<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>177952</bug_id>
          
          <creation_ts>2017-10-05 10:57:10 -0700</creation_ts>
          <short_desc>Only add prototypes to the PrototypeMap if they&apos;re not already present</short_desc>
          <delta_ts>2017-10-07 12:18:20 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>JavaScriptCore</component>
          <version>Safari Technology Preview</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>DUPLICATE</resolution>
          <dup_id>177907</dup_id>
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Saam Barati">saam</reporter>
          <assigned_to name="Saam Barati">saam</assigned_to>
          <cc>benjamin</cc>
    
    <cc>commit-queue</cc>
    
    <cc>fpizlo</cc>
    
    <cc>ggaren</cc>
    
    <cc>gskachkov</cc>
    
    <cc>jfbastien</cc>
    
    <cc>keith_miller</cc>
    
    <cc>mark.lam</cc>
    
    <cc>msaboff</cc>
    
    <cc>rmorisset</cc>
    
    <cc>ryanhaddad</cc>
    
    <cc>ticaiolima</cc>
    
    <cc>webkit-bug-importer</cc>
    
    <cc>ysuzuki</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1357093</commentid>
    <comment_count>0</comment_count>
    <who name="Saam Barati">saam</who>
    <bug_when>2017-10-05 10:57:10 -0700</bug_when>
    <thetext>It&apos;s cheaper to check if the thing isn&apos;t in the prototype map since allocating a Weak is expensive.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357111</commentid>
    <comment_count>1</comment_count>
      <attachid>322865</attachid>
    <who name="Saam Barati">saam</who>
    <bug_when>2017-10-05 11:21:18 -0700</bug_when>
    <thetext>Created attachment 322865
patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357114</commentid>
    <comment_count>2</comment_count>
      <attachid>322865</attachid>
    <who name="Michael Saboff">msaboff</who>
    <bug_when>2017-10-05 11:22:51 -0700</bug_when>
    <thetext>Comment on attachment 322865
patch

r=me</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357115</commentid>
    <comment_count>3</comment_count>
      <attachid>322865</attachid>
    <who name="JF Bastien">jfbastien</who>
    <bug_when>2017-10-05 11:23:06 -0700</bug_when>
    <thetext>Comment on attachment 322865
patch

View in context: https://bugs.webkit.org/attachment.cgi?id=322865&amp;action=review

&gt; Source/JavaScriptCore/runtime/PrototypeMapInlines.h:48
&gt; +        m_prototypes.set(object, object);

Doesn&apos;t this do the search twice? Can you use the result iterator from the search instead?</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357127</commentid>
    <comment_count>4</comment_count>
    <who name="Saam Barati">saam</who>
    <bug_when>2017-10-05 11:37:40 -0700</bug_when>
    <thetext>(In reply to JF Bastien from comment #3)
&gt; Comment on attachment 322865 [details]
&gt; patch
&gt; 
&gt; View in context:
&gt; https://bugs.webkit.org/attachment.cgi?id=322865&amp;action=review
&gt; 
&gt; &gt; Source/JavaScriptCore/runtime/PrototypeMapInlines.h:48
&gt; &gt; +        m_prototypes.set(object, object);
&gt; 
&gt; Doesn&apos;t this do the search twice? Can you use the result iterator from the
&gt; search instead?

Yeah, this is the optimal thing to do. I&apos;ll add the necessary API to WeakMap to allow this to happen.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357135</commentid>
    <comment_count>5</comment_count>
      <attachid>322873</attachid>
    <who name="Saam Barati">saam</who>
    <bug_when>2017-10-05 11:47:40 -0700</bug_when>
    <thetext>Created attachment 322873
patch for landing</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357172</commentid>
    <comment_count>6</comment_count>
      <attachid>322873</attachid>
    <who name="JF Bastien">jfbastien</who>
    <bug_when>2017-10-05 12:31:38 -0700</bug_when>
    <thetext>Comment on attachment 322873
patch for landing

View in context: https://bugs.webkit.org/attachment.cgi?id=322873&amp;action=review

r=me

&gt; Source/JavaScriptCore/runtime/PrototypeMapInlines.h:47
&gt; +    auto addResult = m_prototypes.add(object, Weak&lt;JSObject&gt;());

Saam, using auto‽</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357177</commentid>
    <comment_count>7</comment_count>
    <who name="Saam Barati">saam</who>
    <bug_when>2017-10-05 12:46:00 -0700</bug_when>
    <thetext>(In reply to JF Bastien from comment #6)
&gt; Comment on attachment 322873 [details]
&gt; patch for landing
&gt; 
&gt; View in context:
&gt; https://bugs.webkit.org/attachment.cgi?id=322873&amp;action=review
&gt; 
&gt; r=me
&gt; 
&gt; &gt; Source/JavaScriptCore/runtime/PrototypeMapInlines.h:47
&gt; &gt; +    auto addResult = m_prototypes.add(object, Weak&lt;JSObject&gt;());
&gt; 
&gt; Saam, using auto‽

