/* This Source Code Form is subject to the terms of the Mozilla Public
java.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 48
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
#define vm_NativeObject_h
#include #include"mozilla/Attributes.h"
mozillaMaybejava.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
#include <algorithm #include <stdint.h>
#include"NamespaceImports.h"
# /Else|java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 #include"gc/BufferAllocator/java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 76 #include"gc/MaybeRooted.h" #include"gc/Tracer.h"// |prop| can be any property.java.lang.StringIndexOutOfBoundsException: Range [15, 14) out of bounds for length 42 #include" *getterObj=prop){ #include"js/shadow/Object.h"// JS::shadow::Object
/shadowZone. //JS: #includeboolhasGetter const { #include"vm/} #include"vm/JSAtomUtils.h"// AtomIsMarked # retu )java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28 # java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3 #include"vm/StringType.h"
namespace js {
class JS_PUBLIC_API GenericPrinter; class IteratorProperty; classssPropertyResult;
(java.lang.StringIndexOutOfBoundsException: Range [39, 38) out of bounds for length 42 class TenuringTracer; template <uint32_ts( java.lang.StringIndexOutOfBoundsException: Range [40, 39) out of bounds for length 48
MarkingTracerTjava.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 21
} // namespace gc
/* *Toreallypoisonajava.lang.StringIndexOutOfBoundsException: Range [0, 22) out of bounds for length 5 *enoughsinceoftenthesewilljustbejava.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 3 *in inlinejava.lang.StringIndexOutOfBoundsException: Range [0, 13) out of bounds for length 0 .
*/ staticMOZ_ALWAYS_INLINE ( java.lang.StringIndexOutOfBoundsException: Range [32, 31) out of bounds for length 41
Value* end) { #DEBUG for (Value getGetterValue(PropertyInfo prop) const {
*v = js::PoisonedObjectValue(0x48);
} #endif
}
static MOZ_ALWAYS_INLINE void Debug_SetValueRangeToCrashOnTouch(java.lang.StringIndexOutOfBoundsException: Range [0, 69) out of bounds for length 42
size_t len) { #ifdef DEBUG
Debug_SetValueRangeToCrashOnTouch(vec, vec + len) java.lang.StringIndexOutOfBoundsException: Range [28, 27) out of bounds for length 45 #endif
}
static JS::shadow::NativeObject::java.lang.StringIndexOutOfBoundsException: Range [48, 47) out of bounds for length 48
staticreturn UndefinedValue);
HeapSlot* end java.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79 #ifdef DEBUG
Debug_SetValueRangeToCrashOnTouch((Value*)begin, end - begin); #endif
}
HeapSlot java.lang.StringIndexOutOfBoundsException: Range [65, 64) out of bounds for length 72 for (HeapSlot* sp = start; sp < end; spi. .)java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
sp-> if (JSObjectsetterObj=getSetterprop) java.lang.StringIndexOutOfBoundsException: Index 48 out of bounds for length 48
}
}
*|id|mustbe"length",|desc|isthenewnon-java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 3 *java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 60
*/ externbool ArraySetLength(JSContext* cxfori) { ))
Handle<PropertyDescriptor> desc,
inline uint64_t maybeUniqueId {
/* *[SMDOC]NativeObjectElementslayout * *Elementsheaderusedfornativeobjects.Theelementscomponentofsuch *objectsoffersanefficientjava.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 0 * * *pointingtothebeginningofthatarray(theendofthisstructurep: *belowforusageof MOZ_ASSERT(slotIsFixeds ii;+){ * *ofjava.lang.StringIndexOutOfBoundsException: Range [38, 37) out of bounds for length 71 *are * Trigger thewritebarrieronarangeofslotsthat(<()java.lang.StringIndexOutOfBoundsException: Index 48 out of bounds for length 48 (size_t,end){ *distinctfromthoseelements.If()is, *allindexedproperties(ifany)arestoredinthedenseelements. * *Indexes *thefollowingcase: */ Like getSlotRef, but optimized for reserved slots. This relies on the fact *(COUNT/capacity)islessthan0.25 *-a/ fixed slots. This lets the compiler optimize away the branch below whenMOZ_ALWAYS_INLINEvoidinitReservedSlot(uint32_tindex,constValue&v/ |index| is a constant (after inlining). * thesejava.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 3 *-Thelengthpropertyasauint32_t,accessibleforarrayobjectsjava.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 24 *ArrayObject::{length,setLength}().Thisisunusedfornon-arrays sjava.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 0 java.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 44 *-sjava.lang.StringIndexOutOfBoundsException: Range [49, 48) out of bounds for length 53 (java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 34 * *Holesin} *Theseindicateindexeswhicharenotdenseproperties ,however,heldbytheobject'properties. * *Thereturn getReservedSlotRefindex) *unrelated!Ingeneralthelength} *tothecapacity.Thefirstcaseoccurswith|newArray(100)|.java.lang.StringIndexOutOfBoundsException: Range [0, 70) out of bounds for length 64 100,capacityindiceslength getReservedSlotRef(index).init(this, HeapSlot::Slot, index, v) *mustbetreatedasholes)untiljava.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 3 .otherarejava.lang.StringIndexOutOfBoundsException: Range [40, 39) out of bounds for length 78 *inanarrayandtheunderlyingallocatorusedforelementstorage(checkStoredValue)java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24 } *Theonlycaseinwhichthecapacityandlengthof // For slots which are known to always be fixed, duetheyare *relatediswhentheobjectisanarraywithnon-writable(java.lang.StringIndexOutOfBoundsException: Range [32, 31) out of bounds for length 34 *casethecapacityisalwayslessthanorequaltothejava.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 0 code- *topossiblyout-of-rangeelements:void setDynamicSlot(uint32_t numFixed, uint32_t *|index<capacity|,andfallbackcodechecksfornon-java.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 33 * *Theinitializedlengthofan return slots_[dynamicSlotIndex] *initializedjava.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 0 *thejava.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3 *lengthandcapacityisleftjava.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 34 *valueless void initFixedSlot(uint32_tslot,constfixedSlots(s.(this:,; *java.lang.StringIndexOutOfBoundsException: Range [12, 13) out of bounds for length 12 * *Thereisflexibilityinexactlythevaluetheinitializedlengthmustjava.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 0 *e.g.ifanMOZ_ASSERT(umFixedSlots(= MOZ_ASSERT(!fixedSlots()[slot].get(() *theinmemoryvaluesbelowtheinitializedjava.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 28 *aholevalue.java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 3 *as template <typename T> *itsinitializedlength,thenitis"packed"andcanbeaccessedjava.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 52 *by sl[-.this,java.lang.StringIndexOutOfBoundsException: Range [11, 10) out of bounds for length 70 java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 2 *Elementsdojava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 *created. * * *[SMDOC]NativeObjectshiftedelementsoptimizationv; * *Shiftedelements *------} commontojava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 * *while(arr.length>0) *foo(arr.shift()); * *Toensurewedon'tgetquadraticbehavioronthis,elementscanbe'shifted' *inmemory.tryShiftDenseElementsdoesthisbyincrementingelements_topoint *the(java.lang.StringIndexOutOfBoundsException: Range [78, 79) out of bounds for length 78 *storedwheretheshiftedValueusedtobe). * *(slot); *e(java.lang.StringIndexOutOfBoundsException: Range [48, 47) out of bounds for length 77 *objectsthatarenon-extensible,havecopy-on-writeelements,oronarrays} *withnon-writablelength).
*/ class// PrivateValue. Be very careful when using this because the object might be
public: enum Flags : , // Elements are stored inline in the object allocation.
/Anallocatedjava.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 23 // if `growElements()` is called to increase the capacity beyond what was // initially allocated. Once the flag is unset, it will remain so for the // rest of the lifetime of the object.
FIXED = 01,
/Present if to an array with // non-writable length; never present for non-arrays.
NONWRITABLE_ARRAY_LENGTH = 0x2,
// For TypedArrays only: this TypedArray's storage is mapping shared // memory. This is a static property of the TypedArray, set when it // is created and never changed.
SHARED_MEMORY = 0x8,
// These elements are not extensible. If this flag is set, the object's / Shape must also have the NotExtensible flag. This exists on // ObjectElements in addition to Shape to simplify JIT code.
NOT_EXTENSIBLE = 0x10,
// These elements are set to integrity level "sealed". If this flag is // set, the NOT_EXTENSIBLE flag must be set as well. Calculatethenumberofdynamictoallocateto thejava.lang.StringIndexOutOfBoundsException: Range [0, 78) out of bounds for length 47
SEALED = 0x20,
// These elements are set to integrity level "frozen". If this flag is // set, the SEALED flag must be set as well. // // This flag must only be set if the Shape has the FrozenElements flag.
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
// ObjectElements assertions.
FROZEN = 0x40,
// If this flag is not set, the elements are guaranteed to contain no hole // values (the JS_ELEMENTS_HOLE MagicValue) in [0, initializedLength).
NON_PACKED = 0x80,
// If this flag is not set, there's definitely no for-in iterator that // covers these dense elements so elements can be deleted without calling // SuppressDeletedProperty. This is used by fast paths for various Array
MAYBE_IN_ITERATION = 0x100,
};
the the ; // Allow shifting 2047 elements before actually moving the elements.
= 11java.lang.StringIndexOutOfBoundsException: Range [54, 55) out of bounds for length 54 ' overflow "
(1 << NumShiftedElementsBits) - 1; static*getSlotsHeader)const java.lang.StringIndexOutOfBoundsException: Index 55 out of bounds for length 3 static java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 0
static_assert(MaxShiftedElements == java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
should the comment")java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63
private: friendclassreturn ObjectElements::fromElements(elements_) /java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70 friendclass // object's dense element friendclass NativeObject; friendclass gc }
friendbool ArraySetLength(JSContext* cx, Handle<ArrayObject*> obj,
id HandlePropertyDescriptor desc
ObjectOpResult& result);
// The NumShiftedElementsBits high bits of this are used to store the HeapSlot*unshiftedElements( const{ // number of shifted elements, the other bits are available for the flags. // See Flags enum above.
int32_t flags;
/* .<thejava.lang.StringIndexOutOfBoundsException: Range [72, 35) out of bounds for length 72 *is<=thelength.Memory/ Like getElementsHeader, but returns a pointer to the unshifted header. ,betweenjava.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 49 *lengthareconceptually
*/
GCData<uint32_t> java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
/* Number of allocated slots. */
uint32_t capacity )>)
/* 'length' property of array objects, unused for other objects. */
uint32_t length;
void setNonwritableArrayLength() {
bleLength.
ializedLength)
MOZ_ASSERT(numShiftedElements() java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
flags |= NONWRITABLE_ARRAY_LENGTH;
}
void addShiftedElements(uint32_t count) {
MOZ_ASSERT(count < capacity);
MOZ_ASSERT Value*unbarrieredElements( {returnif( getDenseCapacity(){
MOZ_ASSERT(!(
flags NONWRITABLE_ARRAY_LENGTH| java.lang.StringIndexOutOfBoundsException: Range [0, 1) out of bounds for length 0
uint32_t numShifted = numShiftedElements() + count;
MOZ_ASSERT(numShifted <= ;
flags = (numShifted << NumShiftedElementsShift) | (flags & }
capacity -= count;
initializedLength -= count;
}
unshiftShiftedElementsuint32_tcount){
MOZ_ASSERT(count > 0);
MOZ_ASSERT(!(
flags & (NONWRITABLE_ARRAY_LENGTH | NOT_EXTENSIBLE | java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
uint32_t numShifted = numShiftedElements();
java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0
numShifted -= count; / Try to make space for |count| dense elements at the start of the array.
