1 // Copyright 2016 the V8 project authors. All rights reserved. 2 // Use of this source code is governed by a BSD-style license that can be 3 // found in the LICENSE file. 4 5 #include "src/builtins/builtins.h" 6 #include "src/builtins/builtins-utils.h" 7 8 #include "src/code-factory.h" 9 10 namespace v8 { 11 namespace internal { 12 13 // ES7 sharedmem 6.3.4.1 get SharedArrayBuffer.prototype.byteLength 14 BUILTIN(SharedArrayBufferPrototypeGetByteLength) { 15 HandleScope scope(isolate); 16 CHECK_RECEIVER(JSArrayBuffer, array_buffer, 17 "get SharedArrayBuffer.prototype.byteLength"); 18 if (!array_buffer->is_shared()) { 19 THROW_NEW_ERROR_RETURN_FAILURE( 20 isolate, NewTypeError(MessageTemplate::kIncompatibleMethodReceiver, 21 isolate->factory()->NewStringFromAsciiChecked( 22 "get SharedArrayBuffer.prototype.byteLength"), 23 args.receiver())); 24 } 25 return array_buffer->byte_length(); 26 } 27 28 namespace { 29 30 void ValidateSharedTypedArray(CodeStubAssembler* a, compiler::Node* tagged, 31 compiler::Node* context, 32 compiler::Node** out_instance_type, 33 compiler::Node** out_backing_store) { 34 using namespace compiler; 35 CodeStubAssembler::Label is_smi(a), not_smi(a), is_typed_array(a), 36 not_typed_array(a), is_shared(a), not_shared(a), is_float_or_clamped(a), 37 not_float_or_clamped(a), invalid(a); 38 39 // Fail if it is not a heap object. 40 a->Branch(a->TaggedIsSmi(tagged), &is_smi, ¬_smi); 41 a->Bind(&is_smi); 42 a->Goto(&invalid); 43 44 // Fail if the array's instance type is not JSTypedArray. 45 a->Bind(¬_smi); 46 a->Branch(a->WordEqual(a->LoadInstanceType(tagged), 47 a->Int32Constant(JS_TYPED_ARRAY_TYPE)), 48 &is_typed_array, ¬_typed_array); 49 a->Bind(¬_typed_array); 50 a->Goto(&invalid); 51 52 // Fail if the array's JSArrayBuffer is not shared. 53 a->Bind(&is_typed_array); 54 Node* array_buffer = a->LoadObjectField(tagged, JSTypedArray::kBufferOffset); 55 Node* is_buffer_shared = 56 a->IsSetWord32<JSArrayBuffer::IsShared>(a->LoadObjectField( 57 array_buffer, JSArrayBuffer::kBitFieldOffset, MachineType::Uint32())); 58 a->Branch(is_buffer_shared, &is_shared, ¬_shared); 59 a->Bind(¬_shared); 60 a->Goto(&invalid); 61 62 // Fail if the array's element type is float32, float64 or clamped. 63 a->Bind(&is_shared); 64 Node* elements_instance_type = a->LoadInstanceType( 65 a->LoadObjectField(tagged, JSObject::kElementsOffset)); 66 STATIC_ASSERT(FIXED_INT8_ARRAY_TYPE < FIXED_FLOAT32_ARRAY_TYPE); 67 STATIC_ASSERT(FIXED_INT16_ARRAY_TYPE < FIXED_FLOAT32_ARRAY_TYPE); 68 STATIC_ASSERT(FIXED_INT32_ARRAY_TYPE < FIXED_FLOAT32_ARRAY_TYPE); 69 STATIC_ASSERT(FIXED_UINT8_ARRAY_TYPE < FIXED_FLOAT32_ARRAY_TYPE); 70 STATIC_ASSERT(FIXED_UINT16_ARRAY_TYPE < FIXED_FLOAT32_ARRAY_TYPE); 71 STATIC_ASSERT(FIXED_UINT32_ARRAY_TYPE < FIXED_FLOAT32_ARRAY_TYPE); 72 a->Branch(a->Int32LessThan(elements_instance_type, 73 a->Int32Constant(FIXED_FLOAT32_ARRAY_TYPE)), 74 ¬_float_or_clamped, &is_float_or_clamped); 75 a->Bind(&is_float_or_clamped); 76 a->Goto(&invalid); 77 78 a->Bind(&invalid); 79 a->CallRuntime(Runtime::kThrowNotIntegerSharedTypedArrayError, context, 80 tagged); 81 a->Return(a->UndefinedConstant()); 82 83 a->Bind(¬_float_or_clamped); 84 *out_instance_type = elements_instance_type; 85 86 Node* backing_store = 87 a->LoadObjectField(array_buffer, JSArrayBuffer::kBackingStoreOffset); 