Always for addResult 😎</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357181</commentid>
    <comment_count>8</comment_count>
      <attachid>322873</attachid>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2017-10-05 12:58:11 -0700</bug_when>
    <thetext>Comment on attachment 322873
patch for landing

Clearing flags on attachment: 322873

Committed r222929: &lt;http://trac.webkit.org/changeset/222929&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357182</commentid>
    <comment_count>9</comment_count>
    <who name="WebKit Commit Bot">commit-queue</who>
    <bug_when>2017-10-05 12:58:13 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357183</commentid>
    <comment_count>10</comment_count>
    <who name="Radar WebKit Bug Importer">webkit-bug-importer</who>
    <bug_when>2017-10-05 12:59:09 -0700</bug_when>
    <thetext>&lt;rdar://problem/34840746&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357267</commentid>
    <comment_count>11</comment_count>
    <who name="Ryan Haddad">ryanhaddad</who>
    <bug_when>2017-10-05 15:06:19 -0700</bug_when>
    <thetext>This change caused LayoutTests to exit early with an assertion failure:
https://build.webkit.org/results/Apple%20Sierra%20Debug%20WK2%20(Tests)/r222929%20(3378)/results.html

ASSERTION FAILED: addResult.iterator-&gt;value.get() == object
./runtime/PrototypeMapInlines.h(51) : void JSC::PrototypeMap::addPrototype(JSC::JSObject *)
1   0x118ffb06d WTFCrash
2   0x117d5009d JSC::PrototypeMap::addPrototype(JSC::JSObject*)
3   0x117f657e0 JSC::ObjectPrototype::finishCreation(JSC::VM&amp;, JSC::JSGlobalObject*)
4   0x117f67ffe JSC::ObjectPrototype::create(JSC::VM&amp;, JSC::JSGlobalObject*, JSC::Structure*)
5   0x117d8bf6d JSC::JSGlobalObject::init(JSC::VM&amp;)
6   0x117daae7c JSC::JSGlobalObject::finishCreation(JSC::VM&amp;, JSC::JSObject*)
7   0x10d1220fa WebCore::JSDOMGlobalObject::finishCreation(JSC::VM&amp;, JSC::JSObject*)
8   0x10d271058 WebCore::JSDOMWindowBase::finishCreation(JSC::VM&amp;, WebCore::JSDOMWindowProxy*)
9   0x10d19f9b6 WebCore::JSDOMWindow::finishCreation(JSC::VM&amp;, WebCore::JSDOMWindowProxy*)
10  0x10d27a664 WebCore::JSDOMWindow::create(JSC::VM&amp;, JSC::Structure*, WTF::Ref&lt;WebCore::DOMWindow&gt;&amp;&amp;, WebCore::JSDOMWindowProxy*)
11  0x10d27a127 WebCore::JSDOMWindowProxy::setWindow(WTF::RefPtr&lt;WebCore::DOMWindow&gt;&amp;&amp;)
12  0x10e48d30e WebCore::ScriptController::setDOMWindowForWindowProxy(WebCore::DOMWindow*)
13  0x10c8a5c05 WebCore::FrameLoader::clear(WebCore::Document*, bool, bool, bool)
14  0x10c57a739 WebCore::DocumentWriter::begin(WebCore::URL const&amp;, bool, WebCore::Document*)
15  0x10c530f8e WebCore::DocumentLoader::commitData(char const*, unsigned long)
16  0x10c530a25 WebCore::DocumentLoader::finishedLoading()
17  0x10c537e25 WebCore::DocumentLoader::maybeLoadEmpty()
18  0x10c537fad WebCore::DocumentLoader::startLoadingMainResource()
19  0x10c8c0165 WebCore::FrameLoader::continueLoadAfterNavigationPolicy(WebCore::ResourceRequest const&amp;, WebCore::FormState*, bool, WebCore::AllowNavigationToInvalidURL)::$_7::operator()() const
20  0x10c8bfeb9 WTF::Function&lt;void ()&gt;::CallableWrapper&lt;WebCore::FrameLoader::continueLoadAfterNavigationPolicy(WebCore::ResourceRequest const&amp;, WebCore::FormState*, bool, WebCore::AllowNavigationToInvalidURL)::$_7&gt;::call()
21  0x10bd9d9db WTF::Function&lt;void ()&gt;::operator()() const
22  0x10c8ac80d WebCore::FrameLoader::continueLoadAfterNavigationPolicy(WebCore::ResourceRequest const&amp;, WebCore::FormState*, bool, WebCore::AllowNavigationToInvalidURL)
23  0x10c8be9e8 WebCore::FrameLoader::loadWithDocumentLoader(WebCore::DocumentLoader*, WebCore::FrameLoadType, WebCore::FormState*, WebCore::AllowNavigationToInvalidURL)::$_5::operator()(WebCore::ResourceRequest const&amp;, WebCore::FormState*, bool) const
