Changeset 246801 in webkit
- Timestamp:
- Jun 25, 2019, 12:49:22 PM (6 years ago)
- Location:
- trunk/Source/JavaScriptCore
- Files:
- 
      - 5 edited
 
 - 
          
  ChangeLog (modified) (1 diff)
- 
          
  runtime/JSObject.h (modified) (1 diff)
- 
          
  runtime/Structure.cpp (modified) (2 diffs)
- 
          
  runtime/Structure.h (modified) (2 diffs)
- 
          
  runtime/StructureInlines.h (modified) (2 diffs)
 
Legend:
- Unmodified
- Added
- Removed
- 
      trunk/Source/JavaScriptCore/ChangeLogr246798 r246801 1 2019-06-25 Keith Miller <keith_miller@apple.com> 2 3 Structure::create should call didBecomePrototype() 4 https://bugs.webkit.org/show_bug.cgi?id=196315 5 6 Reviewed by Filip Pizlo. 7 8 Structure::create should also assert that the indexing type makes sense 9 for the prototype being used. 10 11 * runtime/JSObject.h: 12 * runtime/Structure.cpp: 13 (JSC::Structure::isValidPrototype): 14 (JSC::Structure::changePrototypeTransition): 15 * runtime/Structure.h: 16 (JSC::Structure::create): Deleted. 17 * runtime/StructureInlines.h: 18 (JSC::Structure::create): 19 (JSC::Structure::setPrototypeWithoutTransition): 20 1 21 2019-06-25 Joseph Pecoraro <pecoraro@apple.com> 2 22 
- 
      trunk/Source/JavaScriptCore/runtime/JSObject.hr242650 r246801 745 745 bool isFrozen(VM& vm) { return structure(vm)->isFrozen(vm); } 746 746 747 bool anyObjectInChainMayInterceptIndexedAccesses(VM&) const;747 JS_EXPORT_PRIVATE bool anyObjectInChainMayInterceptIndexedAccesses(VM&) const; 748 748 JS_EXPORT_PRIVATE bool prototypeChainMayInterceptStoreTo(VM&, PropertyName); 749 749 bool needsSlowPutIndexing(VM&) const; 
- 
      trunk/Source/JavaScriptCore/runtime/Structure.cppr246780 r246801 322 322 } 323 323 324 bool Structure::isValidPrototype(JSValue prototype) 325 { 326 return prototype.isNull() || (prototype.isObject() && prototype.getObject()->mayBePrototype()); 327 } 328 324 329 void Structure::findStructuresAndMapForMaterialization(Vector<Structure*, 8>& structures, Structure*& structure, PropertyTable*& table) 325 330 { … … 545 550 Structure* Structure::changePrototypeTransition(VM& vm, Structure* structure, JSValue prototype, DeferredStructureTransitionWatchpointFire& deferred) 546 551 { 547 ASSERT( prototype.isObject() || prototype.isNull());552 ASSERT(isValidPrototype(prototype)); 548 553 549 554 DeferGC deferGC(vm.heap); 
- 
      trunk/Source/JavaScriptCore/runtime/Structure.hr246780 r246801 139 139 } 140 140 141 JS_EXPORT_PRIVATE static bool isValidPrototype(JSValue); 142 141 143 protected: 142 144 void finishCreation(VM& vm) 143 145 { 144 146 Base::finishCreation(vm); 145 ASSERT(m_prototype.get().isEmpty() || m_prototype.isObject() || m_prototype.isNull());147 ASSERT(m_prototype.get().isEmpty() || isValidPrototype(m_prototype.get())); 146 148 } 147 149 … … 787 789 }; 788 790 789 // We deliberately put Structure::create here in Structure.h instead of StructureInlines.h, because790 // it is used everywhere. This is so we don't have to hunt down all the places where we would need791 // to #include StructureInlines.h otherwise.792 inline Structure* Structure::create(VM& vm, JSGlobalObject* globalObject, JSValue prototype, const TypeInfo& typeInfo, const ClassInfo* classInfo, IndexingType indexingType, unsigned inlineCapacity)793 {794 ASSERT(vm.structureStructure);795 ASSERT(classInfo);796 Structure* structure = new (NotNull, allocateCell<Structure>(vm.heap)) Structure(vm, globalObject, prototype, typeInfo, classInfo, indexingType, inlineCapacity);797 structure->finishCreation(vm);798 return structure;799 }800 801 791 } // namespace JSC 
- 
      trunk/Source/JavaScriptCore/runtime/StructureInlines.hr246780 r246801 36 36 namespace JSC { 37 37 38 inline Structure* Structure::create(VM& vm, JSGlobalObject* globalObject, JSValue prototype, const TypeInfo& typeInfo, const ClassInfo* classInfo, IndexingType indexingType, unsigned inlineCapacity) 39 { 40 ASSERT(vm.structureStructure); 41 ASSERT(classInfo); 42 if (auto* object = prototype.getObject()) { 43 ASSERT(!object->anyObjectInChainMayInterceptIndexedAccesses(vm) || hasSlowPutArrayStorage(indexingType) || !hasIndexedProperties(indexingType)); 44 object->didBecomePrototype(); 45 } 46 47 Structure* structure = new (NotNull, allocateCell<Structure>(vm.heap)) Structure(vm, globalObject, prototype, typeInfo, classInfo, indexingType, inlineCapacity); 48 structure->finishCreation(vm); 49 return structure; 50 } 51 38 52 inline Structure* Structure::createStructure(VM& vm) 39 53 { … … 494 508 ALWAYS_INLINE void Structure::setPrototypeWithoutTransition(VM& vm, JSValue prototype) 495 509 { 510 ASSERT(isValidPrototype(prototype)); 496 511 m_prototype.set(vm, this, prototype); 497 512 } 
  Note:
 See   TracChangeset
 for help on using the changeset viewer.
  
