Description[turbofan] Fix length in LowerJSCreateLiteralObject.
This fixes the length computation in for object literals in generic
lowering. In rare cases (e.g. boilerplate at end of page) this could
lead to out of bounds reads.
R=bmeurer@chromium.org
Committed: https://crrev.com/db8f0504b819eed060a7c6fa26e71032f892dc47
Cr-Commit-Position: refs/heads/master@{#34328}
Patch Set 1 #
Messages
Total messages: 11 (4 generated)
|