24  0x10c8be972 WTF::Function&lt;void (WebCore::ResourceRequest const&amp;, WebCore::FormState*, bool)&gt;::CallableWrapper&lt;WebCore::FrameLoader::loadWithDocumentLoader(WebCore::DocumentLoader*, WebCore::FrameLoadType, WebCore::FormState*, WebCore::AllowNavigationToInvalidURL)::$_5&gt;::call(WebCore::ResourceRequest const&amp;, WebCore::FormState*, bool)
25  0x10dfd3bad WTF::Function&lt;void (WebCore::ResourceRequest const&amp;, WebCore::FormState*, bool)&gt;::operator()(WebCore::ResourceRequest const&amp;, WebCore::FormState*, bool) const
26  0x10dfd2bc9 WTF::CompletionHandler&lt;void (WebCore::ResourceRequest const&amp;, WebCore::FormState*, bool)&gt;::operator()(WebCore::ResourceRequest const&amp;, WebCore::FormState*, bool)
27  0x10dfd60b9 WebCore::PolicyChecker::checkNavigationPolicy(WebCore::ResourceRequest const&amp;, bool, WebCore::DocumentLoader*, WebCore::FormState*, WTF::CompletionHandler&lt;void (WebCore::ResourceRequest const&amp;, WebCore::FormState*, bool)&gt;&amp;&amp;)::$_1::operator()(WebCore::PolicyAction)
28  0x10dfd5c8a WTF::Function&lt;void (WebCore::PolicyAction)&gt;::CallableWrapper&lt;WebCore::PolicyChecker::checkNavigationPolicy(WebCore::ResourceRequest const&amp;, bool, WebCore::DocumentLoader*, WebCore::FormState*, WTF::CompletionHandler&lt;void (WebCore::ResourceRequest const&amp;, WebCore::FormState*, bool)&gt;&amp;&amp;)::$_1&gt;::call(WebCore::PolicyAction)
29  0x1055d10b1 WTF::Function&lt;void (WebCore::PolicyAction)&gt;::operator()(WebCore::PolicyAction) const
30  0x105cf69c5 WebKit::WebFrameLoaderClient::dispatchDecidePolicyForNavigationAction(WebCore::NavigationAction const&amp;, WebCore::ResourceRequest const&amp;, bool, WebCore::FormState*, WTF::Function&lt;void (WebCore::PolicyAction)&gt;&amp;&amp;)
31  0x10dfd2a3a WebCore::PolicyChecker::checkNavigationPolicy(WebCore::ResourceRequest const&amp;, bool, WebCore::DocumentLoader*, WebCore::FormState*, WTF::CompletionHandler&lt;void (WebCore::ResourceRequest const&amp;, WebCore::FormState*, bool)&gt;&amp;&amp;)
LEAK: 1 WebPageProxy</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357275</commentid>
    <comment_count>12</comment_count>
    <who name="Saam Barati">saam</who>
    <bug_when>2017-10-05 15:16:09 -0700</bug_when>
    <thetext>(In reply to Ryan Haddad from comment #11)
&gt; This change caused LayoutTests to exit early with an assertion failure:
&gt; https://build.webkit.org/results/Apple%20Sierra%20Debug%20WK2%20(Tests)/
&gt; r222929%20(3378)/results.html
&gt; 
&gt; ASSERTION FAILED: addResult.iterator-&gt;value.get() == object
&gt; ./runtime/PrototypeMapInlines.h(51) : void
&gt; JSC::PrototypeMap::addPrototype(JSC::JSObject *)
&gt; 1   0x118ffb06d WTFCrash
&gt; 2   0x117d5009d JSC::PrototypeMap::addPrototype(JSC::JSObject*)
&gt; 3   0x117f657e0 JSC::ObjectPrototype::finishCreation(JSC::VM&amp;,
&gt; JSC::JSGlobalObject*)
&gt; 4   0x117f67ffe JSC::ObjectPrototype::create(JSC::VM&amp;, JSC::JSGlobalObject*,
&gt; JSC::Structure*)
&gt; 5   0x117d8bf6d JSC::JSGlobalObject::init(JSC::VM&amp;)
&gt; 6   0x117daae7c JSC::JSGlobalObject::finishCreation(JSC::VM&amp;, JSC::JSObject*)
&gt; 7   0x10d1220fa WebCore::JSDOMGlobalObject::finishCreation(JSC::VM&amp;,
&gt; JSC::JSObject*)
&gt; 8   0x10d271058 WebCore::JSDOMWindowBase::finishCreation(JSC::VM&amp;,
&gt; WebCore::JSDOMWindowProxy*)
&gt; 9   0x10d19f9b6 WebCore::JSDOMWindow::finishCreation(JSC::VM&amp;,
&gt; WebCore::JSDOMWindowProxy*)
&gt; 10  0x10d27a664 WebCore::JSDOMWindow::create(JSC::VM&amp;, JSC::Structure*,
&gt; WTF::Ref&lt;WebCore::DOMWindow&gt;&amp;&amp;, WebCore::JSDOMWindowProxy*)
&gt; 11  0x10d27a127
&gt; WebCore::JSDOMWindowProxy::setWindow(WTF::RefPtr&lt;WebCore::DOMWindow&gt;&amp;&amp;)
&gt; 12  0x10e48d30e
