CVE-2026-3910 Graph Diff

建立於 差異永不過期
56 刪除
106
44 新增
96
----- After graph building -----
----- After Phi untagging -----
Graph
Graph


17: Constant(0x21ff0101e4ed <FeedbackCell[one closure]>), 3 uses
17: Constant(0x21ff0101e4ed <FeedbackCell[one closure]>), 3 uses
3: Constant(0x21ff0101e589 <JSFunction trigger (sfi = 0x21ff0101e451)>), 6 uses
3: Constant(0x21ff0101e589 <JSFunction trigger (sfi = 0x21ff0101e451)>), 6 uses
4: Constant(0x21ff0101e50d <ScriptContext[3]>), 6 uses
4: Constant(0x21ff0101e50d <ScriptContext[3]>), 6 uses
46: Constant(0x21ff0104b819 <Object map = 0x21ff0101e5bd>), 1 uses
46: Constant(0x21ff0104b819 <Object map = 0x21ff0101e5bd>), 1 uses
5: RootConstant(undefined_value), 1 uses
5: RootConstant(undefined_value), 1 uses
12: RootConstant(true_value), 0 uses 🪦
12: RootConstant(true_value), 0 uses 🪦
28: RootConstant(false_value), 0 uses 🪦
28: RootConstant(false_value), 0 uses 🪦
19: RootConstant(optimized_out), 0 uses 🪦
19: RootConstant(optimized_out), 0 uses 🪦
8: SmiConstant(0), 2 uses
8: SmiConstant(0), 2 uses
22: SmiConstant(1), 1 uses
22: SmiConstant(1), 0 uses 🪦
37: SmiConstant(3), 1 uses
37: SmiConstant(3), 1 uses
9: SmiConstant(5), 1 uses
9: SmiConstant(5), 1 uses
43: SmiConstant(42), 1 uses
43: SmiConstant(42), 1 uses
10: Int32Constant(0), 3 uses, cannot truncate to int32
10: Int32Constant(0), 1 uses, cannot truncate to int32
16: Int32Constant(1), 1 uses, cannot truncate to int32
16: Int32Constant(1), 2 uses, cannot truncate to int32
39: Int32Constant(3), 2 uses, cannot truncate to int32
39: Int32Constant(3), 2 uses, cannot truncate to int32
11: Int32Constant(5), 2 uses, cannot truncate to int32
11: Int32Constant(5), 2 uses, cannot truncate to int32
Block b0
Block b0
0x21ff0101e451 <SharedFunctionInfo trigger> (0x21ff0104a989 <String[6]: "poc.js">:16:16)
0x21ff0101e451 <SharedFunctionInfo trigger> (0x21ff0104a989 <String[6]: "poc.js">:16:16)
0 : 0c LdaZero
0 : 0c LdaZero
1: InitialValue(<this>), 6 uses
1: InitialValue(<this>), 6 uses
2: InitialValue(a0), 8 uses
2: InitialValue(a0), 8 uses
6: FunctionEntryStackCheck
6: FunctionEntryStackCheck
↳ lazy @-1 (3 live vars)
↳ lazy @-1 (3 live vars)
7: Jump b1
7: Jump b1
Block b1
Block b1
0x21ff0101e451 <SharedFunctionInfo trigger> (0x21ff0104a989 <String[6]: "poc.js">:0:0)
0x21ff0101e451 <SharedFunctionInfo trigger> (0x21ff0104a989 <String[6]: "poc.js">:0:0)
14 : 40 f9 01 Add r0, FBV[1]
14 : 40 f9 01 Add r0, FBV[1]
↱ eager @14 (6 live vars)
↱ eager @14 (6 live vars)
13: CheckedSmiUntag [n2], 2 uses, cannot truncate to int32
13: CheckedSmiUntag [n2], 2 uses, cannot truncate to int32
↱ eager @14 (6 live vars)
14: Int32Add [n13, n10], 3 uses, can truncate to int32 [-2147483648, 2147483647]
14: Int32AddWithOverflow [n13, n10], 1 uses, can truncate to int32 [-2147483648, 2147483647]
17 : 53 00 00 BitwiseOrSmi [0], FBV[0]
15: Int32BitwiseOr [n14, n10], 2 uses, cannot truncate to int32
26 : 95 16 00 03 JumpLoop [22], [0], FBV[3]
26 : 95 16 00 03 JumpLoop [22], [0], FBV[3]
18: ReduceInterruptBudgetForLoop(17) [n17]
18: ReduceInterruptBudgetForLoop(17) [n17]
↳ lazy @26 (5 live vars)
↳ lazy @26 (5 live vars)
21: Int32ToNumber[kCanonicalizeSmi] [n15], 1 uses
21: Int32ToNumber[kCanonicalizeSmi] [n14], 0 uses 🪦
20: Jump b2
20: Jump b2
│ with gap moves:
│ with gap moves:
│ - n21 → 23: φᵀ r0
│ - n14 → 23: φᴵ r0
│ - n22 → 24: φᵀ r2
│ - n16 → 24: φᴵ r2
╭─►Block b2 peeled (effects:)
╭─►Block b2 peeled (effects:)
│ 23: φᵀ r0 (n21, n35), 5 uses
│ 23: φᴵ r0 (n14, n30), 8 uses