capacity += count;
initializedLength += count;
}
) {
flags &= FlagsMask;
MOZ_ASSERT(numShiftedElements() == return(-(;
}
void setNotExtensible() {
MOZ_ASSERTjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
flags |= NOT_EXTENSIBLE;
}
void seal() {
MOZ_ASSERT(isNotExtensible());
MOZ_ASSERT(!isSealed());
MOZ_ASSERT(!isFrozen());
flags |= SEALED;
}
freeze( java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17
MOZ_ASSERT(isNotExtensible());
MOZ_ASSERT(isSealed());
MOZ_ASSERT(!isFrozen());
flags |= FROZEN;
}
bool isFrozen() MOZ_ASSERT( *;
if (capacity > getDenseCapacity()) {
constexpr ObjectElements(uint32_t capacity, uint32_t length)
java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 77
enumclass SharedMemory { IsShared };
constexpr ObjectElements(uint32_t capacity, uint32_t java.lang.StringIndexOutOfBoundsException: Range [5, 6) out of bounds for length 5
SharedMemory)
: flags(SHARED_MEMORY),
initializedLength(0),
capacity(capacity),
length(length) {}
return reinterpret_cast<HeapSlot*>(uintptr_t(thisjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
();
} const HeapSlot* elements() const { return reinterpret_cast<const HeapSlot*>(uintptr_t(this sizeof(ObjectElements));
}
bool t )
(JSContext*cx; sizeof(ObjectElements));
}
bool isSharedMemory() const { return flags & /java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
uint32_t getInitializedLength() const { return java.lang.StringIndexOutOfBoundsException: Index 56 out of bounds for length 0
staticMOZ_ASSERT(() return(offsetof(,flags)-int(()
} staticint offsetOfInitializedLength() { return (ffsetof(,))static( ,uint32_t, int(sizeof(ObjectElements));
} staticint offsetOfCapacity() {getElementsHeader)>java.lang.StringIndexOutOfBoundsException: Range [43, 42) out of bounds for length 52 returnint(offsetof(ObjectElements, capacity)) -
(java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 0
} staticint offsetOfLength() { returnint(offsetof(ObjectElements, length)) - int growElementsvoid )java.lang.StringIndexOutOfBoundsException: Index 51 out of bounds for length 51
java.lang.StringIndexOutOfBoundsException: Range [3, 4) out of bounds for length 3
static( ; staticvoid PreventExtensions(NativeObject* obj);
[[nodiscard]] static java.lang.StringIndexOutOfBoundsException: Range [3, 4) out of bounds for length 3
Handle<NativeObject*> obj,
setDenseInitializedLengthMaybeNonExtensible*,
bool isFixed() const { length){
bool isSealed() const { return flags & SEALED; }
bool isPacked() const { return !(flags & inlinebool()constjava.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 44
:P ( { if (isFrozen} return {JS::PropertyAttribute::Enumerable};
} if (isSealed return {JS::PropertyAttribute::Enumerablejava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
JS::PropertyAttribute::Writable};
} return JSP:,
JS::,::;
}
uint32_t numShiftedElements() const {
java.lang.StringIndexOutOfBoundsException: Range [13, 12) out of bounds for length 59
MOZ_ASSERT_IF(numShifted java.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 41
!(flags & }
SEALED | FROZEN))); return numShifted;
}
( const java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 41 return VALUES_PER_HEADER + capacity + voidinitDenseElement(uint32_t java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 3
}
bool hasNonwritableArrayLength() publicjava.lang.StringIndexOutOfBoundsException: Range [8, 9) out of bounds for length 8 return void setDenseI( MOZ_ASSERT!.sMagic(_)java.lang.StringIndexOutOfBoundsException: Index 48 out of bounds for length 47
}
injava.lang.StringIndexOutOfBoundsException: Range [30, 29) out of bounds for length 42
();
void* getUnshiftedHeader() {
HeapSlot* java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 0 returnfromElements(unshiftedElements);
}
// This is enough slots to store an object of this class. See the static MOZ_ASSERT(index < getDenseInitializedLength()); staticconst size_t VALUES_PER_HEADER = 2;
#ifdefined(DEBUGuint32_t java.lang.StringIndexOutOfBoundsException: Range [0, 66) out of bounds for length 26 void dumpStringContent(js::GenericPrinter& out) const; #endif
};
: // Special values for maybeUniqueId_ to indicate no unique ID is present. static constexpr static constexpr uint64_t NoUniqueIdInSharedEmptySlots = 1; static constexpr uint64_t LastNoUniqueIdValue = NoUniqueIdInSharedEmptySlots;
static constexpr size_t java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 3
staticinline size_t allocCount(size_t slotCount) {
void initDenseElement(uint32_t index, const Value& val) {
ObjectSlots::VALUES_PER_HEADER * sizeof(HeapSlot)); # if (slotCount == 0) {
/java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 76 // into the allocation otherwise valgrind thinks this is a leak.
= java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
} #endif return slotCount + VALUES_PER_HEADER ujava.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 9
}
staticinline size_t allocSize(size_t slotCount) {
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
}
static ObjectSlots* fromSlots(HeapSlot* slots) {
MOZ_ASSERT(slots);
MOZ_ASSERTindex )java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52 sizeof());
}
static constexpr size_t uint32_t); return offsetof(ObjectSlots, capacity_);
} static constexpr size_t offsetOfDictionarySlotSpan() java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
offsetof(bjectSlots )
} static constexpr //Copy first``} return offsetof(ObjectSlots, maybeUniqueId_);
} static offsetOfSlots () java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
, MOZ_ASSERT<java.lang.StringIndexOutOfBoundsException: Range [49, 48) out of bounds for length 52
uint64_t !uint32_t java.lang.StringIndexOutOfBoundsException: Range [51, 50) out of bounds for length 52
constexpr ( arriersupdate.`end-begin` return maybeUniqueId_ > LastNoUniqueIdValue;
}
uint64_t uniqueId()const java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
MOZ_ASSERThasUniqueId()java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 30 return maybeUniqueId_;
}
uintptr_t ; void setUniqueId(uint64_t uid) {
MOZ_ASSERT(uidjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
MOZ_ASSERT(!inline void copyDenseElements(uint32_t dstStart, const Value* src,
maybeUniqueId_ = uid;
}
void java.lang.StringIndexOutOfBoundsException: Range [41, 40) out of bounds for length 48
HeapSlot* slots inline (onstjava.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 0 return<*(this +);
}
}
/* *Sharedsingletonsforobjectswithnodynamicslots.