&gt; WebCore::ScriptController::setDOMWindowForWindowProxy(WebCore::DOMWindow*)
&gt; 13  0x10c8a5c05 WebCore::FrameLoader::clear(WebCore::Document*, bool, bool,
&gt; bool)
&gt; 14  0x10c57a739 WebCore::DocumentWriter::begin(WebCore::URL const&amp;, bool,
&gt; WebCore::Document*)
&gt; 15  0x10c530f8e WebCore::DocumentLoader::commitData(char const*, unsigned
&gt; long)
&gt; 16  0x10c530a25 WebCore::DocumentLoader::finishedLoading()
&gt; 17  0x10c537e25 WebCore::DocumentLoader::maybeLoadEmpty()
&gt; 18  0x10c537fad WebCore::DocumentLoader::startLoadingMainResource()
&gt; 19  0x10c8c0165
&gt; WebCore::FrameLoader::continueLoadAfterNavigationPolicy(WebCore::
&gt; ResourceRequest const&amp;, WebCore::FormState*, bool,
&gt; WebCore::AllowNavigationToInvalidURL)::$_7::operator()() const
&gt; 20  0x10c8bfeb9 WTF::Function&lt;void
&gt; ()&gt;::CallableWrapper&lt;WebCore::FrameLoader::
&gt; continueLoadAfterNavigationPolicy(WebCore::ResourceRequest const&amp;,
&gt; WebCore::FormState*, bool,
&gt; WebCore::AllowNavigationToInvalidURL)::$_7&gt;::call()
&gt; 21  0x10bd9d9db WTF::Function&lt;void ()&gt;::operator()() const
&gt; 22  0x10c8ac80d
&gt; WebCore::FrameLoader::continueLoadAfterNavigationPolicy(WebCore::
&gt; ResourceRequest const&amp;, WebCore::FormState*, bool,
&gt; WebCore::AllowNavigationToInvalidURL)
&gt; 23  0x10c8be9e8
&gt; WebCore::FrameLoader::loadWithDocumentLoader(WebCore::DocumentLoader*,
&gt; WebCore::FrameLoadType, WebCore::FormState*,
&gt; WebCore::AllowNavigationToInvalidURL)::$_5::operator()(WebCore::
&gt; ResourceRequest const&amp;, WebCore::FormState*, bool) const
&gt; 24  0x10c8be972 WTF::Function&lt;void (WebCore::ResourceRequest const&amp;,
&gt; WebCore::FormState*,
&gt; bool)&gt;::CallableWrapper&lt;WebCore::FrameLoader::loadWithDocumentLoader(WebCore:
&gt; :DocumentLoader*, WebCore::FrameLoadType, WebCore::FormState*,
&gt; WebCore::AllowNavigationToInvalidURL)::$_5&gt;::call(WebCore::ResourceRequest
&gt; const&amp;, WebCore::FormState*, bool)
&gt; 25  0x10dfd3bad WTF::Function&lt;void (WebCore::ResourceRequest const&amp;,
&gt; WebCore::FormState*, bool)&gt;::operator()(WebCore::ResourceRequest const&amp;,
&gt; WebCore::FormState*, bool) const
&gt; 26  0x10dfd2bc9 WTF::CompletionHandler&lt;void (WebCore::ResourceRequest
&gt; const&amp;, WebCore::FormState*, bool)&gt;::operator()(WebCore::ResourceRequest
&gt; const&amp;, WebCore::FormState*, bool)
&gt; 27  0x10dfd60b9
&gt; WebCore::PolicyChecker::checkNavigationPolicy(WebCore::ResourceRequest
&gt; const&amp;, bool, WebCore::DocumentLoader*, WebCore::FormState*,
&gt; WTF::CompletionHandler&lt;void (WebCore::ResourceRequest const&amp;,
&gt; WebCore::FormState*, bool)&gt;&amp;&amp;)::$_1::operator()(WebCore::PolicyAction)
&gt; 28  0x10dfd5c8a WTF::Function&lt;void
&gt; (WebCore::PolicyAction)&gt;::CallableWrapper&lt;WebCore::PolicyChecker::
&gt; checkNavigationPolicy(WebCore::ResourceRequest const&amp;, bool,
&gt; WebCore::DocumentLoader*, WebCore::FormState*, WTF::CompletionHandler&lt;void
&gt; (WebCore::ResourceRequest const&amp;, WebCore::FormState*,
&gt; bool)&gt;&amp;&amp;)::$_1&gt;::call(WebCore::PolicyAction)
&gt; 29  0x1055d10b1 WTF::Function&lt;void
&gt; (WebCore::PolicyAction)&gt;::operator()(WebCore::PolicyAction) const
&gt; 30  0x105cf69c5
&gt; WebKit::WebFrameLoaderClient::
&gt; dispatchDecidePolicyForNavigationAction(WebCore::NavigationAction const&amp;,
&gt; WebCore::ResourceRequest const&amp;, bool, WebCore::FormState*,
&gt; WTF::Function&lt;void (WebCore::PolicyAction)&gt;&amp;&amp;)
&gt; 31  0x10dfd2a3a
&gt; WebCore::PolicyChecker::checkNavigationPolicy(WebCore::ResourceRequest
&gt; const&amp;, bool, WebCore::DocumentLoader*, WebCore::FormState*,
&gt; WTF::CompletionHandler&lt;void (WebCore::ResourceRequest const&amp;,
&gt; WebCore::FormState*, bool)&gt;&amp;&amp;)
&gt; LEAK: 1 WebPageProxy