│ 24: φᵀ r2 (n22, n36), 2 uses
│ 24: φᴵ r2 (n16, n32), 5 uses
│ 6 : 77 f7 01 00 TestLessThan r2, EmbeddedFeedback[0x1]
│ 6 : 77 f7 01 00 TestLessThan r2, EmbeddedFeedback[0x1]
│ ↱ eager @6 (6 live vars)
│ 26: Int32Compare[LessThan] [n24, n11], 0 uses 🪦
│ 25: CheckedSmiUntag [n24], 3 uses, cannot truncate to int32
│ 26: Int32Compare[LessThan] [n25, n11], 0 uses 🪦
│ 10 : a6 14 JumpIfFalse [20]
│ 10 : a6 14 JumpIfFalse [20]
│╭──27: BranchIfInt32Compare(LessThan) [n25, n11] b3 b4
│╭──27: BranchIfInt32Compare(LessThan) [n24, n11] b3 b4
││ ↓
││ ↓
││ Block b3
││ Block b3
││ 14 : 40 f9 01 Add r0, FBV[1]
││ 14 : 40 f9 01 Add r0, FBV[1]
││ ↱ eager @6 (6 live vars)
││ 30: Int32Add [n13, n23], 3 uses, can truncate to int32 [-2147483648, 2147483647]
││ 29: CheckedSmiUntag [n23], 1 uses, cannot truncate to int32
││ ↱ eager @6 (6 live vars)
││ 30: Int32AddWithOverflow [n13, n29], 1 uses, can truncate to int32 [-2147483648, 2147483647]
││ 17 : 53 00 00 BitwiseOrSmi [0], FBV[0]
││ 31: Int32BitwiseOr [n30, n10], 2 uses, cannot truncate to int32
││ 23 : 59 02 Inc FBV[2]
││ 23 : 59 02 Inc FBV[2]
││ ↱ eager @6 (6 live vars)
││ ↱ eager @6 (6 live vars)
││ 32: Int32IncrementWithOverflow [n25], 2 uses, cannot truncate to int32
││ 32: Int32IncrementWithOverflow [n24], 3 uses, cannot truncate to int32
││ 26 : 95 16 00 03 JumpLoop [22], [0], FBV[3]
││ 26 : 95 16 00 03 JumpLoop [22], [0], FBV[3]
││ 33: ReduceInterruptBudgetForLoop(17) [n17]
││ 33: ReduceInterruptBudgetForLoop(17) [n17]
││ ↳ lazy @26 (5 live vars)
││ ↳ lazy @26 (5 live vars)
││ 35: Int32ToNumber[kCanonicalizeSmi] [n31], 1 uses
││ 35: Int32ToNumber[kCanonicalizeSmi] [n30], 0 uses 🪦
││ 36: Int32ToNumber[kCanonicalizeSmi] [n32], 1 uses
││ 36: Int32ToNumber[kCanonicalizeSmi] [n32], 0 uses 🪦
││ ↱ eager @6 (6 live vars)
││ ↱ eager @6 (6 live vars)
╰─◄─34: JumpLoop b2
╰─◄─34: JumpLoop b2
│ with gap moves:
│ with gap moves:
│ - n35 → 23: φᵀ r0
│ - n30 → 23: φᴵ r0
│ - n36 → 24: φᵀ r2
│ - n32 → 24: φᴵ r2
╰►Block b4
╰►Block b4
32 : 78 f9 01 00 TestGreaterThan r0, EmbeddedFeedback[0x1]
32 : 78 f9 01 00 TestGreaterThan r0, EmbeddedFeedback[0x1]
↱ eager @32 (5 live vars)
40: Int32Compare[GreaterThan] [n23, n39], 0 uses 🪦
38: CheckedSmiUntag [n23], 2 uses, cannot truncate to int32
40: Int32Compare[GreaterThan] [n38, n39], 0 uses 🪦
36 : a6 06 JumpIfFalse [6]
36 : a6 06 JumpIfFalse [6]
╭───41: BranchIfInt32Compare(GreaterThan) [n38, n39] b5 b6
╭───41: BranchIfInt32Compare(GreaterThan) [n23, n39] b5 b6
│ ↓
│ ↓
│ Block b5
│ Block b5
│ 50: Int32ToNumber[kCanonicalizeSmi] [n23], 1 uses
│ 40 : 96 04 Jump [4]
│ 40 : 96 04 Jump [4]
│╭──42: Jump b7
│╭──42: Jump b7
││ with gap moves:
││ with gap moves:
││ - n23 → 45: φᵀ <accumulator>
││ - n50 → 45: φᵀ <accumulator>
││
││
╰─►Block b6
╰─►Block b6
│ 44 : d1 Star1
│ 44 : d1 Star1
│ 44: Jump b7
│ 44: Jump b7
│ │ with gap moves:
│ │ with gap moves:
│ │ - n43 → 45: φᵀ <accumulator>
│ │ - n43 → 45: φᵀ <accumulator>
│ ▼
│ ▼
╰►Block b7
╰►Block b7
45: φᵀ <accumulator> (n23, n43), 1 uses
45: φᵀ <accumulator> (n50, n43), 1 uses
52 : 39 f6 01 04 SetNamedProperty r3, [1:"x"], FBV[4]
52 : 39 f6 01 04 SetNamedProperty r3, [1:"x"], FBV[4]
47: StoreTaggedFieldNoWriteBarrier(0xc: 0x21ff00003665 <String[1]: #x>) [n46, n45]
47: StoreTaggedFieldNoWriteBarrier(0xc: 0x21ff00003665 <String[1]: #x>) [n46, n45]
57 : b7 Return
57 : b7 Return
48: ReduceInterruptBudgetForReturn(57) [n17]
48: ReduceInterruptBudgetForReturn(57) [n17]
49: Return [n5]
49: Return [n5]