Changeset 224564 in webkit for trunk/Source/JavaScriptCore/bytecode/AccessCase.cpp
- Timestamp:
- Nov 7, 2017, 10:29:31 PM (8 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/Source/JavaScriptCore/bytecode/AccessCase.cpp
r224539 r224564 625 625 CCallHelpers::Address(baseForAccessGPR, JSObject::butterflyOffset()), 626 626 loadedValueGPR); 627 jit.cage(Gigacage::JSValue, loadedValueGPR);628 627 storageGPR = loadedValueGPR; 629 628 } … … 976 975 977 976 jit.loadPtr(CCallHelpers::Address(baseGPR, JSObject::butterflyOffset()), scratchGPR3); 978 jit.cage(Gigacage::JSValue, scratchGPR3);979 977 980 978 // We have scratchGPR = new storage, scratchGPR3 = old storage, … … 1057 1055 offsetInInlineStorage(m_offset) * sizeof(JSValue))); 1058 1056 } else { 1059 if (!allocating) {1057 if (!allocating) 1060 1058 jit.loadPtr(CCallHelpers::Address(baseGPR, JSObject::butterflyOffset()), scratchGPR); 1061 jit.cage(Gigacage::JSValue, scratchGPR);1062 }1063 1059 jit.storeValue( 1064 1060 valueRegs, … … 1096 1092 case ArrayLength: { 1097 1093 jit.loadPtr(CCallHelpers::Address(baseGPR, JSObject::butterflyOffset()), scratchGPR); 1098 jit.cage(Gigacage::JSValue, scratchGPR);1099 1094 jit.load32(CCallHelpers::Address(scratchGPR, ArrayStorage::lengthOffset()), scratchGPR); 1100 1095 state.failAndIgnore.append(
Note:
See TracChangeset
for help on using the changeset viewer.