Looking into it. This is really surprising.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357296</commentid>
    <comment_count>13</comment_count>
    <who name="Saam Barati">saam</who>
    <bug_when>2017-10-05 15:46:30 -0700</bug_when>
    <thetext>This is the bug:

```
void Heap::pruneStaleEntriesFromWeakGCMaps()
{
    if (m_collectionScope != CollectionScope::Full)
        return;
    for (auto&amp; pruneCallback : m_weakGCMaps.values())
        pruneCallback();
}
```
But the WeakGCMap we use is:
WeakGCMap&lt;JSObject*, JSObject*&gt;

which really is
HashMap&lt;JSObject*, Weak&lt;JSObject&gt;&gt;

It&apos;s really suspicious we don&apos;t clear entries in this map on every GC. I&apos;m working on a more fundamental fix in:
https://bugs.webkit.org/show_bug.cgi?id=177907</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357297</commentid>
    <comment_count>14</comment_count>
    <who name="Ryan Haddad">ryanhaddad</who>
    <bug_when>2017-10-05 15:52:33 -0700</bug_when>
    <thetext>Reverted r222929 for reason:

Caused assertion failures during LayoutTests.

Committed r222939: &lt;http://trac.webkit.org/changeset/222939&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357301</commentid>
    <comment_count>15</comment_count>
    <who name="Saam Barati">saam</who>
    <bug_when>2017-10-05 15:57:43 -0700</bug_when>
    <thetext>

*** This bug has been marked as a duplicate of bug 177907 ***</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357940</commentid>
    <comment_count>16</comment_count>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2017-10-07 12:16:54 -0700</bug_when>
    <thetext>(In reply to Saam Barati from comment #13)
&gt; This is the bug:
&gt; 
&gt; ```
&gt; void Heap::pruneStaleEntriesFromWeakGCMaps()
&gt; {
&gt;     if (m_collectionScope != CollectionScope::Full)
&gt;         return;
&gt;     for (auto&amp; pruneCallback : m_weakGCMaps.values())
&gt;         pruneCallback();
&gt; }
&gt; ```
&gt; But the WeakGCMap we use is:
&gt; WeakGCMap&lt;JSObject*, JSObject*&gt;
&gt; 
&gt; which really is
&gt; HashMap&lt;JSObject*, Weak&lt;JSObject&gt;&gt;
&gt; 
&gt; It&apos;s really suspicious we don&apos;t clear entries in this map on every GC. I&apos;m
&gt; working on a more fundamental fix in:
&gt; https://bugs.webkit.org/show_bug.cgi?id=177907

No, your patch was wrong. You should have said:

    auto addResult = m_prototypes.add(object, Weak&lt;JSObject&gt;());
    if (addResult.isNewEntry || !addResult.iterator-&gt;value)
        addResult.iterator-&gt;value = Weak&lt;JSObject&gt;(object);
    else
        ASSERT(addResult.iterator-&gt;value.get() == object);

Pruning a WeakGCMap is an optimization. All methods in WeakGCMap must assume that an entry with a null value is as if the entry was not there at all.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357942</commentid>
    <comment_count>17</comment_count>
      <attachid>322873</attachid>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2017-10-07 12:18:06 -0700</bug_when>
    <thetext>Comment on attachment 322873
patch for landing

View in context: https://bugs.webkit.org/attachment.cgi?id=322873&amp;action=review

&gt; Source/JavaScriptCore/runtime/PrototypeMapInlines.h:48
&gt; +    if (addResult.isNewEntry)

This should have also checked if the value is null.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1357943</commentid>
    <comment_count>18</comment_count>
    <who name="Filip Pizlo">fpizlo</who>
    <bug_when>2017-10-07 12:18:20 -0700</bug_when>
    <thetext>I&apos;ll fix this in https://bugs.webkit.org/show_bug.cgi?id=178051</thetext>
  </long_desc>
      
