Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(663)

Unified Diff: src/lookup.cc

Issue 2534613002: [ic] Use validity cells to protect keyed element stores against object's prototype chain modificati… (Closed)
Patch Set: The fix Created 4 years ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: src/lookup.cc
diff --git a/src/lookup.cc b/src/lookup.cc
index 186823df8470b2faf0453cc5002c79e9a801f57c..593e6928f9ae79f9e67c96953e10141f38e9a2c9 100644
--- a/src/lookup.cc
+++ b/src/lookup.cc
@@ -526,11 +526,8 @@ void LookupIterator::TransitionToAccessorPair(Handle<Object> pair,
Handle<SeededNumberDictionary> dictionary =
JSObject::NormalizeElements(receiver);
- // We unconditionally pass used_as_prototype=false here because the call
- // to RequireSlowElements takes care of the required IC clearing and
- // we don't want to walk the heap twice.
- dictionary =
- SeededNumberDictionary::Set(dictionary, index_, pair, details, false);
+ dictionary = SeededNumberDictionary::Set(dictionary, index_, pair, details,
+ receiver);
receiver->RequireSlowElements(*dictionary);
if (receiver->HasSlowArgumentsElements()) {
« src/ic/accessor-assembler.cc ('K') | « src/ic/ic-inl.h ('k') | src/objects.h » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698