Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: 1b1238d3e3949865f1370bfc0cbfe295116a8b33
https://github.com/WebKit/WebKit/commit/1b1238d3e3949865f1370bfc0cbfe295116a8b33
Author: Sergey Rubanov <[email protected]>
Date: 2026-09-30 (Wed, 30 Sep 2026)
Changed paths:
A JSTests/stress/arraybuffer-constructor-toindex-before-prototype.js
M Source/JavaScriptCore/runtime/JSArrayBufferConstructor.cpp
Log Message:
-----------
[JSC] Apply ToIndex before reading ArrayBuffer's newTarget.prototype
https://bugs.webkit.org/show_bug.cgi?id=325496
Reviewed by Yusuke Suzuki.
ArrayBuffer(length) converted length with ToNumber, read
newTarget.prototype, and only then applied ToIndex. A length ToIndex
rejects, such as -1 or Infinity, therefore ran the prototype getter
first and surfaced that exception instead of RangeError.
ToIndex the length, then the maxByteLength option, before
AllocateArrayBuffer reads the prototype. Both results stay in
uint64_t for the comparison, so a 32-bit size_t cannot wrap a length
above 2^32 and skip the RangeError. A length above the array buffer
limit fails allocation after that prototype read.
* JSTests/stress/arraybuffer-constructor-toindex-before-prototype.js: Added.
* Source/JavaScriptCore/runtime/JSArrayBufferConstructor.cpp:
(JSC::JSGenericArrayBufferConstructor::constructImpl):
Canonical link: https://commits.webkit.org/322281@main
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications