Quellcodebibliothek Statistik Leitseite products/Sources/formale Sprachen/PVS/while/pvsbin/   (PVS Prover Version 6.0.9©)  Datei vom 8.10.2014 mit Größe 1 MB image not shown  

Quelle  NativeObject.h

  Sprache: C
 

/* This Source Code Form is subject to the terms of the Mozilla Public
java.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 48
 * file, You can obtain one at http://mozilla.org/MPL/2.0/. */



#define vm_NativeObject_h

#include
#include "mozilla/Attributes.h"
mozillaMaybejava.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26

#include <algorithm
#include <stdint.h>

#include "NamespaceImports.h"

#  / Else|java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
#include "gc/BufferAllocator/java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 76
#include "gc/MaybeRooted.h"
#include "gc/Tracer.h"  // |prop| can be any property.java.lang.StringIndexOutOfBoundsException: Range [15, 14) out of bounds for length 42
#include " *getterObj=prop){
#include "js/shadow/Object.h"  // JS::shadow::Object
/shadowZone. //JS:
#include   boolhasGetter  const {
#include "vm/}
#include "vm/JSAtomUtils.h"  // AtomIsMarked
#    retu )java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
#  java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
#include "vm/StringType.h"

namespace js {

class JS_PUBLIC_API GenericPrinter;
class IteratorProperty;
classssPropertyResult;

(java.lang.StringIndexOutOfBoundsException: Range [39, 38) out of bounds for length 42
class TenuringTracer;
template <uint32_ts(  java.lang.StringIndexOutOfBoundsException: Range [40, 39) out of bounds for length 48
 MarkingTracerTjava.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 21
}  // namespace gc

/*
 * To really poison ajava.lang.StringIndexOutOfBoundsException: Range [0, 22) out of bounds for length 5
 * enough since often these will just be java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 3
 * in   inlinejava.lang.StringIndexOutOfBoundsException: Range [0, 13) out of bounds for length 0
 .
 */

staticMOZ_ALWAYS_INLINE ( java.lang.StringIndexOutOfBoundsException: Range [32, 31) out of bounds for length 41
                                                                Value* end) {
#DEBUG
  for (Value getGetterValue(PropertyInfo prop) const {
    *v = js::PoisonedObjectValue(0x48);
  }
#endif
}

static MOZ_ALWAYS_INLINE void Debug_SetValueRangeToCrashOnTouch(java.lang.StringIndexOutOfBoundsException: Range [0, 69) out of bounds for length 42
                                                                size_t len) {
#ifdef DEBUG
  Debug_SetValueRangeToCrashOnTouch(vec, vec + len)  java.lang.StringIndexOutOfBoundsException: Range [28, 27) out of bounds for length 45
#endif
}

static JS::shadow::NativeObject::java.lang.StringIndexOutOfBoundsException: Range [48, 47) out of bounds for length 48
    
#ifdef DEBUG
  Debug_SetValueRangeToCrashOnTouch((Value*)vec, len);
#endif
}

private
                                                               uint32_t len) {
#ifdef DEBUG
  Debug_SetValueRangeToCrashOnTouch((Value*)vec, len);
#endif
}

staticreturn UndefinedValue);
HeapSlot* end java.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79
#ifdef DEBUG
  Debug_SetValueRangeToCrashOnTouch((Value*)begin, end - begin);
#endif
}

   HeapSlot  java.lang.StringIndexOutOfBoundsException: Range [65, 64) out of bounds for length 72
  for (HeapSlot* sp = start; sp < end; spi.   .)java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
    sp->    if (JSObjectsetterObj=getSetterprop) java.lang.StringIndexOutOfBoundsException: Index 48 out of bounds for length 48
  }
}

class ArrayObjectreturn ObjectValue(*setterObj)}

/**
 * 10.4.2.4 ArraySetLength ( A, Desc )
 /
 * ES2025 draft rev ac21460fedf4b926520b06c9820bdbebad596a8b

 * |id| must be "length", |desc| is the new non-java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 3
* java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 60
 */

extern bool ArraySetLength(JSContext* cxfori) { )) 
                           Handle<PropertyDescriptor> desc,
                             inline uint64_t maybeUniqueId {

/*
 * [SMDOC] NativeObject Elements layout
 *
 * Elements header used for native objects. The elements component of such
 * objects offers an efficient java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 0
*       
 *   
 