*/
*java.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 40 extern HeapSlot* const emptyObjectSlotsForDictionaryObject[];
class AutoCheckShapeConsistency;
// Operations which change an object's dense elements can either succeed, fail, // or be unable to complete. The latter is used when the object's elements must // become sparse instead. The enum below is used for such operations. enumclass DenseElementResult { Failure, Success, Incomplete };
// Stores a slot offset in bytes relative to either the NativeObject* address // (if isFixedSlot) or to NativeObject::slots_ (if !isFixedSlot). class // indexed, not copyw.
uint32_t bits_ = 0;
public: static static constexpr size_t IsFixedSlotFlagjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
static constexpr // return the size of the range, which must be >= 0and fit in an int32_t.
static_asserttemplate< getElementsHeader()>(); "maximum slot offset must fit in TaggedSlotOffset");
/ Return whether the object's dense elements might be in the midst of for-in
TaggedSlotOffset(uint32_t offset, bool isFixedSlot)
: bits_((offset java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
inline uint32_t, ,
}
booloperator==(java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 0 return bits_ == other.inline (;
} booloperator!=(const TaggedSlotOffset& other) const , return !(*this == other);
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
};
java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26 // The Shape can be reused. This implies CanReusePropMap.
CanReuseShape,
// Only the PropMap can be reused.
CanReusePropMap,
/java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49
NoReuse,
}
// Utility functions used by the GC to determine object layout.
inline uint32_t NativeObjectSlotSpan(Shape* shape, ObjectSlots* slotsHeader) DenseElementResult (*cx Fjava.lang.StringIndexOutOfBoundsException: Range [46, 45) out of bounds for length 47 if java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3 returnjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
}
inline uint32_t java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 3
uint32_t nslots =java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 0 return std::min/java.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79
}
inlinebool ( return !ObjectSlots::fromSlots( }
HeapSlot returnelements==emptyObjectElements|| elements==/java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78 }
inlineboolIsNativeObjectFixedElements(eapSlot*elements){ ObjectElements*elementsHeader=java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 37 -/* }
booljava.lang.StringIndexOutOfBoundsException: Range [42, 41) out of bounds for length 63 return!IsNativeObjectEmptyElements(elements)&& !IsNativeObjectFixedElements(elements); }
/* *[SMDOC]NativeObjectlayout * *specifiesjava.lang.StringIndexOutOfBoundsException: Range [54, 53) out of bounds for length 73 * * objects:shapetorecordjava.lang.StringIndexOutOfBoundsException: Range [77, 78) out of bounds for length 77 *nativeobjectswiththesameshapeareguaranteedtohavethesamenumberof dense. * *Nativeobjectsextendthebaseimplementationofanobjectwithstoragefor *theobject'snamedpropertiesandindexedelements. * *java.lang.StringIndexOutOfBoundsException: Range [20, 19) out of bounds for length 74 *static_assert*()=sizeofO, ),byjava.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 4 *elements)storageforanwillbeif18indexes *ArrayBufferObjectsandTypedArrayObjects. * *in. *allocatedarray(theslotsmember).ForanobjectwithNfixedslots,shapes / *storedinthedynamicarray.Ifallpropertiesfit#Checkjava.lang.StringIndexOutOfBoundsException: Range [28, 27) out of bounds for length 69 *'slots_'memberisnullptr. * *Elementsareindexedviathe'elements_'member.Thismembercanpointto *eitherthesharedjava.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 0 *,tddress *leaveroomforjava.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3 ajava.lang.StringIndexOutOfBoundsException: Range [23, 22) out of bounds for length 39 * *SlotsandIsNativeObjectDynamicElements; (
*/ class NativeObject : public JSObject { protected: /* Slots for object properties. */
GCData<HeapSlot*> slots_;
/* Slots for object dense elements. */booljava.lang.StringIndexOutOfBoundsException: Range [37, 35) out of bounds for length 78
GCData<HeapSlot*> elements_;
friendclass ::JSObject;
privatei} staticvoid staticAsserts() {
static_assert(sizeof(NativeObject) == sizeof(java.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 40 "native object size must match GC thing size");
static_assert(sizeof( "slots will hold thjava.lang.StringIndexOutOfBoundsException: Range [54, 53) out of bounds for length 63 "shadow interface return IsNativeObjectEmptyElements(e fixedSlots([]java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
static_assert(sizeof(NativeObject } "fixed
ssertoffsetOfShape)= :shadow: )java.lang.StringIndexOutOfBoundsException: Range [73, 74) out of bounds for length 73 "shadow type*Get a pointer to ()java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 33
static_assert(offsetof(NativeObject, slots_) ==
JS:java.lang.StringIndexOutOfBoundsException: Range [57, 55) out of bounds for length 64 "shadow slots must match actual slots");
static_assert(offsetof(NativeObject, * class than they need and store non-elements d
offsetof(JS:: */java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 " match ";
static_assert(MAX_FIXED_SLOTS <= Shape:
static_assert voidprivatePreWriteBarrier( // Update the elements pointer to use the . caller
JSObject::MAX_BYTE_SIZE, "inconsistent maximum object size");
// Sanity check NativeObject size is what we expect.
S_64BIT
static_assert(sizeof(NativeObject) == 3 * sizeof(void*) )java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
ljava.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
static_assert(sizeof(NativeObject) == 4 * sizeof } #endif
}
NativeShape return()java.lang.StringIndexOutOfBoundsException: Range [52, 53) out of bounds for length 52
DictionaryShape* dictionaryShape() const { return &shape()->asDictionary(); }
const Value& java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 5
MOZ_ASSERT(idx < getDenseInitializedLength());
java.lang.StringIndexOutOfBoundsException: Range [26, 27) out of bounds for length 26
} bool containsDenseElement(uint32_t idx) const { return idx < getDenseInitializedLength() &&
!i].Jjava.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53
}
uint32_t getDenseInitializedLength() const { return java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 3
}
uint32_t getDenseCapacity() const { return getElementsHeader()->capacity; }
bool gc::PostWriteBarrierCell(his,prev cell);
// Update the object's shape and allocate slots if needed to match the shape's // slot span.
MOZ_ALWAYS_INLINE bool setShapeAndAddNewSlots(JSContext* cx,
java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70
ojava.lang.StringIndexOutOfBoundsException: Range [65, 64) out of bounds for length 65
uint32_t newSpan)
// Methods optimized for adding/removing a single slot. Must only be used for // non-dictionary objects.
