests/stress/new-shared-array-buffer-cross-realm.js

* Source/JavaScriptCore/dfg/DFGOperations.cpp:
(JSC::DFG::JSC_DEFINE_JIT_OPERATION):
* Source/JavaScriptCore/runtime/JSArrayBufferConstructor.cpp:
(JSC::constructArrayBufferWithSize):
* Source/JavaScriptCore/runtime/JSArrayBufferConstructor.h:
* JSTests/stress/new-shared-array-buffer-cross-realm.js: Added.
(newInt32):
(newUntyped):

Canonical link: https://commits.webkit.org/322572@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to