 * pointing to the beginning of that array (the end of this structure   p:
 * below for usage of     MOZ_ASSERT(slotIsFixed    s i i ; +){
 *
 * of java.lang.StringIndexOutOfBoundsException: Range [38, 37) out of bounds for length 71
 * are    * Trigger thewritebarrier on a range of slots that(<()java.lang.StringIndexOutOfBoundsException: Index 48 out of bounds for length 48
    (size_t, end){
*distinctfrom those  elements.If ()is    ,
 * all indexed properties (if any) are stored in the dense elements.
 *
 * Indexes
 * the following case:
 *     / Like getSlotRef, but optimized for reserved slots. This relies on the fact
 *    (COUNT / capacity) is less than 0.25
 *  - a   / fixed slots. This lets the compiler optimize away the branch below whenMOZ_ALWAYS_INLINE void initReservedSlot(uint32_t index, const Value& v  / |index| is a constant (after inlining).
 *
 these  java.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 3
 *  - The length property as a uint32_t, accessible for array objects java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 24
 *    ArrayObject::{length,setLength}().  This is unused for non-arrays
 sjava.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 0
      java.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 44
*- s java.lang.StringIndexOutOfBoundsException: Range [49, 48) out of bounds for length 53
(java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 34
 *
 * Holes in}
 * These indicate indexes which are not dense properties
 ,however, held by the object' properties.
 *
 * The return getReservedSlotRefindex)
 * unrelated!  In general the length}
 * to the capacity.  The first case occurs with |new Array(100)|.  java.lang.StringIndexOutOfBoundsException: Range [0, 70) out of bounds for length 64
   100, capacity  indices length     getReservedSlotRef(index).init(this, HeapSlot::Slot, index, v)
 * must be treated as holes) until java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 3
 .other  are java.lang.StringIndexOutOfBoundsException: Range [40, 39) out of bounds for length 78
 * in an array and the underlying allocator used for element storage    ( checkStoredValue)java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24
   }
 * The only case in which the capacity and length of   // For slots which are known to always be fixed, duetheyare
 * related is when the object is an array with non-writable    (java.lang.StringIndexOutOfBoundsException: Range [32, 31) out of bounds for length 34
 * case the capacity is always less than or equal to the java.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 0
 code    - 
 * to possibly out-of-range elements: void setDynamicSlot(uint32_t numFixed, uint32_t
 * |index < capacity|, and fallback code checks for non-java.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 33
 *
 * The initialized length of an     return slots_[dynamicSlotIndex]
* initialized java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 0
* the  java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
 * length and capacity is left java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 34
 * value less   void initFixedSlot(uint32_t slot, const fixedSlots(s.(this :, ;
*java.lang.StringIndexOutOfBoundsException: Range [12, 13) out of bounds for length 12
 *
 * There is flexibility in exactly the value the initialized length must java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 0
 * e.g. if an  MOZ_ASSERT(umFixedSlots( =    MOZ_ASSERT(!fixedSlots()[slot].get(()
 
 * the in memory values below the initialized java.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 28
 * a hole value. java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 3
 *as     template <typename T>
 * its initialized length, then it is "packed" and can be accessed java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 52
 * by    sl[-.this,    java.lang.StringIndexOutOfBoundsException: Range [11, 10) out of bounds for length 70
 java.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 2
 * Elements dojava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
 * created.
*
 *
 * [SMDOC] NativeObject shifted elements optimization    v;
 *
 * Shifted elements
 * ------}
  common to java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
 *
 *    while (arr.length > 0)
 *        foo(arr.shift());
 *
 * To ensure we don't get quadratic behavior on this, elements can be 'shifted'
 * in memory. tryShiftDenseElements does this by incrementing elements_ to point
*the  (java.lang.StringIndexOutOfBoundsException: Range [78, 79) out of bounds for length 78
 * stored where the shifted Value used to be).
 *
 *        (slot);
*e( java.lang.StringIndexOutOfBoundsException: Range [48, 47) out of bounds for length 77
 * objects that are non-extensible, have copy-on-write elements, or on arrays  }
 * with non-writable length).
 */

class  // PrivateValue. Be very careful when using this because the object might be
 public:
  enum Flags :                           ,
    // Elements are stored inline in the object allocation.
    /Anallocatedjava.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 23
    // if `growElements()` is called to increase the capacity beyond what was
    // initially allocated. Once the flag is unset, it will remain so for the
    // rest of the lifetime of the object.
    FIXED = 01,

    /Present  if   to an array with
    // non-writable length; never present for non-arrays.
    NONWRITABLE_ARRAY_LENGTH = 0x2,

    // For TypedArrays only: this TypedArray's storage is mapping shared
    // memory.  This is a static property of the TypedArray, set when it
    // is created and never changed.
    SHARED_MEMORY = 0x8,

    // These elements are not extensible. If this flag is set, the object's
    / Shape must also have the NotExtensible flag. This exists on
    // ObjectElements in addition to Shape to simplify JIT code.
    NOT_EXTENSIBLE = 0x10,

    // These elements are set to integrity level "sealed". If this flag is
    // set, the NOT_EXTENSIBLE flag must be set as well. Calculatethenumberofdynamictoallocateto thejava.lang.StringIndexOutOfBoundsException: Range [0, 78) out of bounds for length 47
    SEALED = 0x20,

    // These elements are set to integrity level "frozen". If this flag is
    // set, the SEALED flag must be set as well.
    //
    // This flag must only be set if the Shape has the FrozenElements flag.
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  
    // ObjectElements assertions.
    FROZEN = 0x40,

    // If this flag is not set, the elements are guaranteed to contain no hole
    // values (the JS_ELEMENTS_HOLE MagicValue) in [0, initializedLength).
    NON_PACKED = 0x80,

    // If this flag is not set, there's definitely no for-in iterator that
    // covers these dense elements so elements can be deleted without calling
    // SuppressDeletedProperty. This is used by fast paths for various Array

    MAYBE_IN_ITERATION = 0x100,
  };

 the   the                                                         ;
  // Allow shifting 2047 elements before actually moving the elements.
   = 11java.lang.StringIndexOutOfBoundsException: Range [54, 55) out of bounds for length 54
          ' overflow "
      (1 << NumShiftedElementsBits) - 1;
  static*getSlotsHeader)const  java.lang.StringIndexOutOfBoundsException: Index 55 out of bounds for length 3
  static java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 0
  static_assert(MaxShiftedElements == java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
                 should the comment")java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63

 private:
  friend class     return ObjectElements::fromElements(elements_) /java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70
  friend class // object's dense element
  friend class NativeObject;
  friend class gc  }

  friend bool js::SetIntegrityLevel(JSContext
                                    IntegrityLevel level);

  friend bool ArraySetLength(JSContext* cx, Handle<ArrayObject*> obj,
                             id HandlePropertyDescriptor desc
                             ObjectOpResult& result);

  // The NumShiftedElementsBits high bits of this are used to store the HeapSlot*unshiftedElements( const{
  // number of shifted elements, the other bits are available for the flags.
  // See Flags enum above.
int32_t flags;

