Skip to content

Commit 5d3535b

Browse files
author
Robert Fancsik
committed
Accessors should be kept alive during their invocation
This patch fixes #4900. JerryScript-DCO-1.0-Signed-off-by: Robert Fancsik [email protected]
1 parent 49a1a80 commit 5d3535b

File tree

6 files changed

+104
-30
lines changed

6 files changed

+104
-30
lines changed

jerry-core/ecma/operations/ecma-function-object.c

Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1389,6 +1389,55 @@ ecma_op_function_call_bound (ecma_object_t *func_obj_p, /**< Function object */
13891389
return ret_value;
13901390
} /* ecma_op_function_call_bound */
13911391

1392+
/**
1393+
* Invoke accessor getter function
1394+
*
1395+
* @return ecma value
1396+
* Returned value must be freed with ecma_free_value
1397+
*/
1398+
extern inline ecma_value_t JERRY_ATTR_ALWAYS_INLINE
1399+
ecma_op_invoke_getter (ecma_getter_setter_pointers_t *get_set_pair_p, /**< accessor pair */
1400+
ecma_value_t this_value) /**< 'this' argument's value */
1401+
{
1402+
if (get_set_pair_p->getter_cp == JMEM_CP_NULL)
1403+
{
1404+
return ECMA_VALUE_UNDEFINED;
1405+
}
1406+
1407+
ecma_object_t *getter_p = ECMA_GET_NON_NULL_POINTER (ecma_object_t, get_set_pair_p->getter_cp);
1408+
ecma_ref_object (getter_p);
1409+
1410+
ecma_value_t result = ecma_op_function_call (getter_p, this_value, NULL, 0);
1411+
ecma_deref_object (getter_p);
1412+
1413+
return result;
1414+
} /* ecma_op_invoke_getter */
1415+
1416+
/**
1417+
* Invoke accessor setter function
1418+
*
1419+
* @return ecma value
1420+
* Returned value must be freed with ecma_free_value
1421+
*/
1422+
extern inline ecma_value_t JERRY_ATTR_ALWAYS_INLINE
1423+
ecma_op_invoke_setter (ecma_getter_setter_pointers_t *get_set_pair_p, /**< accessor pair */
1424+
ecma_value_t this_value, /**< 'this' argument's value */
1425+
ecma_value_t value) /**< value to set */
1426+
{
1427+
if (get_set_pair_p->setter_cp == JMEM_CP_NULL)
1428+
{
1429+
return ECMA_VALUE_UNDEFINED;
1430+
}
1431+
1432+
ecma_object_t *setter_p = ECMA_GET_NON_NULL_POINTER (ecma_object_t, get_set_pair_p->setter_cp);
1433+
ecma_ref_object (setter_p);
1434+
1435+
ecma_value_t result = ecma_op_function_call (setter_p, this_value, &value, 1);
1436+
ecma_deref_object (setter_p);
1437+
1438+
return result;
1439+
} /* ecma_op_invoke_setter */
1440+
13921441
/**
13931442
* General [[Call]] implementation
13941443
*

jerry-core/ecma/operations/ecma-function-object.h

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -84,6 +84,11 @@ ecma_object_t *ecma_op_get_prototype_from_constructor (ecma_object_t *ctor_obj_p
8484

8585
ecma_value_t ecma_op_function_has_instance (ecma_object_t *func_obj_p, ecma_value_t value);
8686

87+
ecma_value_t ecma_op_invoke_getter (ecma_getter_setter_pointers_t *get_set_pair_p, ecma_value_t this_value);
88+
89+
ecma_value_t
90+
ecma_op_invoke_setter (ecma_getter_setter_pointers_t *get_set_pair_p, ecma_value_t this_value, ecma_value_t value);
91+
8792
ecma_value_t ecma_op_function_validated_call (ecma_value_t callee,
8893
ecma_value_t this_arg_value,
8994
const ecma_value_t *arguments_list_p,

jerry-core/ecma/operations/ecma-objects.c

Lines changed: 5 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -748,16 +748,7 @@ ecma_op_object_find_own (ecma_value_t base_value, /**< base value */
748748
return ecma_fast_copy_value (prop_value_p->value);
749749
}
750750

751-
ecma_getter_setter_pointers_t *get_set_pair_p = ecma_get_named_accessor_property (prop_value_p);
752-
753-
if (get_set_pair_p->getter_cp == JMEM_CP_NULL)
754-
{
755-
return ECMA_VALUE_UNDEFINED;
756-
}
757-
758-
ecma_object_t *getter_p = ECMA_GET_NON_NULL_POINTER (ecma_object_t, get_set_pair_p->getter_cp);
759-
760-
return ecma_op_function_call (getter_p, base_value, NULL, 0);
751+
return ecma_op_invoke_getter (ecma_get_named_accessor_property (prop_value_p), base_value);
761752
} /* ecma_op_object_find_own */
762753

763754
/**
@@ -1532,6 +1523,7 @@ ecma_op_object_put_with_receiver (ecma_object_t *object_p, /**< the object */
15321523
}
15331524
}
15341525

1526+
ecma_getter_setter_pointers_t *get_set_pair_p = NULL;
15351527
jmem_cpointer_t setter_cp = JMEM_CP_NULL;
15361528

