runtime-typedarray.cc 7.26 KB
Newer Older
1 2 3 4
// Copyright 2014 the V8 project authors. All rights reserved.
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.

5
#include "src/common/message-template.h"
6
#include "src/execution/arguments-inl.h"
7
#include "src/heap/factory.h"
8
#include "src/heap/heap-inl.h"
9
#include "src/logging/counters.h"
10
#include "src/objects/elements.h"
11
#include "src/objects/js-array-buffer-inl.h"
12
#include "src/objects/objects-inl.h"
13
#include "src/runtime/runtime-utils.h"
14 15 16 17 18
#include "src/runtime/runtime.h"

namespace v8 {
namespace internal {

19
RUNTIME_FUNCTION(Runtime_ArrayBufferDetach) {
20
  HandleScope scope(isolate);
21
  DCHECK_EQ(1, args.length());
22 23 24 25 26 27 28 29
  Handle<Object> argument = args.at(0);
  // This runtime function is exposed in ClusterFuzz and as such has to
  // support arbitrary arguments.
  if (!argument->IsJSArrayBuffer()) {
    THROW_NEW_ERROR_RETURN_FAILURE(
        isolate, NewTypeError(MessageTemplate::kNotTypedArray));
  }
  Handle<JSArrayBuffer> array_buffer = Handle<JSArrayBuffer>::cast(argument);
30
  array_buffer->Detach();
31
  return ReadOnlyRoots(isolate).undefined_value();
32 33
}

34 35 36
RUNTIME_FUNCTION(Runtime_TypedArrayCopyElements) {
  HandleScope scope(isolate);
  DCHECK_EQ(3, args.length());
37
  CONVERT_ARG_HANDLE_CHECKED(JSTypedArray, target, 0);
38
  CONVERT_ARG_HANDLE_CHECKED(Object, source, 1);
39 40
  CONVERT_NUMBER_ARG_HANDLE_CHECKED(length_obj, 2);

41 42 43 44 45
  size_t length;
  CHECK(TryNumberToSize(*length_obj, &length));

  ElementsAccessor* accessor = target->GetElementsAccessor();
  return accessor->CopyElements(source, target, length);
46 47
}

48 49
RUNTIME_FUNCTION(Runtime_TypedArrayGetBuffer) {
  HandleScope scope(isolate);
50
  DCHECK_EQ(1, args.length());
51 52 53 54
  CONVERT_ARG_HANDLE_CHECKED(JSTypedArray, holder, 0);
  return *holder->GetBuffer();
}

55

56 57
namespace {

58 59 60 61 62 63 64 65 66 67 68 69 70 71 72
template <typename T>
bool CompareNum(T x, T y) {
  if (x < y) {
    return true;
  } else if (x > y) {
    return false;
  } else if (!std::is_integral<T>::value) {
    double _x = x, _y = y;
    if (x == 0 && x == y) {
      /* -0.0 is less than +0.0 */
      return std::signbit(_x) && !std::signbit(_y);
    } else if (!std::isnan(_x) && std::isnan(_y)) {
      /* number is less than NaN */
      return true;
    }
73
  }
74 75
  return false;
}
76 77 78 79 80 81 82

}  // namespace

RUNTIME_FUNCTION(Runtime_TypedArraySortFast) {
  HandleScope scope(isolate);
  DCHECK_EQ(1, args.length());

83 84 85
  // Validation is handled in the Torque builtin.
  CONVERT_ARG_HANDLE_CHECKED(JSTypedArray, array, 0);
  DCHECK(!array->WasDetached());
86

87
  size_t length = array->length();
88
  if (length <= 1) return *array;
89

90 91 92
  // In case of a SAB, the data is copied into temporary memory, as
  // std::sort might crash in case the underlying data is concurrently
  // modified while sorting.
93
  CHECK(array->buffer().IsJSArrayBuffer());
94 95 96 97 98 99 100 101 102 103 104
  Handle<JSArrayBuffer> buffer(JSArrayBuffer::cast(array->buffer()), isolate);
  const bool copy_data = buffer->is_shared();

  Handle<ByteArray> array_copy;
  if (copy_data) {
    const size_t bytes = array->byte_length();
    // TODO(szuend): Re-check this approach once support for larger typed
    //               arrays has landed.
    CHECK_LE(bytes, INT_MAX);
    array_copy = isolate->factory()->NewByteArray(static_cast<int>(bytes));
    std::memcpy(static_cast<void*>(array_copy->GetDataStartAddress()),
105
                static_cast<void*>(array->DataPtr()), bytes);
106 107 108 109
  }