  /*
      .  < the java.lang.StringIndexOutOfBoundsException: Range [72, 35) out of bounds for length 72
   * is <= the length. Memory   / Like getElementsHeader, but returns a pointer to the unshifted header.
    ,  between   java.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 49
   * length are conceptually
   */

  GCData<uint32_t>        java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0

  /* Number of allocated slots. */
  uint32_t capacity       )>)

  /* 'length' property of array objects, unused for other objects. */
  uint32_t length;

  void setNonwritableArrayLength() {
bleLength.
ializedLength)
    MOZ_ASSERT(numShiftedElements() java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
    flags |= NONWRITABLE_ARRAY_LENGTH;
  }

  void addShiftedElements(uint32_t count) {
    MOZ_ASSERT(count < capacity);
    MOZ_ASSERT  Value*unbarrieredElements( {return    if(  getDenseCapacity(){
    MOZ_ASSERT(!(
        flags  NONWRITABLE_ARRAY_LENGTH| java.lang.StringIndexOutOfBoundsException: Range [0, 1) out of bounds for length 0
    uint32_t numShifted = numShiftedElements() + count;
MOZ_ASSERT(numShifted <=     ;
    flags = (numShifted << NumShiftedElementsShift) | (flags &  }
    capacity -= count;
    initializedLength -= count;
  }
   unshiftShiftedElementsuint32_tcount){
    MOZ_ASSERT(count > 0);
    MOZ_ASSERT(!(
        flags & (NONWRITABLE_ARRAY_LENGTH | NOT_EXTENSIBLE | java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
    uint32_t numShifted = numShiftedElements();
    java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0
    numShifted -= count;
  / Try to make space for |count| dense elements at the start of the array.
    capacity += count;
    initializedLength += count;
  }
) {
    flags &= FlagsMask;
    MOZ_ASSERT(numShiftedElements() ==  return(-(;
  }

  void markNonPacked() { flags |= NON_PACKED; }

  void markMaybeInIteration() { flags |= MAYBE_IN_ITERATION

  void setNotExtensible() {
MOZ_ASSERTjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
    flags |= NOT_EXTENSIBLE;
  }

  void seal() {
    MOZ_ASSERT(isNotExtensible());
    MOZ_ASSERT(!isSealed());
    MOZ_ASSERT(!isFrozen());
    flags |= SEALED;
  }
  freeze( java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17
    MOZ_ASSERT(isNotExtensible());
    MOZ_ASSERT(isSealed());
    MOZ_ASSERT(!isFrozen());
    flags |= FROZEN;
  }

  bool isFrozen()    MOZ_ASSERT(                   *;

     if (capacity > getDenseCapacity()) {
  constexpr ObjectElements(uint32_t capacity, uint32_t length)
       java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 77

  enum class SharedMemory { IsShared };

  constexpr ObjectElements(uint32_t capacity, uint32_t     java.lang.StringIndexOutOfBoundsException: Range [5, 6) out of bounds for length 5
                           SharedMemory)
      : flags(SHARED_MEMORY),
        initializedLength(0),
        capacity(capacity),
        length(length) {}

  
    return reinterpret_cast<HeapSlot*>(uintptr_t(thisjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
                     ();
  }
  const HeapSlot* elements() const {
    return reinterpret_cast<const HeapSlot*>(uintptr_t(this
                                             sizeof(ObjectElements));
  }
    bool t )
   (JSContext*cx;
                                             sizeof(ObjectElements));
  }

  bool isSharedMemory() const { return flags &  /java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74

  uint32_t getInitializedLength() const { return java.lang.StringIndexOutOfBoundsException: Index 56 out of bounds for length 0

  staticMOZ_ASSERT(()
return(offsetof(,flags)-int(()
  }
  static int offsetOfInitializedLength() {
   return (ffsetof(,))static( ,uint32_t,
           int(sizeof(ObjectElements));
  }
  static int offsetOfCapacity() {getElementsHeader)>java.lang.StringIndexOutOfBoundsException: Range [43, 42) out of bounds for length 52
    return int(offsetof(ObjectElements, capacity)) -
          (java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 0
  }
  static int offsetOfLength() {
    return int(offsetof(ObjectElements, length)) - int  growElementsvoid )java.lang.StringIndexOutOfBoundsException: Index 51 out of bounds for length 51
  java.lang.StringIndexOutOfBoundsException: Range [3, 4) out of bounds for length 3

  static(   ;
  static void PreventExtensions(NativeObject* obj);
  [[nodiscard]] static  java.lang.StringIndexOutOfBoundsException: Range [3, 4) out of bounds for length 3
                                         Handle<NativeObject*> obj,
                                         setDenseInitializedLengthMaybeNonExtensible*,

  bool isFixed() const {                                      length){

  bool isSealed() const { return flags & SEALED; }

  bool isPacked() const { return !(flags &  inlinebool()constjava.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 44

  :P (  {
    if (isFrozen}
      return {JS::PropertyAttribute::Enumerable};
    }
    if (isSealed
      return {JS::PropertyAttribute::Enumerablejava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
              JS::PropertyAttribute::Writable};
    }
return JSP:,
JS::,::;
  }

  uint32_t numShiftedElements() const {
    java.lang.StringIndexOutOfBoundsException: Range [13, 12) out of bounds for length 59
    MOZ_ASSERT_IF(numShifted  java.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 41
                  !(flags & }
                             SEALED | FROZEN)));
    return numShifted;
  }