15371529
if (property_p != NULL)
@@ -1557,7 +1549,6 @@ ecma_op_object_put_with_receiver (ecma_object_t *object_p, /**< the object */
15571549
}
15581550
else
15591551
{
1560-
ecma_getter_setter_pointers_t *get_set_pair_p;
15611552
get_set_pair_p = ecma_get_named_accessor_property (ECMA_PROPERTY_VALUE_PTR (property_p));
15621553
setter_cp = get_set_pair_p->setter_cp;
15631554
}
@@ -1598,7 +1589,8 @@ ecma_op_object_put_with_receiver (ecma_object_t *object_p, /**< the object */
15981589

15991590
if (!(inherited_property & ECMA_PROPERTY_FLAG_DATA))
16001591
{
1601-
setter_cp = ecma_get_named_accessor_property (property_ref.value_p)->setter_cp;
1592+
get_set_pair_p = ecma_get_named_accessor_property (property_ref.value_p);
1593+
setter_cp = get_set_pair_p->setter_cp;
16021594
create_new_property = false;
16031595
break;
16041596
}
@@ -1673,8 +1665,7 @@ ecma_op_object_put_with_receiver (ecma_object_t *object_p, /**< the object */
16731665
return ecma_raise_readonly_assignment (property_name_p, is_throw);
16741666
}
16751667

1676-
ecma_value_t ret_value =
1677-
ecma_op_function_call (ECMA_GET_NON_NULL_POINTER (ecma_object_t, setter_cp), receiver, &value, 1);
1668+
ecma_value_t ret_value = ecma_op_invoke_setter (get_set_pair_p, receiver, value);
16781669

16791670
if (!ECMA_IS_VALUE_ERROR (ret_value))
16801671
{

jerry-core/ecma/operations/ecma-reference.c

Lines changed: 2 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -371,17 +371,8 @@ ecma_op_resolve_reference_value (ecma_object_t *lex_env_p, /**< starting lexical
371371
return ecma_fast_copy_value (prop_value_p->value);
372372
}
373373

374-
ecma_getter_setter_pointers_t *get_set_pair_p = ecma_get_named_accessor_property (prop_value_p);
375-
376-
if (get_set_pair_p->getter_cp == JMEM_CP_NULL)
377-
{
378-
return ECMA_VALUE_UNDEFINED;
379-
}
380-
381-
ecma_object_t *getter_p = ECMA_GET_NON_NULL_POINTER (ecma_object_t, get_set_pair_p->getter_cp);
382-
383-
ecma_value_t base_value = ecma_make_object_value (binding_obj_p);
384-
return ecma_op_function_call (getter_p, base_value, NULL, 0);
374+
return ecma_op_invoke_getter (ecma_get_named_accessor_property (prop_value_p),
375+
ecma_make_object_value (binding_obj_p));
385376
}
386377
#endif /* JERRY_LCACHE */
387378
}

jerry-core/vm/opcodes.c

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1429,9 +1429,7 @@ opfunc_private_set (ecma_value_t base, /**< this object */
14291429
return ecma_raise_type_error (ECMA_ERR_PRIVATE_FIELD_WAS_DEFINED_WITHOUT_A_SETTER);
14301430
}
14311431

1432-
ecma_object_t *setter_p = ECMA_GET_NON_NULL_POINTER (ecma_object_t, get_set_pair_p->setter_cp);
1433-
1434-
return ecma_op_function_call (setter_p, base, &value, 1);
1432+
return ecma_op_invoke_setter (get_set_pair_p, base, value);
14351433
} /* opfunc_private_set */
14361434

14371435
/**
@@ -1479,8 +1477,7 @@ opfunc_private_get (ecma_value_t base, /**< this object */
14791477
}
14801478
else
14811479
{
1482-
ecma_object_t *getter_p = ECMA_GET_NON_NULL_POINTER (ecma_object_t, get_set_pair_p->getter_cp);
1483-
result = ecma_op_function_call (getter_p, base, NULL, 0);
1480+
result = ecma_op_invoke_getter (get_set_pair_p, base);
14841481
}
14851482
}
14861483

Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
// Copyright JS Foundation and other contributors, http://js.foundation
2+
//
3+
// Licensed under the Apache License, Version 2.0 (the "License");
4+
// you may not use this file except in compliance with the License.
5+
// You may obtain a copy of the License at
6+
//
7+
// http://www.apache.org/licenses/LICENSE-2.0
8+
//
9+
// Unless required by applicable law or agreed to in writing, software
10+
// distributed under the License is distributed on an "AS IS" BASIS
11+
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12+
// See the License for the specific language governing permissions and
13+
// limitations under the License.
14+
15+
function assertArrayEqual(actual, expected) {
16+
assert(actual.length === expected.length);
17+
18+
for (var i = 0; i < actual.length; i++) {
19+
assert(actual[i] === expected[i]);
20+
}
21+
}
22+
23+
var i = 0;
24+
var a = [];
25+
var JSEtest = [];
26+
27+
JSEtest.__defineGetter__(0, function NaN() {
28+
if (i++ > 2) {
29+
return;
30+
}
31+
32+
JSEtest.shift();
33+
gc();
34+
a.push(0);
35+
a.concat(JSEtest);
36+
});
37+
38+
JSEtest[0];
39+
40+
assertArrayEqual(a, [0, 0, 0]);
41+
assertArrayEqual(JSEtest, []);

0 commit comments

Comments
 (0)