Stop JSObject::isUsingInlineStorage() from using the structure
Created attachment 88521 [details] Patch
Committed r83107: <http://trac.webkit.org/changeset/83107>
Comment on attachment 88521 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=88521&action=review > Source/JavaScriptCore/runtime/JSObject.h:223 > + bool isUsingInlineStorage() const { return static_cast<const void*>(m_propertyStorage) == static_cast<const void*>(this + 1); } You should only have to cast one of these two to const void*. > Source/JavaScriptCore/runtime/JSObject.h:404 > + ASSERT(static_cast<void*>(inlineStorage) == static_cast<void*>(this + 1)); You should only have to cast one of these two to void*.