  ( const java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 41
    return VALUES_PER_HEADER + capacity +  voidinitDenseElement(uint32_t java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 3
  }

  bool hasNonwritableArrayLength()  publicjava.lang.StringIndexOutOfBoundsException: Range [8, 9) out of bounds for length 8
    return   void setDenseI(     MOZ_ASSERT!.sMagic(_)java.lang.StringIndexOutOfBoundsException: Index 48 out of bounds for length 47
  }

    injava.lang.StringIndexOutOfBoundsException: Range [30, 29) out of bounds for length 42

    ();

  void* getUnshiftedHeader() {
    HeapSlot* java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 0
returnfromElements(unshiftedElements);
}

  // This is enough slots to store an object of this class. See the static
      MOZ_ASSERT(index < getDenseInitializedLength());
  static const size_t VALUES_PER_HEADER = 2;

#if defined(DEBUGuint32_t java.lang.StringIndexOutOfBoundsException: Range [0, 66) out of bounds for length 26
  void dumpStringContent(js::GenericPrinter& out) const;
#endif
};

static_assert(ObjectElements::VALUES_PER_HEADER * sizeof(HeapSlot) ==
                  sizeof(ObjectElements),
             shrinkCapacityToInitializedLength)

/*
  Slots header usedfornative     }
 * slot data follows in memory.
 */

 {
  GCData<uint32_t> capacity_;
  GCData<checkStoredValue
  GCData<uint64_t> maybeUniqueId_;

 :
  // Special values for maybeUniqueId_ to indicate no unique ID is present.
  static constexpr
  static constexpr uint64_t NoUniqueIdInSharedEmptySlots = 1;
  static constexpr uint64_t LastNoUniqueIdValue = NoUniqueIdInSharedEmptySlots;

  static constexpr size_t java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 3

  static inline size_t allocCount(size_t slotCount) {
    void initDenseElement(uint32_t index, const Value& val) {
                  ObjectSlots::VALUES_PER_HEADER * sizeof(HeapSlot));
#
    if (slotCount == 0) {
/java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 76
      // into the allocation otherwise valgrind thinks this is a leak.
       = java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
    }
#endif
    return slotCount + VALUES_PER_HEADER   ujava.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 9
  }

  static inline size_t allocSize(size_t slotCount) {
    java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  }

  static ObjectSlots* fromSlots(HeapSlot* slots) {
    MOZ_ASSERT(slots);
   MOZ_ASSERTindex  )java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52
           sizeof());
  }

  static constexpr size_t                                 uint32_t);
    return offsetof(ObjectSlots, capacity_);
  }
  static constexpr size_t offsetOfDictionarySlotSpan() java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
 offsetof(bjectSlots )
  }
  static constexpr  //Copy  first``}
    return offsetof(ObjectSlots, maybeUniqueId_);
  }
static offsetOfSlots   () java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73

, MOZ_ASSERT<java.lang.StringIndexOutOfBoundsException: Range [49, 48) out of bounds for length 52
                        uint64_t    !uint32_t java.lang.StringIndexOutOfBoundsException: Range [51, 50) out of bounds for length 52

  constexpr uint32_t capacity() const { return capacity_; }

  constexpruint32_t( { java.lang.StringIndexOutOfBoundsException: Index 66 out of bounds for length 0

  bool isSharedEmptySlots() const {
return maybeUniqueId_ = ;
  }

  /

constexpr  (    arriersupdate.`end-begin` 
    return maybeUniqueId_ > LastNoUniqueIdValue;
  }
  uint64_t uniqueId()const java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 29
    MOZ_ASSERThasUniqueId()java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 30
    return maybeUniqueId_;
  }
  uintptr_t ;
  void setUniqueId(uint64_t uid) {
    MOZ_ASSERT(uidjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
    MOZ_ASSERT(!inline void copyDenseElements(uint32_t dstStart, const Value* src,
    maybeUniqueId_ = uid;
  }

  void                   java.lang.StringIndexOutOfBoundsException: Range [41, 40) out of bounds for length 48

  HeapSlot* slots  inline  (onstjava.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 0
return<*(this +);
  }
}

/*
*                                                       ,
 *          uint32_t)
 * maps shared memory.
 */

emptyObjectElements
extern HeapSlot* const emptyObjectElementsShared;

/*
 * Shared singletons for objects with no dynamic slots.
 */

*java.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 40
extern HeapSlot* const emptyObjectSlotsForDictionaryObject[];

class AutoCheckShapeConsistency;

// Operations which change an object's dense elements can either succeed, fail,
// or be unable to complete. The latter is used when the object's elements must
// become sparse instead. The enum below is used for such operations.
enum class DenseElementResult { Failure, Success, Incomplete };

// Stores a slot offset in bytes relative to either the NativeObject* address
// (if isFixedSlot) or to NativeObject::slots_ (if !isFixedSlot).
class   // indexed, not  copyw.  
  uint32_t bits_ = 0;

 public:
  static
  static constexpr size_t IsFixedSlotFlagjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0

  static constexpr   // return the size of the range, which must be >= 0 and fit in an int32_t.
  static_asserttemplate<    getElementsHeader()>();
                "maximum slot offset must fit in TaggedSlotOffset");

    / Return whether the object's dense elements might be in the midst of for-in

  TaggedSlotOffset(uint32_t offset, bool isFixedSlot)
      : bits_((offset java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
      inline uint32_t, ,
  }

  uint32_t offset() const { return bits_ >> OffsetShift; }
  bool isFixedSlotinline ()

  bool operator==(java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 0
    return bits_ == other.inline     (;
  }
  bool operator!=(const TaggedSlotOffset& other) const                                                      ,
    return !(*this == other);
  java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
};

   java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
  // The Shape can be reused. This implies CanReusePropMap.
  CanReuseShape,

  // Only the PropMap can be reused.
  CanReusePropMap,

/java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49
  NoReuse,
}

// Utility functions used by the GC to determine object layout.