  DisallowHeapAllocation no_gc;

110
  switch (array->type()) {
111 112
#define TYPED_ARRAY_SORT(Type, type, TYPE, ctype)                          \
  case kExternal##Type##Array: {                                           \
113 114 115
    ctype* data =                                                          \
        copy_data                                                          \
            ? reinterpret_cast<ctype*>(array_copy->GetDataStartAddress())  \
116
            : static_cast<ctype*>(array->DataPtr());                       \
117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135
    if (kExternal##Type##Array == kExternalFloat64Array ||                 \
        kExternal##Type##Array == kExternalFloat32Array) {                 \
      if (COMPRESS_POINTERS_BOOL && alignof(ctype) > kTaggedSize) {        \
        /* TODO(ishell, v8:8875): See UnalignedSlot<T> for details. */     \
        std::sort(UnalignedSlot<ctype>(data),                              \
                  UnalignedSlot<ctype>(data + length), CompareNum<ctype>); \
      } else {                                                             \
        std::sort(data, data + length, CompareNum<ctype>);                 \
      }                                                                    \
    } else {                                                               \
      if (COMPRESS_POINTERS_BOOL && alignof(ctype) > kTaggedSize) {        \
        /* TODO(ishell, v8:8875): See UnalignedSlot<T> for details. */     \
        std::sort(UnalignedSlot<ctype>(data),                              \
                  UnalignedSlot<ctype>(data + length));                    \
      } else {                                                             \
        std::sort(data, data + length);                                    \
      }                                                                    \
    }                                                                      \
    break;                                                                 \
136 137 138 139 140 141
  }

    TYPED_ARRAYS(TYPED_ARRAY_SORT)
#undef TYPED_ARRAY_SORT
  }

142 143 144
  if (copy_data) {
    DCHECK(!array_copy.is_null());
    const size_t bytes = array->byte_length();
145
    std::memcpy(static_cast<void*>(array->DataPtr()),
146 147 148
                static_cast<void*>(array_copy->GetDataStartAddress()), bytes);
  }

149 150
  return *array;
}
151

152
// 22.2.3.23 %TypedArray%.prototype.set ( overloaded [ , offset ] )
153 154 155 156 157 158
RUNTIME_FUNCTION(Runtime_TypedArraySet) {
  HandleScope scope(isolate);
  Handle<JSTypedArray> target = args.at<JSTypedArray>(0);
  Handle<Object> obj = args.at(1);
  Handle<Smi> offset = args.at<Smi>(2);

159
  DCHECK(!target->WasDetached());  // Checked in TypedArrayPrototypeSet.
160
  DCHECK(!obj->IsJSTypedArray());  // Should be handled by CSA.
161
  DCHECK_LE(0, offset->value());
162 163 164

  const uint32_t uint_offset = static_cast<uint32_t>(offset->value());

165 166 167 168 169 170 171 172 173 174 175 176 177
  if (obj->IsNumber()) {
    // For number as a first argument, throw TypeError
    // instead of silently ignoring the call, so that
    // users know they did something wrong.
    // (Consistent with Firefox and Blink/WebKit)
    THROW_NEW_ERROR_RETURN_FAILURE(
        isolate, NewTypeError(MessageTemplate::kInvalidArgument));
  }

  ASSIGN_RETURN_FAILURE_ON_EXCEPTION(isolate, obj,
                                     Object::ToObject(isolate, obj));

  Handle<Object> len;
178
  ASSIGN_RETURN_FAILURE_ON_EXCEPTION(
179
      isolate, len,
180
      Object::GetProperty(isolate, obj, isolate->factory()->length_string()));
181 182 183
  ASSIGN_RETURN_FAILURE_ON_EXCEPTION(isolate, len,
                                     Object::ToLength(isolate, len));

184
  if (uint_offset + len->Number() > target->length()) {
185 186
    THROW_NEW_ERROR_RETURN_FAILURE(
        isolate, NewRangeError(MessageTemplate::kTypedArraySetSourceTooLarge));
187 188
  }

189 190 191 192 193 194
  uint32_t int_l;
  CHECK(DoubleToUint32IfEqualToSelf(len->Number(), &int_l));

  Handle<JSReceiver> source = Handle<JSReceiver>::cast(obj);
  ElementsAccessor* accessor = target->GetElementsAccessor();
  return accessor->CopyElements(source, target, int_l, uint_offset);
195 196
}

197 198
}  // namespace internal
}  // namespace v8