88 Node* byte_offset = a->ChangeUint32ToWord(a->TruncateTaggedToWord32( 89 context, 90 a->LoadObjectField(tagged, JSArrayBufferView::kByteOffsetOffset))); 91 *out_backing_store = a->IntPtrAdd(backing_store, byte_offset); 92 } 93 94 // https://tc39.github.io/ecmascript_sharedmem/shmem.html#Atomics.ValidateAtomicAccess 95 compiler::Node* ConvertTaggedAtomicIndexToWord32(CodeStubAssembler* a, 96 compiler::Node* tagged, 97 compiler::Node* context) { 98 using namespace compiler; 99 CodeStubAssembler::Variable var_result(a, MachineRepresentation::kWord32); 100 101 Callable to_number = CodeFactory::ToNumber(a->isolate()); 102 Node* number_index = a->CallStub(to_number, context, tagged); 103 CodeStubAssembler::Label done(a, &var_result); 104 105 CodeStubAssembler::Label if_numberissmi(a), if_numberisnotsmi(a); 106 a->Branch(a->TaggedIsSmi(number_index), &if_numberissmi, &if_numberisnotsmi); 107 108 a->Bind(&if_numberissmi); 109 { 110 var_result.Bind(a->SmiToWord32(number_index)); 111 a->Goto(&done); 112 } 113 114 a->Bind(&if_numberisnotsmi); 115 { 116 Node* number_index_value = a->LoadHeapNumberValue(number_index); 117 Node* access_index = a->TruncateFloat64ToWord32(number_index_value); 118 Node* test_index = a->ChangeInt32ToFloat64(access_index); 119 120 CodeStubAssembler::Label if_indexesareequal(a), if_indexesarenotequal(a); 121 a->Branch(a->Float64Equal(number_index_value, test_index), 122 &if_indexesareequal, &if_indexesarenotequal); 123 124 a->Bind(&if_indexesareequal); 125 { 126 var_result.Bind(access_index); 127 a->Goto(&done); 128 } 129 130 a->Bind(&if_indexesarenotequal); 131 a->Return( 132 a->CallRuntime(Runtime::kThrowInvalidAtomicAccessIndexError, context)); 133 } 134 135 a->Bind(&done); 136 return var_result.value(); 137 } 138 139 void ValidateAtomicIndex(CodeStubAssembler* a, compiler::Node* index_word, 140 compiler::Node* array_length_word, 141 compiler::Node* context) { 142 using namespace compiler; 143 // Check if the index is in bounds. If not, throw RangeError. 144 CodeStubAssembler::Label if_inbounds(a), if_notinbounds(a); 145 // TODO(jkummerow): Use unsigned comparison instead of "i<0 || i>length". 146 a->Branch( 147 a->WordOr(a->Int32LessThan(index_word, a->Int32Constant(0)), 148 a->Int32GreaterThanOrEqual(index_word, array_length_word)), 149 &if_notinbounds, &if_inbounds); 150 a->Bind(&if_notinbounds); 151 a->Return( 152 a->CallRuntime(Runtime::kThrowInvalidAtomicAccessIndexError, context)); 153 a->Bind(&if_inbounds); 154 } 155 156 } // anonymous namespace 157 158 void Builtins::Generate_AtomicsLoad(CodeStubAssembler* a) { 159 using namespace compiler; 160 Node* array = a->Parameter(1); 161 Node* index = a->Parameter(2); 162 Node* context = a->Parameter(3 + 2); 163 164 Node* instance_type; 165 Node* backing_store; 166 ValidateSharedTypedArray(a, array, context, &instance_type, &backing_store); 167 168 Node* index_word32 = ConvertTaggedAtomicIndexToWord32(a, index, context); 169 Node* array_length_word32 = a->TruncateTaggedToWord32( 170 context, a->LoadObjectField(array, JSTypedArray::kLengthOffset)); 171 ValidateAtomicIndex(a, index_word32, array_length_word32, context); 172 Node* index_word = a->ChangeUint32ToWord(index_word32); 173 174 CodeStubAssembler::Label i8(a), u8(a), i16(a), u16(a), i32(a), u32(a), 