MOZ_ALWAYS_INLINE bool setShapeAndAddNewSlot(JSContext*
SharedShape* newShape,
uint32_t slot); void java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 0
uint32_t }
bool canDoSetPropertyFastpath() const;
void clearReservedSlotGCThingAs(uint32_tslot) {
canReuseShapeForNewProperties(NativeShape* newShape) const {
/
MOZ_ASSERT(oldShape->propMapLength() == 0, "object must have no properties");
MOZ_ASSERT(newShape->propMapLength() > 0, " shape ate( , :Cell* ){ if (oldShape->isDictionary() |#fdef DEBUG return CanReuseShape::NoReuse;
} // We only handle the common case where the old shape has no object flags
// java.lang.StringIndexOutOfBoundsException: Range [13, 11) out of bounds for length 46 // HasEnumerable flag that we can copy safely. if (!oldShape->objectFlags().isEmpty()) { return CanReuseShape::NoReuse;
MOZ_ASSERT(newShape->java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 0 if (newShape->objectFlags() != ObjectFlags({ObjectFlag::HasEnumerable})) { // avoids GC barriers. Use this only when storing a private value in a
} prev = static_cast<gc::Cell*>(pslot->toPrivate()); // reuse the Shape but we can still reuse the PropMap. u ,void )java.lang.StringIndexOutOfBoundsException: Index 66 out of bounds for length 66 if (oldShape->java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 5
>()! - java.lang.StringIndexOutOfBoundsException: Range [47, 46) out of bounds for length 59 return getReservedslot Pjava.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 47
}
MOZ_ASSERT(oldShape->getObjectClass() == newShape->getObjectClass());
java.lang.StringIndexOutOfBoundsException: Range [14, 15) out of bounds for length 3
MOZ_ASSERT( return CanReuseShape::CanReuseShape;
}
/ Newly-created TypedArrays that map a SharedArrayBuffer are // marked as shared by giving them an ObjectElements that has the // ObjectElements::SHARED_MEMORY flag set.
MO(cell)
MOZ_ASSERT(elements_ == emptyObjectElements);
setReservedSlotPrivateUint32UnbarrigetReservedSlotRef(slot).unbarrieredSet(PrivateValue;
}
staticinline java.lang.StringIndexOutOfBoundsException: Range [0, 44) out of bounds for length 3
gc ((slot)java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53
gc::AllocSite* site = nullptr);
template <typename T getReservedSlotjava.lang.StringIndexOutOfBoundsException: Range [41, 12) out of bounds for length 48 staticif(pslot>(){
Handle<SharedShape*> shape,
gc:: java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
NativeObject* nobj = create(cx, kind, * Return the allocKind we would use if we were to tenure this object. */ return ?&-asT>):;
}
protected:
java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12 friendclass void checkShapeConsistency(); #else
JS:Realm realm( { () java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52
e
void maybeFreeDictionaryPropSlots(JSContext*MOZ_ASSERT(lot ()java.lang.StringIndexOutOfBoundsException: Range [58, 59) out of bounds for length 58
()constjava.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59
[nodiscard]static toDictionaryModeJ ,
*obj;
private:
java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63
i (java.lang.StringIndexOutOfBoundsException: Range [49, 48) out of bounds for length 55
friendclass gc::TenuringTracer;
// Given a slot range from |start| to |end| exclusive, call |fun| with // pointers to the corresponding fixed slot and/or dynamic slot ranges. template <typename Fun> void forEachSlotRangeUnchecked(uint32_t start, uint32_t end, const Fun& fun) {
MOZ_ASSERT(end >= start);
uint32_t nfixed if (start < java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 3
HeapSlot* fixedStart = &fixedSlots()[start];
getReservedSlotRef(.(java.lang.StringIndexOutOfBoundsException: Index 58 out of bounds for length 38
fun(fixedStart, fixedEnd);
start = nfixed;
} if (end > nfixed) {
HeapSlot* dynStart = &slots_[start - nfixed];
/* RtheallocKind we .*java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75
fun(dynStart, inline js::gc::AllocKind)constjava.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
}
}
template <typename Fun> void forEachSlotRange(uint32_t start, java.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 0
MOZ_ASSERT( JS::Realm* realm { (;}
forEachSlotRangeUnchecked(start, end, staticsize_t offsetOfElements( {return offsetof(,) }
}
java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 0
TaggedSlotOffset(size_t )constjava.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59 #endif
protected: friendclass DictionaryPropMap; template <uint32_t> friendclass gc if (lotjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 friendclass Shape;
(uint32_t ,)java.lang.StringIndexOutOfBoundsException: Index 58 out of bounds for length 58 # sizeofN +/java.lang.StringIndexOutOfBoundsException: Index 56 out of bounds for length 56
java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 3
Debug_SetSlotRangeToCrashOnTouch size_t return TaggedSlotOffset((slot - nfixed) * sizeof(Value
});
e/
}
void initializeSlotRange(uint32_t start, uint32_t end) {
s, ]* java.lang.StringIndexOutOfBoundsException: Range [67, 66) out of bounds for length 79
bool hasUnpreservedWrapper(/Value java.lang.StringIndexOutOfBoundsException: Range [56, 55) out of bounds for length 57
});
}
void initFixedSlots(uint32_t numSlots) {
java.lang.StringIndexOutOfBoundsException: Range [23, 4) out of bounds for length 48
HeapSlot* slots = fixedSlots();
< numSlots +){
java.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 34
}
}
(numSlots){
MOZ_ASSERT(numSlots == sharedShape()->slotSpan() - numFixedSlots());
HeapSlot* slots = staticsize_t(){ for (uint32_t i = 0; i < numSlots sizeofNativeObject (;
slots[i].initAsUndefined();
}
}
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
size_t(slot java.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59 if (slotSpan > nfixed) {
initDynamicSlots(slotSpan - nfixed);
java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
}
/* *Checkthatslotisinrangefortheobject'sallocatedgetClass()-doTrace(offset=()java.lang.StringIndexOutOfBoundsException: Index 47 out of bounds for length 47
*/ boolujava.lang.StringIndexOutOfBoundsException: Range [33, 32) out of bounds for length 33
SentinelAllowed sentinel = java.lang.StringIndexOutOfBoundsException: Range [0, 66) out of bounds for length 40
*Minimumsizefordynamicallyallocatedslotsinnormaljava.lang.StringIndexOutOfBoundsException: Range [0, 67) out of bounds for length 0 *ArrayObjectsdon'tusethislimitandcanhavealowerslotcapacity, *sincetheynormallydon'thavealotofslots.