inline uint32_t NativeObjectSlotSpan(Shape* shape, ObjectSlots* slotsHeader)   DenseElementResult (*cx Fjava.lang.StringIndexOutOfBoundsException: Range [46, 45) out of bounds for length 47
  if  java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
    returnjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  }

  MOZ_ASSERT(slotsHeader->dictionarySlotSpan() == 0  inline DenseElementResult extendDenseElementsJSContext*cx
  return shapeuint32_t requiredCapacity
  }

inline uint32_t NumNativeObjectFixedSlots(Shape* shape) {
  auto*                    uint32_textra;
  return JS::shadow::NumObjectFixedSlots(shadowShape);
}

inline uint32_t java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 3
  uint32_t nslots =java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 0
  return std::min/java.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79
}

inlinebool (  
  return !ObjectSlots::fromSlots(  
}

HeapSlot  
  return elements == emptyObjectElements ||
         elements ==/java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
}

inline bool IsNativeObjectFixedElements(eapSlot*elements){
  ObjectElements* elementsHeader = java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 37
   -/*
}

booljava.lang.StringIndexOutOfBoundsException: Range [42, 41) out of bounds for length 63
  return !IsNativeObjectEmptyElements(elements) &&
         !IsNativeObjectFixedElements(elements);
}

/*
 * [SMDOC] NativeObject layout
 *
*specifiesjava.lang.StringIndexOutOfBoundsException: Range [54, 53) out of bounds for length 73
 *
*  objects :shapeto record  java.lang.StringIndexOutOfBoundsException: Range [77, 78) out of bounds for length 77
 * native objects with the same shape are guaranteed to have the same number of  
     dense .
 *
 * Native objects extend the base implementation of an object with storage for
 * the object's named properties and indexed elements.
 *
*  java.lang.StringIndexOutOfBoundsException: Range [20, 19) out of bounds for length 74
 * static_assert*() =sizeofO,
 ), byjava.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 4
 * elements)    storage foran willbe if 18indexes
 * ArrayBufferObjects and TypedArrayObjects.
 *
* in.
 * allocated array (the slots member). For an object with N fixed slots, shapes
 /
 * stored in the dynamic array. If all properties fit #   Check  java.lang.StringIndexOutOfBoundsException: Range [28, 27) out of bounds for length 69
 * 'slots_' member is nullptr.
 *
 * Elements are indexed via the 'elements_' member. This member can point to
 * either the shared java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 0
*,    t ddress   
 * leave room for   java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
  a java.lang.StringIndexOutOfBoundsException: Range [23, 22) out of bounds for length 39
 *
 * Slots and IsNativeObjectDynamicElements;
    (
 */

class NativeObject : public JSObject {
 protected:
  /* Slots for object properties. */
  GCData<HeapSlot*> slots_;

  /* Slots for object dense elements. */booljava.lang.StringIndexOutOfBoundsException: Range [37, 35) out of bounds for length 78
  GCData<HeapSlot*> elements_;

  friend class ::JSObject;

 privatei}
  static void staticAsserts() {
    static_assert(sizeof(NativeObject) == sizeof(java.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 40
                  "native object size must match GC thing size");
    static_assert(sizeof(                  "slots will hold thjava.lang.StringIndexOutOfBoundsException: Range [54, 53) out of bounds for length 63
                  "shadow interface     return IsNativeObjectEmptyElements(e fixedSlots([]java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
    static_assert(sizeof(NativeObject  }
                  "fixed

ssertoffsetOfShape)= :shadow: )java.lang.StringIndexOutOfBoundsException: Range [73, 74) out of bounds for length 73
                  "shadow type*Get  a pointer to     ()java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 33
    static_assert(offsetof(NativeObject, slots_) ==
                      JS:java.lang.StringIndexOutOfBoundsException: Range [57, 55) out of bounds for length 64
                  "shadow slots must match actual slots");
    static_assert(offsetof(NativeObject,    * class than they need and store non-elements d
                      offsetof(JS::   */java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
" match ";

    static_assert(MAX_FIXED_SLOTS <= Shape:
                  
    static_assert   voidprivatePreWriteBarrier(  // Update the elements pointer to use the . caller
                      JSObject::MAX_BYTE_SIZE,
                  "inconsistent maximum object size");

    // Sanity check NativeObject size is what we expect.
 S_64BIT
    static_assert(sizeof(NativeObject) == 3 * sizeof(void*)   )java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42
ljava.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
    static_assert(sizeof(NativeObject) == 4 * sizeof }
#endif
  }


  NativeShape  
  return()java.lang.StringIndexOutOfBoundsException: Range [52, 53) out of bounds for length 52
  DictionaryShape* dictionaryShape() const { return &shape()->asDictionary(); }

  PropertyInfoWithKey getLastProperty() const {
    return shape()->lastProperty();
  }

  HeapSlotArray getDenseElements() const { return HeapSlotArray(elements_); }

  const Value& java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 5
    MOZ_ASSERT(idx < getDenseInitializedLength());
java.lang.StringIndexOutOfBoundsException: Range [26, 27) out of bounds for length 26
  }
  bool containsDenseElement(uint32_t idx) const {
    return idx < getDenseInitializedLength() &&
     !i].Jjava.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53
  }
  uint32_t getDenseInitializedLength() const {
    return java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 3
  }
  uint32_t getDenseCapacity() const { return getElementsHeader()->capacity; }

  bool gc::PostWriteBarrierCell(his,prev cell);

  // Update the object's shape and allocate slots if needed to match the shape's
  // slot span.
  MOZ_ALWAYS_INLINE bool setShapeAndAddNewSlots(JSContext* cx,
                                               java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70
                                         ojava.lang.StringIndexOutOfBoundsException: Range [65, 64) out of bounds for length 65
uint32_t newSpan)

