Bug 158350

Summary: Proxy.ownKeys should no longer throw an exception when duplicate keys are returned and the target is non-extensible
Product: WebKit Reporter: Saam Barati <sbarati>
Component: JavaScriptCoreAssignee: Saam Barati <sbarati>
Status: RESOLVED FIXED    
Severity: Normal CC: benjamin, commit-queue, fpizlo, ggaren, gskachkov, keith_miller, mark.lam, msaboff, oliver, sukolsak, webkit-bug-importer, ysuzuki
Priority: P2 Keywords: InRadar
Version: WebKit Nightly Build   
Hardware: Unspecified   
OS: Unspecified   
Attachments:
Description Flags
Patch
msaboff: review+
Patch for landing none

Description Saam Barati 2016-06-03 11:13:02 PDT
See:
https://github.com/tc39/ecma262/pull/594
Comment 1 Radar WebKit Bug Importer 2016-06-03 11:16:28 PDT
<rdar://problem/26626211>
Comment 2 Saam Barati 2016-06-03 14:29:26 PDT
Created attachment 280467 [details]
Patch
Comment 3 Mark Lam 2016-06-03 14:40:54 PDT
Comment on attachment 280467 [details]
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=280467&action=review

> Source/JavaScriptCore/runtime/ProxyObject.cpp:938
> +            bool isContainedIn = false;
> +            return isContainedIn;

Your definition of "isContainedIn" here differs from the one below.  Did you mean "isNotContainedIn" instead?
Comment 4 Michael Saboff 2016-06-03 14:41:03 PDT
Comment on attachment 280467 [details]
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=280467&action=review

r=me

> Source/JavaScriptCore/runtime/ProxyObject.cpp:934
>      auto removeIfContainedInUncheckedResultKeys = [&] (UniquedStringImpl* impl) -> bool {

This lambda's name should probably change to something without "removeIf".

> Source/JavaScriptCore/runtime/ProxyObject.cpp:938
> +            bool isContainedIn = false;
> +            return isContainedIn;

Change this to "return false".

> Source/JavaScriptCore/runtime/ProxyObject.cpp:943
> +        bool isContainedIn = true;
>          return isContainedIn;

Change this to "return true".
Comment 5 Saam Barati 2016-06-03 15:13:58 PDT
Comment on attachment 280467 [details]
Patch

View in context: https://bugs.webkit.org/attachment.cgi?id=280467&action=review

>> Source/JavaScriptCore/runtime/ProxyObject.cpp:934
>>      auto removeIfContainedInUncheckedResultKeys = [&] (UniquedStringImpl* impl) -> bool {
> 
> This lambda's name should probably change to something without "removeIf".

I think this would be more confusing. The function conditionally removes a key from the HashSet and the name of this lambda indicates that.

>>> Source/JavaScriptCore/runtime/ProxyObject.cpp:938
>>> +            return isContainedIn;
>> 
>> Your definition of "isContainedIn" here differs from the one below.  Did you mean "isNotContainedIn" instead?
> 
> Change this to "return false".

I'm going with an enum.
Comment 6 Saam Barati 2016-06-03 15:17:26 PDT
Created attachment 280471 [details]
Patch for landing
Comment 7 WebKit Commit Bot 2016-06-03 17:33:06 PDT
Comment on attachment 280471 [details]
Patch for landing

Clearing flags on attachment: 280471

Committed r201672: <http://trac.webkit.org/changeset/201672>
Comment 8 WebKit Commit Bot 2016-06-03 17:33:10 PDT
All reviewed patches have been landed.  Closing bug.