          <attachment
              isobsolete="1"
              ispatch="1"
              isprivate="0"
          >
            <attachid>322865</attachid>
            <date>2017-10-05 11:21:18 -0700</date>
            <delta_ts>2017-10-05 11:47:40 -0700</delta_ts>
            <desc>patch</desc>
            <filename>c-backup.diff</filename>
            <type>text/plain</type>
            <size>1927</size>
            <attacher name="Saam Barati">saam</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9DaGFuZ2VMb2cKPT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291
cmNlL0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkocmV2aXNpb24gMjIyOTIwKQorKysgU291cmNl
L0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDIwIEBA
CisyMDE3LTEwLTA1ICBTYWFtIEJhcmF0aSAgPHNiYXJhdGlAYXBwbGUuY29tPgorCisgICAgICAg
IE9ubHkgYWRkIHByb3RvdHlwZXMgdG8gdGhlIFByb3RvdHlwZU1hcCBpZiB0aGV5J3JlIG5vdCBh
bHJlYWR5IHByZXNlbnQKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcu
Y2dpP2lkPTE3Nzk1MgorCisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisg
ICAgICAgIFdpdGggcG9seSBwcm90bywgd2UgbmVlZCB0byBjYWxsIFByb3RvdHlwZU1hcDo6YWRk
IG1vcmUgZnJlcXVlbnRseSBzaW5jZSB3ZSBkb24ndAorICAgICAgICBrbm93IGlmIHRoZSBwcm90
b3R5cGUgaXMgYWxyZWFkeSBpbiB0aGUgbWFwIG9yIG5vdCBiYXNlZCBzb2xlbHkgb24gU3RydWN0
dXJlLgorICAgICAgICBQcm90b3R5cGVNYXA6OmFkZCB3YXMgY2FsbGluZyBXZWFrTWFwOjpzZXQg
dW5jb25kaXRpb25hbGx5LCB3aGljaCB3b3VsZCB1bmNvbmRpdGlvbmFsbHkKKyAgICAgICAgYWxs
b2NhdGUgYSBXZWFrIGhhbmRsZS4gQWxsb2NhdGluZyBhIFdlYWsgaGFuZGxlIGlzIGV4cGVuc2l2
ZS4gSXQncyBhdCBsZWFzdCA4eCBtb3JlCisgICAgICAgIGV4cGVuc2l2ZSB0aGFuIGp1c3QgY2hl
Y2tpbmcgaWYgdGhlIHByb3RvdHlwZSBpcyBpbiB0aGUgbWFwIHByaW9yIHRvIGFkZGluZyBpdC4g
VGhpcworICAgICAgICBwYXRjaCBtYWtlcyB0aGUgY2hhbmdlIHRvIG9ubHkgYWRkIHRoZSBwcm90
b3R5cGUgaWYgaXQncyBub3QgYWxyZWFkeSBpbiB0aGUgbWFwLgorCisgICAgICAgICogcnVudGlt
ZS9Qcm90b3R5cGVNYXBJbmxpbmVzLmg6CisgICAgICAgIChKU0M6OlByb3RvdHlwZU1hcDo6YWRk
UHJvdG90eXBlKToKKwogMjAxNy0xMC0wNSAgU2FhbSBCYXJhdGkgIDxzYmFyYXRpQGFwcGxlLmNv
bT4KIAogICAgICAgICBNYWtlIHN1cmUgYWxsIHByb3RvdHlwZXMgdW5kZXIgcG9seSBwcm90byBn
ZXQgYWRkZWQgaW50byB0aGUgVk0ncyBwcm90b3R5cGUgbWFwCkluZGV4OiBTb3VyY2UvSmF2YVNj
cmlwdENvcmUvcnVudGltZS9Qcm90b3R5cGVNYXBJbmxpbmVzLmgKPT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291
cmNlL0phdmFTY3JpcHRDb3JlL3J1bnRpbWUvUHJvdG90eXBlTWFwSW5saW5lcy5oCShyZXZpc2lv
biAyMjI5MTEpCisrKyBTb3VyY2UvSmF2YVNjcmlwdENvcmUvcnVudGltZS9Qcm90b3R5cGVNYXBJ
bmxpbmVzLmgJKHdvcmtpbmcgY29weSkKQEAgLTQ0LDcgKzQ0LDggQEAgQUxXQVlTX0lOTElORSBU