  // Methods optimized for adding/removing a single slot. Must only be used for
  // non-dictionary objects.
  MOZ_ALWAYS_INLINE bool setShapeAndAddNewSlot(JSContext*
                                               SharedShape* newShape,
                                               uint32_t slot);
  void java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 0
                                 uint32_t   }

  bool canDoSetPropertyFastpath() const;

  void clearReservedSlotGCThingAs(uint32_tslot) {
  canReuseShapeForNewProperties(NativeShape* newShape) const {
  /
    MOZ_ASSERT(oldShape->propMapLength() == 0,
               "object must have no properties");
    MOZ_ASSERT(newShape->propMapLength() > 0,
 " shape  ate( , :Cell* ){
    if (oldShape->isDictionary() |#fdef DEBUG
      return CanReuseShape::NoReuse;
    }
    // We only handle the common case where the old shape has no object flags
//      java.lang.StringIndexOutOfBoundsException: Range [13, 11) out of bounds for length 46
    // HasEnumerable flag that we can copy safely.
    if (!oldShape->objectFlags().isEmpty()) {
      return CanReuseShape::NoReuse;
    
    MOZ_ASSERT(newShape->java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 0
    if (newShape->objectFlags() != ObjectFlags({ObjectFlag::HasEnumerable})) {
  // avoids GC barriers. Use this only when storing a private value in a
    }
          prev = static_cast<gc::Cell*>(pslot->toPrivate());
    // reuse the Shape but we can still reuse the PropMap. u ,void )java.lang.StringIndexOutOfBoundsException: Index 66 out of bounds for length 66
    if (oldShape->java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 5
>()! -    java.lang.StringIndexOutOfBoundsException: Range [47, 46) out of bounds for length 59
      return                getReservedslot    Pjava.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 47
}
    MOZ_ASSERT(oldShape->getObjectClass() == newShape->getObjectClass());
    java.lang.StringIndexOutOfBoundsException: Range [14, 15) out of bounds for length 3
    MOZ_ASSERT(
    return CanReuseShape::CanReuseShape;
  }

 / Newly-created TypedArrays that map a SharedArrayBuffer are
  // marked as shared by giving them an ObjectElements that has the
  // ObjectElements::SHARED_MEMORY flag set.
      MO(cell)
    MOZ_ASSERT(elements_ == emptyObjectElements);
     setReservedSlotPrivateUint32UnbarrigetReservedSlotRef(slot).unbarrieredSet(PrivateValue;
  }

  static inline java.lang.StringIndexOutOfBoundsException: Range [0, 44) out of bounds for length 3
gc ((slot)java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53
                                     gc::AllocSite* site = nullptr);

  template <typename T               getReservedSlotjava.lang.StringIndexOutOfBoundsException: Range [41, 12) out of bounds for length 48
  staticif(pslot>(){
                          Handle<SharedShape*> shape,
                          gc:: java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
    NativeObject* nobj = create(cx, kind,         * Return the allocKind we would use if we were to tenure this object. */
return ?&-asT>):;
  }

#ifdef  }
  static void enableShapeConsistencyChecks();
#endif

 protected:
java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
  friend class  
  void checkShapeConsistency();
#else
  JS:Realm realm(  { () java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52
e

  void maybeFreeDictionaryPropSlots(JSContext*MOZ_ASSERT(lot  ()java.lang.StringIndexOutOfBoundsException: Range [58, 59) out of bounds for length 58
                                    ()constjava.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59

[nodiscard]static  toDictionaryModeJ ,
                                            *obj;

 private:
java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63

i (java.lang.StringIndexOutOfBoundsException: Range [49, 48) out of bounds for length 55

  friend class gc::TenuringTracer;

  // Given a slot range from |start| to |end| exclusive, call |fun| with
  // pointers to the corresponding fixed slot and/or dynamic slot ranges.
  template <typename Fun>
  void forEachSlotRangeUnchecked(uint32_t start, uint32_t end, const Fun& fun) {
    MOZ_ASSERT(end >= start);
    uint32_t nfixed                             
    if (start < java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 3
      HeapSlot* fixedStart = &fixedSlots()[start];
      getReservedSlotRef(.(java.lang.StringIndexOutOfBoundsException: Index 58 out of bounds for length 38
      fun(fixedStart, fixedEnd);
      start = nfixed;
    }
    if (end > nfixed) {
      HeapSlot* dynStart = &slots_[start - nfixed];
  /* RtheallocKind   we   .*java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75
      fun(dynStart,   inline js::gc::AllocKind)constjava.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
    }
  }

  template <typename Fun>
  void forEachSlotRange(uint32_t start, java.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 0
    MOZ_ASSERT(  JS::Realm* realm  { (;}
    forEachSlotRangeUnchecked(start, end,  staticsize_t offsetOfElements( {return offsetof(,) }
  }

java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 0
 TaggedSlotOffset(size_t )constjava.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59
#endif

 protected:
  friend class DictionaryPropMap;
  template <uint32_t>
  friend class gc if (lotjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  friend class Shape;