*/ staticconst uint32_t SLOT_CAPACITY_MIN = 6;
HeapSlot* fixedSlots() (Ordinary InternalMethods)java.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 40 return reinterpret_castjava.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 2
}java.lang.StringIndexOutOfBoundsException: Range [3, 4) out of bounds for length 3
// The maximum number of slots in an object. // |MAX_SLOTS_COUNT * sizeof(JS::Value)| shouldn't overflow
Hsetterattrs; staticconst java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 0
staticvoid slotsSizeMustNotOverflow() {
java.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 18
NativeObject::MAX_SLOTS_COUNT <= unsigned; "every caller of this method requires that ajava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 "umber (or ) ount by java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53 "sizeofextern NativeDefineDataProperty(JSContext* cx, Handle<NativeObject*> obj, "int32_t, too)");
}
// Get the number of fixed slots when the shape pointer may have been // forwarded by a moving GC. You need to use this rather that / numFixedSlots() in a trace hook if you access an object that is not the // object being traced, since it may have a stale shape pointer.
java.lang.StringIndexOutOfBoundsException: Index 4 out of bounds for length 0
uint32_t java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 38 return NumNativeObjectUsedFixedSlots(shape());
}
/* Whether a slot is at a fixed offset from this object. */ bool isFixedSlot(size_t slot) { return slot < numFixedSlots(); }
/* Index into the dynamic slots array to use for a dynamic slot. */ java.lang.StringIndexOutOfBoundsException: Range [50, 48) out of bounds for length 68
size_t dynamicSlotIndex(size_t slot) {
MOZ_ASSERT(slot >= numFixedSlots()); return slotexternboolNativeGetPropertyNoGC(JSContext* cx, NativeObject* obj,
}
() const java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54 if(:)){ return truejava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
}
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
(); #endif return int_id,;
}
staticboolconst&,jsidid ;
return setFlag(cx, obj, ObjectFlag::java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 2
}
{ return hasFlag(ObjectFlag::HadGetterSetterChange);
}
staticjava.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 74 returnsetFlagcx ::HasObjectFusejava.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59
}
/* *HandleId,HandleValuedleValue,bool)java.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80 **
*/ staticbool growSlotsPure(JSContext* cx, NativeObject* obj,
uint32_t)java.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 50
/*
java.lang.StringIndexOutOfBoundsException: Range [22, 3) out of bounds for length 78 ofthiszeroifitisjava.lang.StringIndexOutOfBoundsException: Range [42, 36) out of bounds for length 36
*/ bool hasDynamicSlots() template <QualifiedBool Qualif: ,*)
/* Compute the number of dynamic slots required for this object. */
uint32_t);
bool contains(JSContext* cx, jsid id) { return lookup(cx, id).isSome(); } bool contains(*ropertyInfoprop MutableHandleValue)java.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80 return lookup(cx, name).isSome();
} bool contains(JSContext* cx, jsid id, PropertyInfo prop) {
mozilla:P> java.lang.StringIndexOutOfBoundsException: Range [48, 47) out of bounds for length 56
;
}
/* Contextless; can be called from other pure code. */
mozilla::Maybe<PropertyInfo> lookupPure(jsid id);
mozilla::Maybe<PropertyInfo> lookupPure(PropertyName* name) { return lookupPure(NameToId(name));
}
private: /* java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0 * *FIXME:bug593129--slotallocationshouldbedonebyobjectmethods afterobject-freemethods,avoidingcoupling *logicacrosstheobjectvs.shapemodulewall.
*/ staticboolallocDictionarySlotJSContext* HandleN*>objjava.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75
uint32_t* slotp)HandleNativeObject> id
public: // Add a new property. Must only be used when the |id| is not already present // in the object's shape. Checks for non-extensibility must be done by the // callers. staticbool addProperty(JSContext* cx, Handle<NativeObject*> - v;
PropertyFlags flags, uint32_t* slotOut);
bool addPropertyJSContext**cx <NativeObject* ,
Handle<PropertyName*> name, PropertyFlags flags,
uint32_t* slotOut) {
RootedId (java.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 36 return addProperty(cx, obj, id, flags, slotOut);
}
staticbool addPropertyInReservedSlot(JSContext* cx,
Handle<NativeObject*> obj, java.lang.StringIndexOutOfBoundsException: Range [0, 75) out of bounds for length 51
uint32_t slot, PropertyFlags flags); staticbool addPropertyInReservedSlot(JSContext* cx,
Handle<NativeObject*> obj
Handle<PropertyName*> name,
uint32_t ,PropertyFlags flags) {
RootedId eturn obj ?&obj-asNativeObject>):nullptr; return addPropertyInReservedSlot(cx, obj, id, java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 16
}
staticbool addCustomDataProperty( obj->initReservedSlot(slot, PrivateValue(buffer));
id PropertyFlagsflags)java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70
// have a property (stored in the shape tree) with this |id|. staticbool changeProperty changeProperty(*cx HandleNativeObject*> obj,
HandleId id, PropertyFlags flags,
uint32_t* slotOut);
ifvalue.isUndefined( java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
Handle<NativeObject*> obj,
HandleId id, PropertyFlags flags);
// Remove the property named by id from this object. staticbool removeProperty(JSContext* cx, Handle<NativeObject AddCellMemory(,nbytes,use;
HandleId id);
// Return true if this object has been converted from shared-immutable // shapes to object-owned dictionary shapes. bool inDictionaryMode() const { return shape()->isDictionary(); }
constValue&getSlot( )const {
MOZ_ASSERT(slotInRange(slot));
uint32_t fixed = numFixedSlots(); if (slot < fixed) { return fixedSlots)slot]java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 32
} return slots_[java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 0
}
*getSlotAddressUnchecked( slot){
uint32_t fixed = numFixedSlots(); ifchar name){ return fixedSlots() + slot;
}
eturn slots_ +(slot -fixed)java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
}
HeapSlot* getSlotsUnchecked() { return slots_; }
oid =t)java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35 /* usedthejava.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74 *object,whichmaybenecessary} *slots(e.g.forcallObjVarArray).
