[JSC] JSCell_freeListNext and JSCell_structureID are considered not overlapping
Created attachment 272717 [details] Patch
Comment on attachment 272717 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=272717&action=review > Source/JavaScriptCore/ftl/FTLAbstractHeapRepository.h:57 > + macro(JSCell_header, OBJECT_OFFSETOF(MarkedBlock::FreeList, head)) \ I would change the offset to just 0. The reason why MarkedBlock::FreeList::head overlaps with JSCell::structure is that they are both the first thing in the cell. "0" really is the best way of saying that.
Created attachment 272723 [details] Patch for landing
Comment on attachment 272723 [details] Patch for landing Clearing flags on attachment: 272723 Committed r197491: <http://trac.webkit.org/changeset/197491>
All reviewed patches have been landed. Closing bug.