(uint32_t ,)java.lang.StringIndexOutOfBoundsException: Index 58 out of bounds for length 58
#     sizeofN +/java.lang.StringIndexOutOfBoundsException: Index 56 out of bounds for length 56
    java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 3
      Debug_SetSlotRangeToCrashOnTouch size_t    return TaggedSlotOffset((slot - nfixed) * sizeof(Value
    });
e/
  }

  void initializeSlotRange(uint32_t start, uint32_t end) {
    s, ]*  java.lang.StringIndexOutOfBoundsException: Range [67, 66) out of bounds for length 79
      bool hasUnpreservedWrapper(/Value  java.lang.StringIndexOutOfBoundsException: Range [56, 55) out of bounds for length 57
    });
  }

  void initFixedSlots(uint32_t numSlots) {
java.lang.StringIndexOutOfBoundsException: Range [23, 4) out of bounds for length 48
    HeapSlot* slots = fixedSlots();
< numSlots +){
          java.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 34
    }
  }
(numSlots){
    MOZ_ASSERT(numSlots == sharedShape()->slotSpan() - numFixedSlots());
    HeapSlot* slots =  staticsize_t(){
    for (uint32_t i = 0; i < numSlots    sizeofNativeObject  (;
      slots[i].initAsUndefined();
    }
  }
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
     size_t(slot java.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59
    if (slotSpan > nfixed) {
      initDynamicSlots(slotSpan - nfixed);
    java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
  }

#ifdef DEBUG}
  enumSentinelAllowed {SENTINEL_NOT_ALLOWED, SENTINEL_ALLOWED };

  /*
   * Check that slot is in range for the object's allocated    getClass()-doTrace(offset =()java.lang.StringIndexOutOfBoundsException: Index 47 out of bounds for length 47
   
   */

  boolujava.lang.StringIndexOutOfBoundsException: Range [33, 32) out of bounds for length 33
                   SentinelAllowed sentinel = java.lang.StringIndexOutOfBoundsException: Range [0, 66) out of bounds for length 40

  /*
   *
   */

   * Man objects noto}

  /*
   * Check whether the supplied number of fixed slots is correct.
   */

   isNumFixedSlotsnfixed ;
#endif


   * Minimum size for dynamically allocated slots in normal java.lang.StringIndexOutOfBoundsException: Range [0, 67) out of bounds for length 0
   * ArrayObjects don't use this limit and can have a lower slot capacity,
   * since they normally don't have a lot of slots.
   */

  static const uint32_t SLOT_CAPACITY_MIN = 6;

  /*
   * Minimum size for dynamically allocated elements in normal Objects.
   */

  static const uint32_t ELEMENT_CAPACITY_MIN = 6;

  HeapSlot* fixedSlots()   (Ordinary InternalMethods)java.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 40
    return reinterpret_castjava.lang.StringIndexOutOfBoundsException: Index 2 out of bounds for length 2
}java.lang.StringIndexOutOfBoundsException: Range [3, 4) out of bounds for length 3

:
inline(;

  [[nodiscard]] static bool generateNewDictionaryShape(
      JSContext* cx, Handle<NativeObject*> obj);

  // The maximum number of slots in an object.
  // |MAX_SLOTS_COUNT * sizeof(JS::Value)| shouldn't overflow
  Hsetterattrs;
  static const java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 0

  static void slotsSizeMustNotOverflow() {
java.lang.StringIndexOutOfBoundsException: Range [18, 17) out of bounds for length 18
        NativeObject::MAX_SLOTS_COUNT <=                                      unsigned;
        "every caller of this method requires that ajava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
        "umber (or  ) ount by java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53
        "sizeofextern NativeDefineDataProperty(JSContext* cx, Handle<NativeObject*> obj,
        "int32_t, too)");
  }

  uint32_t numFixedSlots() const { return NumNativeObjectFixedSlots(shape()); }

  // Get the number of fixed slots when the shape pointer may have been
  // forwarded by a moving GC. You need to use this rather that
 / numFixedSlots() in a trace hook if you access an object that is not the
  // object being traced, since it may have a stale shape pointer.
  java.lang.StringIndexOutOfBoundsException: Index 4 out of bounds for length 0

uint32_t java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 38
    return NumNativeObjectUsedFixedSlots(shape());
  }

  uint32_t slotSpan() const {
    return NativeObjectSlotSpan HandleObject getter,
  }

  dictionaryModeSlotSpan  {
    MOZ_ASSERT(inDictionaryMode());
    return getSlotsHeader()->dictionarySlotSpan()
  }

  /* Whether a slot is at a fixed offset from this object. */
  bool isFixedSlot(size_t slot) { return slot < numFixedSlots(); }

  /* Index into the dynamic slots array to use for a dynamic slot. */ java.lang.StringIndexOutOfBoundsException: Range [50, 48) out of bounds for length 68
  size_t dynamicSlotIndex(size_t slot) {
    MOZ_ASSERT(slot >= numFixedSlots());
    return slotexternboolNativeGetPropertyNoGC(JSContext* cx, NativeObject* obj,
  }

/   neverconstValuereceiver  id,Value*vp;
  bool nonProxyIsExtensible() const = delete;

  bool isExtensible() const { return !hasFlag(ObjectFlag bool ( ,<* java.lang.StringIndexOutOfBoundsException: Range [0, 70) out of bounds for length 53

  /*
         (, ObjectValueobj)
   * the object's elements.
   */

  bool isIndexed() const { return hasFlag(ObjectFlag::Indexed); }

  bool hasInterestingSymbol() const {
    return hasFlag(ObjectFlag    JSContext*cx,<ativeObject>obj  ,
  }

  bool hasEnumerableProperty() const {
    return hasFlag(ObjectFlag::HasEnumerable);
  }

  () const java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
if(:)){
      return truejava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18
    }
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
();
#endif
    return                 int_id,;
  }

  static bool  const&,jsidid  ;
                                       
    return setFlag(cx, obj, ObjectFlag::java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 2
  }
 {
    return hasFlag(ObjectFlag::HadGetterSetterChange);
  }

  staticjava.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 74
   returnsetFlagcx  ::HasObjectFusejava.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59
  }

  bool allocateInitialSlots(JSContext* cx, uint32_t capacity);

