DescriptionMore -fsanitize=vptr fixes.
This actually fixes 3 different issues when accessing Operand1:
* Object vs. HeapObject
* Wrong defaults for equals/hash
* silently dropping const
TEST=test/mjsunit/regress/regress-441099.js
BUG=chromium:441099
LOG=y
Committed: https://crrev.com/cbf3b0bcc745536ee97ca21a3f9a7e613f31bc18
Cr-Commit-Position: refs/heads/master@{#25843}
Patch Set 1 #Messages
Total messages: 7 (2 generated)
|