cmlTdGF0ZSBQcm90b3R5cGVNYXA6OmlzUAogCiBBTFdBWVNfSU5MSU5FIHZvaWQgUHJvdG90eXBl
TWFwOjphZGRQcm90b3R5cGUoSlNPYmplY3QqIG9iamVjdCkKIHsKLSAgICBtX3Byb3RvdHlwZXMu
c2V0KG9iamVjdCwgb2JqZWN0KTsKKyAgICBpZiAoIW1fcHJvdG90eXBlcy5jb250YWlucyhvYmpl
Y3QpKQorICAgICAgICBtX3Byb3RvdHlwZXMuc2V0KG9iamVjdCwgb2JqZWN0KTsKIAogICAgIC8v
IE5vdGUgdGhhdCB0aGlzIG1ldGhvZCBtYWtlcyB0aGUgc29tZXdoYXQgb2RkIGRlY2lzaW9uIHRv
IG5vdCBjaGVjayBpZiB0aGlzCiAgICAgLy8gb2JqZWN0IGN1cnJlbnRseSBoYXMgaW5kZXhlZCBh
Y2Nlc3NvcnMuIFdlIGNvdWxkIGRvIHRoYXQgY2hlY2sgaGVyZSwgYW5kIGlmCg==
</data>
<flag name="review"
          id="342689"
          type_id="1"
          status="+"
          setter="msaboff"
    />
          </attachment>
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>322873</attachid>
            <date>2017-10-05 11:47:40 -0700</date>
            <delta_ts>2017-10-05 12:58:11 -0700</delta_ts>
            <desc>patch for landing</desc>
            <filename>c-backup.diff</filename>
            <type>text/plain</type>
            <size>2909</size>
            <attacher name="Saam Barati">saam</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9DaGFuZ2VMb2cKPT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291
cmNlL0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkocmV2aXNpb24gMjIyOTIwKQorKysgU291cmNl
L0phdmFTY3JpcHRDb3JlL0NoYW5nZUxvZwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDI1IEBA
CisyMDE3LTEwLTA1ICBTYWFtIEJhcmF0aSAgPHNiYXJhdGlAYXBwbGUuY29tPgorCisgICAgICAg
IE9ubHkgYWRkIHByb3RvdHlwZXMgdG8gdGhlIFByb3RvdHlwZU1hcCBpZiB0aGV5J3JlIG5vdCBh
bHJlYWR5IHByZXNlbnQKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcvc2hvd19idWcu
Y2dpP2lkPTE3Nzk1MgorCisgICAgICAgIFJldmlld2VkIGJ5IE1pY2hhZWwgU2Fib2ZmIGFuZCBK
RiBCYXN0aWVuLgorCisgICAgICAgIFdpdGggcG9seSBwcm90bywgd2UgbmVlZCB0byBjYWxsIFBy
b3RvdHlwZU1hcDo6YWRkIG1vcmUgZnJlcXVlbnRseSBzaW5jZSB3ZSBkb24ndAorICAgICAgICBr
bm93IGlmIHRoZSBwcm90b3R5cGUgaXMgYWxyZWFkeSBpbiB0aGUgbWFwIG9yIG5vdCBiYXNlZCBz
b2xlbHkgb24gU3RydWN0dXJlLgorICAgICAgICBQcm90b3R5cGVNYXA6OmFkZCB3YXMgY2FsbGlu
ZyBXZWFrTWFwOjpzZXQgdW5jb25kaXRpb25hbGx5LCB3aGljaCB3b3VsZCB1bmNvbmRpdGlvbmFs
bHkKKyAgICAgICAgYWxsb2NhdGUgYSBXZWFrIGhhbmRsZS4gQWxsb2NhdGluZyBhIFdlYWsgaGFu
ZGxlIGlzIGV4cGVuc2l2ZS4gSXQncyBhdCBsZWFzdCA4eCBtb3JlCisgICAgICAgIGV4cGVuc2l2
ZSB0aGFuIGp1c3QgY2hlY2tpbmcgaWYgdGhlIHByb3RvdHlwZSBpcyBpbiB0aGUgbWFwIHByaW9y
IHRvIGFkZGluZyBpdC4gVGhpcworICAgICAgICBwYXRjaCBtYWtlcyB0aGUgY2hhbmdlIHRvIG9u
bHkgYWRkIHRoZSBwcm90b3R5cGUgaWYgaXQncyBub3QgYWxyZWFkeSBpbiB0aGUgbWFwLiBUbwor
ICAgICAgICBkbyB0aGlzLCBJJ3ZlIGFkZGVkIGEgV2Vha01hcDo6YWRkIEFQSSB0aGF0IGp1c3Qg