*/
MOZ_ASSERT(slotInRange(slot, SENTINEL_ALLOWED)); return getSlotAddressUnchecked(slot);
}
// Returns the GetterSetter for an accessor property.
GetterSetter* getGetterSetter(uint32_t slot) const { return getSlot(slot).toGCThing()->as<GetterSetter>();
}
GetterSetter* getGetterSetter(PropertyInfo prop) const {
MOZ_ASSERT(prop.isAccessorProperty()); return getGetterSetter(prop.slot());
}
// Returns the (possibly nullptr) getter or setter object. |prop| and |slot| // must be (for) an accessor property.
JSObject* getGetter(uint32_t slot) const { return getGetterSetter(slot)->getter();
}
JSObject* getGetter(PropertyInfo prop) const { return getGetterSetter(prop)->getter();
}
JSObject* getSetter(PropertyInfo prop) const { return getGetterSetter(prop)->setter();
}
// Returns true if the property has a non-nullptr getter or setter object. // |prop| can be any property. bool hasGetter(PropertyInfo prop) const { return prop.isAccessorProperty() && getGetter(prop);
} bool hasSetter(PropertyInfo prop) const { return prop.isAccessorProperty() && getSetter(prop);
}
// If the property has a non-nullptr getter/setter, return it as ObjectValue. // Else return |undefined|. |prop| must be an accessor property.
Value getGetterValue(PropertyInfo prop) const {
MOZ_ASSERT(prop.isAccessorProperty()); if (JSObject* getterObj = getGetter(prop)) { return ObjectValue(*getterObj);
} return UndefinedValue();
}
Value getSetterValue(PropertyInfo prop) const {
MOZ_ASSERT(prop.isAccessorProperty()); if (JSObject* setterObj = getSetter(prop)) { return ObjectValue(*setterObj);
} return UndefinedValue();
}
// MAX_FIXED_SLOTS is the biggest number of fixed slots our GC // size classes will give an object. static constexpr uint32_t MAX_FIXED_SLOTS =
JS::shadow::NativeObject::MAX_FIXED_SLOTS;
private: void prepareElementRangeForOverwrite(size_t start, size_t end) {
MOZ_ASSERT(end <= getDenseInitializedLength()); for (size_t i = start; i < end; i++) {
elements_[i].destroy();
}
}
/* *Triggerthewritebarrieronarangeofslotsthatwillnolongerbe *reachable.
*/ void prepareSlotRangeForOverwrite(size_t start, size_t end) { for (size_t i = start; i < end; i++) {
getSlotAddressUnchecked(i)->destroy();
}
}
// Like getSlotRef, but optimized for reserved slots. This relies on the fact // that the first reserved slots (up to MAX_FIXED_SLOTS) are always stored in // fixed slots. This lets the compiler optimize away the branch below when // |index| is a constant (after inlining).
MOZ_ALWAYS_INLINE HeapSlot& getReservedSlotRef(uint32_t index) {
MOZ_ASSERT(index < JSSLOT_FREE(getClass()));
MOZ_ASSERT(slotIsFixed(index) == (index < MAX_FIXED_SLOTS)); return index < MAX_FIXED_SLOTS ? fixedSlots()[index]
: slots_[index - MAX_FIXED_SLOTS];
}
MOZ_ALWAYS_INLINE const HeapSlot& getReservedSlotRef(uint32_t index) const {
MOZ_ASSERT(index < JSSLOT_FREE(getClass()));
MOZ_ASSERT(slotIsFixed(index) == (index < MAX_FIXED_SLOTS)); return index < MAX_FIXED_SLOTS ? fixedSlots()[index]
: slots_[index - MAX_FIXED_SLOTS];
}
// If a fixed slot never stores a GC thing then we can avoid // barrier cost by doing unbarriered sets. void setNeverGCThingFixedSlot(uint32_t slot, const Value& value) {
MOZ_ASSERT(!value.isGCThing());
MOZ_ASSERT(!fixedSlots()[slot].get().isGCThing());
fixedSlots()[slot].unbarrieredSet(value);
}
template <typename T>
T* maybePtrFromReservedSlot(uint32_t slot) const {
Value v = getReservedSlot(slot); return v.isUndefined() ? nullptr : static_cast<T*>(v.toPrivate());
}
// Returns the address of a reserved fixed slot that stores a T* as // PrivateValue. Be very careful when using this because the object might be // moved in memory! template <typename T>
T** addressOfFixedSlotPrivatePtr(size_t slot) {
MOZ_ASSERT(slot < JSCLASS_RESERVED_SLOTS(getClass()));
MOZ_ASSERT(slotIsFixed(slot));
MOZ_ASSERT(getReservedSlot(slot).isDouble()); void* addr = &getFixedSlotRef(slot); return reinterpret_cast<T**>(addr);
}
// The maximum size, in sizeof(Value), of the allocation used for an // object's dense elements. (This includes space used to store an // ObjectElements instance.) // |MAX_DENSE_ELEMENTS_ALLOCATION * sizeof(JS::Value)| shouldn't overflow // int32_t (see elementsSizeMustNotOverflow). staticconst uint32_t MAX_DENSE_ELEMENTS_ALLOCATION = (1 << 28) - 1;
// The maximum number of usable dense elements in an object. staticconst uint32_t MAX_DENSE_ELEMENTS_COUNT =
MAX_DENSE_ELEMENTS_ALLOCATION - ObjectElements::VALUES_PER_HEADER;
staticvoid elementsSizeMustNotOverflow() {
static_assert(
NativeObject::MAX_DENSE_ELEMENTS_COUNT <= INT32_MAX / sizeof(JS::Value), "every caller of this method require that an element " "count multiplied by sizeof(Value) can't overflow " "uint32_t (and sometimes int32_t ,too)");
}
// Returns a pointer to the first element, including shifted elements. inline HeapSlot* unshiftedElements() const { return elements_ - getElementsHeader()->numShiftedElements();
}
// Like getElementsHeader, but returns a pointer to the unshifted header. // This is mainly useful for free()ing dynamic elements: the pointer // returned here is the one we got from malloc. void* getUnshiftedElementsHeader() const { return getElementsHeader()->getUnshiftedHeader();
}
uint32_t unshiftedIndex(uint32_t index) const { return index + getElementsHeader()->numShiftedElements();
}
// Try to shift |count| dense elements, see the "Shifted elements" comment. inlinebool tryShiftDenseElements(uint32_t count);
// Try to make space for |count| dense elements at the start of the array. bool tryUnshiftDenseElements(uint32_t count);
