...
<rdar://problem/35667869>
Created attachment 328147 [details] patch
Comment on attachment 328147 [details] patch r=me.
Comment on attachment 328147 [details] patch View in context: https://bugs.webkit.org/attachment.cgi?id=328147&action=review > Source/JavaScriptCore/runtime/JSObject.cpp:1611 > + switchToSlowPutArrayStorage(vm); Isn't this infinitely recursing?
Comment on attachment 328147 [details] patch oops, didn't mean to set the r? flag
Comment on attachment 328147 [details] patch View in context: https://bugs.webkit.org/attachment.cgi?id=328147&action=review r=me too. >> Source/JavaScriptCore/runtime/JSObject.cpp:1611 >> + switchToSlowPutArrayStorage(vm); > > Isn't this infinitely recursing? OK, I see what's happening. The ensureArrayStorage() ensures that the indexingType is no longer ArrayClass before recursing. Nothing to see here. Moving along.
Comment on attachment 328147 [details] patch View in context: https://bugs.webkit.org/attachment.cgi?id=328147&action=review > Source/JavaScriptCore/ChangeLog:13 > + in non empty indexing types as broken, instead of having to opt out all I suggest replacing "non empty" with "non-empty" to be consistent with your usage below. Plus it's easier to read.
Created attachment 328153 [details] patch for landing
Comment on attachment 328153 [details] patch for landing Clearing flags on attachment: 328153 Committed r225423: <https://trac.webkit.org/changeset/225423>
All reviewed patches have been landed. Closing bug.