Zm9yd2FyZHMgaW50byBIYXNoTWFwJ3MgYWRkIEFQSS4KKyAgICAgICAgVGhpcyBhbGxvd3MgdXMg
dG8gYm90aCBvbmx5IGRvIGEgc2luZ2xlIGhhc2ggdGFibGUgbG9va3VwIGFuZCBhbHNvIHRvIGFs
bG9jYXRlIG9ubHkKKyAgICAgICAgYSBzaW5nbGUgV2VhayBoYW5kbGUgd2hlbiBuZWNlc3Nhcnku
CisKKyAgICAgICAgKiBydW50aW1lL1Byb3RvdHlwZU1hcElubGluZXMuaDoKKyAgICAgICAgKEpT
Qzo6UHJvdG90eXBlTWFwOjphZGRQcm90b3R5cGUpOgorICAgICAgICAqIHJ1bnRpbWUvV2Vha0dD
TWFwLmg6CisgICAgICAgIChKU0M6OldlYWtHQ01hcDo6YWRkKToKKwogMjAxNy0xMC0wNSAgU2Fh
bSBCYXJhdGkgIDxzYmFyYXRpQGFwcGxlLmNvbT4KIAogICAgICAgICBNYWtlIHN1cmUgYWxsIHBy
b3RvdHlwZXMgdW5kZXIgcG9seSBwcm90byBnZXQgYWRkZWQgaW50byB0aGUgVk0ncyBwcm90b3R5
cGUgbWFwCkluZGV4OiBTb3VyY2UvSmF2YVNjcmlwdENvcmUvcnVudGltZS9Qcm90b3R5cGVNYXBJ
bmxpbmVzLmgKPT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PQotLS0gU291cmNlL0phdmFTY3JpcHRDb3JlL3J1bnRpbWUvUHJv
dG90eXBlTWFwSW5saW5lcy5oCShyZXZpc2lvbiAyMjI5MTEpCisrKyBTb3VyY2UvSmF2YVNjcmlw
dENvcmUvcnVudGltZS9Qcm90b3R5cGVNYXBJbmxpbmVzLmgJKHdvcmtpbmcgY29weSkKQEAgLTQ0
LDcgKzQ0LDExIEBAIEFMV0FZU19JTkxJTkUgVHJpU3RhdGUgUHJvdG90eXBlTWFwOjppc1AKIAog
QUxXQVlTX0lOTElORSB2b2lkIFByb3RvdHlwZU1hcDo6YWRkUHJvdG90eXBlKEpTT2JqZWN0KiBv
YmplY3QpCiB7Ci0gICAgbV9wcm90b3R5cGVzLnNldChvYmplY3QsIG9iamVjdCk7CisgICAgYXV0
byBhZGRSZXN1bHQgPSBtX3Byb3RvdHlwZXMuYWRkKG9iamVjdCwgV2VhazxKU09iamVjdD4oKSk7
CisgICAgaWYgKGFkZFJlc3VsdC5pc05ld0VudHJ5KQorICAgICAgICBhZGRSZXN1bHQuaXRlcmF0
b3ItPnZhbHVlID0gV2VhazxKU09iamVjdD4ob2JqZWN0KTsKKyAgICBlbHNlCisgICAgICAgIEFT
U0VSVChhZGRSZXN1bHQuaXRlcmF0b3ItPnZhbHVlLmdldCgpID09IG9iamVjdCk7CiAKICAgICAv
LyBOb3RlIHRoYXQgdGhpcyBtZXRob2QgbWFrZXMgdGhlIHNvbWV3aGF0IG9kZCBkZWNpc2lvbiB0
byBub3QgY2hlY2sgaWYgdGhpcwogICAgIC8vIG9iamVjdCBjdXJyZW50bHkgaGFzIGluZGV4ZWQg
YWNjZXNzb3JzLiBXZSBjb3VsZCBkbyB0aGF0IGNoZWNrIGhlcmUsIGFuZCBpZgpJbmRleDogU291
cmNlL0phdmFTY3JpcHRDb3JlL3J1bnRpbWUvV2Vha0dDTWFwLmgKPT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PQotLS0gU291
cmNlL0phdmFTY3JpcHRDb3JlL3J1bnRpbWUvV2Vha0dDTWFwLmgJKHJldmlzaW9uIDIyMjkxMSkK
KysrIFNvdXJjZS9KYXZhU2NyaXB0Q29yZS9ydW50aW1lL1dlYWtHQ01hcC5oCSh3b3JraW5nIGNv
cHkpCkBAIC01OCw2ICs1OCwxMSBAQCBwdWJsaWM6CiAgICAgICAgIHJldHVybiBtX21hcC5zZXQo
a2V5LCBXVEZNb3ZlKHZhbHVlKSk7CiAgICAgfQogCisgICAgQWRkUmVzdWx0IGFkZChjb25zdCBL
ZXlUeXBlJiBrZXksIFZhbHVlVHlwZSB2YWx1ZSkKKyAgICB7CisgICAgICAgIHJldHVybiBtX21h
cC5hZGQoa2V5LCBXVEZNb3ZlKHZhbHVlKSk7CisgICAgfQorCiAgICAgYm9vbCByZW1vdmUoY29u
c3QgS2V5VHlwZSYga2V5KQogICAgIHsKICAgICAgICAgcmV0dXJuIG1fbWFwLnJlbW92ZShrZXkp
Owo=
</data>

          </attachment>
      

    </bug>

</bugzilla>