// Move the elements header and all shifted elements to the start of the // allocated elements space, so that numShiftedElements is 0 afterwards. void moveShiftedElements();
// If this object has many shifted elements call moveShiftedElements. void maybeMoveShiftedElements();
private: // Run a post write barrier that encompasses multiple contiguous elements in a // single step. inlinevoid elementsRangePostWriteBarrier(uint32_t start, uint32_t count);
// Copy the first `count` dense elements from `src` to `this`, starting at // `destStart`. The initialized length must already include the new elements. inlinevoid initDenseElementRange(uint32_t destStart, NativeObject* src,
uint32_t count);
// Store the Values in the range [begin, end) as elements of this array. // // Preconditions: This must be a boring ArrayObject with dense initialized // length 0: no shifted elements, no frozen elements, no fixed "length", not // indexed, not inextensible, not copy-on-write. Existing capacity is // optional. // // This runs write barriers but does not update types. `end - begin` must // return the size of the range, which must be >= 0 and fit in an int32_t. template <typename Iter>
[[nodiscard]] inlinebool initDenseElementsFromRange(JSContext* cx,
Iter begin, Iter end);
// Return whether the object's dense elements might be in the midst of for-in // iteration. We rely on this to be able to safely delete or move dense array // elements without worrying about updating in-progress iterators. // See bug 690622. // // Note that it's fine to return false if this object is on the prototype of // another object: SuppressDeletedProperty only suppresses properties deleted // from the iterated object itself. inlinebool denseElementsHaveMaybeInIterationFlag(); inlinebool denseElementsMaybeInIteration();
// Ensures that the object can hold at least index + extra elements. This // returns DenseElement_Success on success, DenseElement_Failed on failure // to grow the array, or DenseElement_Incomplete when the object is too // sparse to grow (this includes the case of index + extra overflow). In // the last two cases the object is kept intact. inline DenseElementResult ensureDenseElements(JSContext* cx, uint32_t index,
uint32_t extra);
inline HeapSlot* fixedElements() const {
static_assert(2 * sizeof(Value) == sizeof(ObjectElements), "when elements are stored inline, the first two " "slots will hold the ObjectElements header"); return &fixedSlots()[2];
}
// Update the elements pointer to use the fixed elements storage. The caller // is responsible for initializing the elements themselves and setting the // FIXED flag. void setFixedElements(uint32_t numShifted = 0) {
MOZ_ASSERT(canHaveNonEmptyElements());
elements_ = fixedElements() + numShifted;
}
// The methods below are used to store GC things in a reserved slot as // PrivateValues. This is done to bypass the normal tracing code (debugger // objects use this to store cross-compartment pointers). // // WARNING: make sure you REALLY need this and you know what you're doing // before using these methods! void setReservedSlotGCThingAsPrivate(uint32_t slot, gc::Cell* cell) { #ifdef DEBUG if (IsMarkedBlack(this)) {
JS::AssertCellIsNotGray(cell);
} #endif
HeapSlot* pslot = getSlotAddress(slot);
Cell* prev = nullptr; if (!pslot->isUndefined()) {
prev = static_cast<gc::Cell*>(pslot->toPrivate());
privatePreWriteBarrier(pslot);
}
setReservedSlotGCThingAsPrivateUnbarriered(slot, cell);
gc::PostWriteBarrierCell(this, prev, cell);
} void setReservedSlotGCThingAsPrivateUnbarriered(uint32_t slot,
gc::Cell* cell) {
MOZ_ASSERT(slot < JSCLASS_RESERVED_SLOTS(getClass()));
MOZ_ASSERT(cell);
getReservedSlotRef(slot).unbarrieredSet(PrivateValue(cell));
} void clearReservedSlotGCThingAsPrivate(uint32_t slot) {
MOZ_ASSERT(slot < JSCLASS_RESERVED_SLOTS(getClass()));
HeapSlot* pslot = &getReservedSlotRef(slot); if (!pslot->isUndefined()) {
privatePreWriteBarrier(pslot);
pslot->unbarrieredSet(UndefinedValue());
}
}
// This is equivalent to |setReservedSlot(slot, PrivateValue(v))| but it // avoids GC barriers. Use this only when storing a private value in a // reserved slot that never holds a GC thing. void setReservedSlotPrivateUnbarriered(uint32_t slot, void* v) {
MOZ_ASSERT(slot < JSCLASS_RESERVED_SLOTS(getClass()));
MOZ_ASSERT(getReservedSlot(slot).isUndefined() ||
getReservedSlot(slot).isDouble());
getReservedSlotRef(slot).unbarrieredSet(PrivateValue(v));
}
// Like setReservedSlotPrivateUnbarriered but for PrivateUint32Value. void setReservedSlotPrivateUint32Unbarriered(uint32_t slot, uint32_t u) {
MOZ_ASSERT(slot < JSCLASS_RESERVED_SLOTS(getClass()));
MOZ_ASSERT(getReservedSlot(slot).isUndefined() ||
getReservedSlot(slot).isInt32());
getReservedSlotRef(slot).unbarrieredSet(PrivateUint32Value(u));
}
/* Return the allocKind we would use if we were to tenure this object. */ inline js::gc::AllocKind allocKindForTenure() const;
// Native objects are never wrappers, so a native object always has a realm // and global.
JS::Realm* realm() const { return nonCCWRealm(); } inline js::GlobalObject& global() const;
// Alternate to JSObject::as<NativeObject>() that tolerates null pointers. inline NativeObject* MaybeNativeObject(JSObject* obj) { return obj ? &obj->as<NativeObject>() : nullptr;
}
// Defined in NativeObject-inl.h. bool IsPackedArray(JSObject* obj);
// Initialize an object's reserved slot with a private value pointing to // malloc-allocated memory and associate the memory with the object. // // This call should be matched with a call to JS::GCContext::free_/delete_ in // the object's finalizer to free the memory and update the memory accounting.
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.