Description[heap] Track length for array buffers to avoid free-ing dependency
The dependency would only happen if we have a smi overflow for the length and
have create a heap number. In this case the heap number would've to survive
until the array buffer is collected.
To avoid this dependency we track the length (as we previously used to).
BUG=chromium:625748, chromium:625752
LOG=N
TEST=test/mjsunit/regress/regress-625752.js
R=hpayer@chromium.org
Committed: https://crrev.com/ddc75cc1356a58b6cfd63f9da0586e1150496b3d
Cr-Commit-Position: refs/heads/master@{#37530}
Patch Set 1 #Patch Set 2 : fix exception #
Messages
Total messages: 19 (9 generated)
|