| Index: src/typedarray.js
|
| diff --git a/src/typedarray.js b/src/typedarray.js
|
| index 21dd9c82d14f02d1d265f87604386e57cd09f890..c0f07eda85623defe627fa5f7d834bfb5f2ba6e5 100644
|
| --- a/src/typedarray.js
|
| +++ b/src/typedarray.js
|
| @@ -243,6 +243,10 @@ function TypedArraySet(obj, offset) {
|
| if (intOffset < 0) {
|
| throw MakeTypeError("typed_array_set_negative_offset");
|
| }
|
| +
|
| + if (intOffset > %MaxSmi()) {
|
| + throw MakeRangeError("typed_array_set_source_too_large");
|
| + }
|
| switch (%TypedArraySetFastCases(this, obj, intOffset)) {
|
| // These numbers should be synchronized with runtime.cc.
|
| case 0: // TYPED_ARRAY_SET_TYPED_ARRAY_SAME_TYPE
|
|
|