flattenDictionaryStructure needs to zero properties that have been compressed away
Created attachment 343122 [details] Patch
Comment on attachment 343122 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=343122&action=review r=me > Source/JavaScriptCore/runtime/Structure.cpp:783 > + // We need to make sure we zero our unused butterfly space otherwise the GC might see a stale pointer. I think you can drop the "make sure we" part, and I suggest adding a semicolon after "space" and a comma after "otherwise".
Created attachment 343128 [details] Patch for landing
Committed r233001: <https://trac.webkit.org/changeset/233001>
<rdar://problem/41272865>