175 other(a); 176 int32_t case_values[] = { 177 FIXED_INT8_ARRAY_TYPE, FIXED_UINT8_ARRAY_TYPE, FIXED_INT16_ARRAY_TYPE, 178 FIXED_UINT16_ARRAY_TYPE, FIXED_INT32_ARRAY_TYPE, FIXED_UINT32_ARRAY_TYPE, 179 }; 180 CodeStubAssembler::Label* case_labels[] = { 181 &i8, &u8, &i16, &u16, &i32, &u32, 182 }; 183 a->Switch(instance_type, &other, case_values, case_labels, 184 arraysize(case_labels)); 185 186 a->Bind(&i8); 187 a->Return( 188 a->SmiTag(a->AtomicLoad(MachineType::Int8(), backing_store, index_word))); 189 190 a->Bind(&u8); 191 a->Return(a->SmiTag( 192 a->AtomicLoad(MachineType::Uint8(), backing_store, index_word))); 193 194 a->Bind(&i16); 195 a->Return(a->SmiTag(a->AtomicLoad(MachineType::Int16(), backing_store, 196 a->WordShl(index_word, 1)))); 197 198 a->Bind(&u16); 199 a->Return(a->SmiTag(a->AtomicLoad(MachineType::Uint16(), backing_store, 200 a->WordShl(index_word, 1)))); 201 202 a->Bind(&i32); 203 a->Return(a->ChangeInt32ToTagged(a->AtomicLoad( 204 MachineType::Int32(), backing_store, a->WordShl(index_word, 2)))); 205 206 a->Bind(&u32); 207 a->Return(a->ChangeUint32ToTagged(a->AtomicLoad( 208 MachineType::Uint32(), backing_store, a->WordShl(index_word, 2)))); 209 210 // This shouldn't happen, we've already validated the type. 211 a->Bind(&other); 212 a->Return(a->Int32Constant(0)); 213 } 214 215 void Builtins::Generate_AtomicsStore(CodeStubAssembler* a) { 216 using namespace compiler; 217 Node* array = a->Parameter(1); 218 Node* index = a->Parameter(2); 219 Node* value = a->Parameter(3); 220 Node* context = a->Parameter(4 + 2); 221 222 Node* instance_type; 223 Node* backing_store; 224 ValidateSharedTypedArray(a, array, context, &instance_type, &backing_store); 225 226 Node* index_word32 = ConvertTaggedAtomicIndexToWord32(a, index, context); 227 Node* array_length_word32 = a->TruncateTaggedToWord32( 228 context, a->LoadObjectField(array, JSTypedArray::kLengthOffset)); 229 ValidateAtomicIndex(a, index_word32, array_length_word32, context); 230 Node* index_word = a->ChangeUint32ToWord(index_word32); 231 232 Node* value_integer = a->ToInteger(context, value); 233 Node* value_word32 = a->TruncateTaggedToWord32(context, value_integer); 234 235 CodeStubAssembler::Label u8(a), u16(a), u32(a), other(a); 236 int32_t case_values[] = { 237 FIXED_INT8_ARRAY_TYPE, FIXED_UINT8_ARRAY_TYPE, FIXED_INT16_ARRAY_TYPE, 238 FIXED_UINT16_ARRAY_TYPE, FIXED_INT32_ARRAY_TYPE, FIXED_UINT32_ARRAY_TYPE, 239 }; 240 CodeStubAssembler::Label* case_labels[] = { 241 &u8, &u8, &u16, &u16, &u32, &u32, 242 }; 243 a->Switch(instance_type, &other, case_values, case_labels, 244 arraysize(case_labels)); 245 246 a->Bind(&u8); 247 a->AtomicStore(MachineRepresentation::kWord8, backing_store, index_word, 248 value_word32); 249 a->Return(value_integer); 250 251 a->Bind(&u16); 252 a->AtomicStore(MachineRepresentation::kWord16, backing_store, 253 a->WordShl(index_word, 1), value_word32); 254 a->Return(value_integer); 255 256 a->Bind(&u32); 257 a->AtomicStore(MachineRepresentation::kWord32, backing_store, 258 a->WordShl(index_word, 2), value_word32); 259 a->Return(value_integer); 260 261 // This shouldn't happen, we've already validated the type. 262 a->Bind(&other); 263 a->Return(a->Int32Constant(0)); 264 } 265 266 } // namespace internal 267 } // namespace v8 268