  /*
   * Grow or shrink slots immediately before changing the slot span.
   * The number                             ,index,
   * the slots must track changes in the slot span.
   */

  bool growSlots(JSContext* cx, uint32_t oldCapacity, bool GetSparseElementHelper(JSContext* cx, Handle<NativeObject
  bool growSlotsForNewSlot(JSContext* cx, uint32_t numFixed, uint32_t slot);
(JSContext cx uint32_t oldCapacity, uint32_t newCapacity;

  bool allocateSlots(Nursery& nursery, uint32_tbool AddOrUpdateSparseElementHelper(SContext , NativeSetPropertyJSContext*cx,HandleNativeObject*obj,

  /*
   *        HandleId ,HandleValuedleValue ,bool)java.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80
* *
   */

  static bool growSlotsPure(JSContext* cx, NativeObject* obj,
           uint32_t)java.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 50

  /*
   * Like growSlotsPure but for dense elements. This will return
   * false if we failed to allocate a dense element for some reason (OOM, too
   * many dense elements, non-writable array length, etc).
   */

  static bool addDenseElementPure(JSContext* cx, NativeObject* obj);

  /*
java.lang.StringIndexOutOfBoundsException: Range [22, 3) out of bounds for length 78
   ofthis   zero if it isjava.lang.StringIndexOutOfBoundsException: Range [42, 36) out of bounds for length 36
   */

  bool hasDynamicSlots() template <QualifiedBool Qualif: ,*)

  /* Compute the number of dynamic slots required for this object. */
  uint32_t);

  MOZ_ALWAYS_INLINE uint32_t numDynamicSlots() const;

#ifdef DEBUG
  outOfLineNumDynamicSlots( const;
#endif

  bool empty() const { return shape()->propMapLength() == 0; }

  mozilla::Maybe<PropertyInfo> lookup(JSContext* cx, jsid id);
mozilla:<PropertyInfo>lookup(JSContext cx,PropertyName*name) {
    return lookup(cx, NameToId(name));
  }

  bool contains(JSContext* cx, jsid id) { return lookup(cx, id).isSome(); }
  bool contains(*ropertyInfoprop MutableHandleValue)java.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80
    return lookup(cx, name).isSome();
  }
  bool contains(JSContext* cx, jsid id, PropertyInfo prop) {
mozilla:P> java.lang.StringIndexOutOfBoundsException: Range [48, 47) out of bounds for length 56
;
  }

  /* Contextless; can be called from other pure code. */
  mozilla::Maybe<PropertyInfo> lookupPure(jsid id);
  mozilla::Maybe<PropertyInfo> lookupPure(PropertyName* name) {
    return lookupPure(NameToId(name));
  }

  bool containsPure(jsid id) { return lookupPure(id).isSome(); }
  bool  bool NativeLookupOwnProperty
  bool containsPure(jsid id, PropertyInfo prop) {
mozilla:Maybe<PropertyInfo>found=lookupPure(d;
    return foundisSome)& *ound= ;
  }

 private:
  /*
    java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 0
   *
   * FIXME: bug 593129 -- slot allocation should be done by object methods
 after  object-free  methods,avoiding coupling
   * logic across the object vs. shape module wall.
   */

  staticboolallocDictionarySlotJSContext* HandleN*>objjava.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75
                                  uint32_t* slotp)HandleNativeObject> id

  void freeDictionarySlot(uint32_t slotPropertyInfo   vp;

  static MOZ_ALWAYS_INLINE bool maybeConvertToDictionaryForAdd(
      JSContext* cx, Handle<NativeObject*> obj);

 public:
  // Add a new property. Must only be used when the |id| is not already present
  // in the object's shape. Checks for non-extensibility must be done by the
  // callers.
  static bool addProperty(JSContext* cx, Handle<NativeObject*>   -                                      v;
                          PropertyFlags flags, uint32_t* slotOut);

  bool addPropertyJSContext**cx <NativeObject* ,
                          Handle<PropertyName*> name, PropertyFlags flags,
                          uint32_t* slotOut) {
RootedId (java.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 36
    return addProperty(cx, obj, id, flags, slotOut);
  }

  static bool addPropertyInReservedSlot(JSContext* cx,
                                        Handle<NativeObject*> obj, java.lang.StringIndexOutOfBoundsException: Range [0, 75) out of bounds for length 51
                                        uint32_t slot, PropertyFlags flags);
  static bool addPropertyInReservedSlot(JSContext* cx,
                                        Handle<NativeObject*> obj
                      Handle<PropertyName*> name,
                                        uint32_t ,PropertyFlags flags) {
    RootedId  eturn obj ?&obj-asNativeObject>):nullptr;
    return addPropertyInReservedSlot(cx, obj, id, java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 16
  }

  static bool addCustomDataProperty(  obj->initReservedSlot(slot, PrivateValue(buffer));
                                   id PropertyFlagsflags)java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70

 
  // have a property (stored in the shape tree) with this |id|.
  static bool changeProperty changeProperty(*cx HandleNativeObject*> obj,
                             HandleId id, PropertyFlags flags,
                             uint32_t* slotOut);

    ifvalue.isUndefined( java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
                                             Handle<NativeObject*> obj,
                                             HandleId id, PropertyFlags flags);

  // Remove the property named by id from this object.
  static bool removeProperty(JSContext* cx, Handle<NativeObject  AddCellMemory(,nbytes,use;
                             HandleId id);

  static bool freezeOrSealProperties(JSContext* cx, Handle<NativeObject*> obj,
                                     IntegrityLevel level);

  // Return true if this object has been converted from shared-immutable
  // shapes to object-owned dictionary shapes.
  bool inDictionaryMode() const { return shape()->isDictionary(); }

constValue&getSlot( )const {
    MOZ_ASSERT(slotInRange(slot));
    uint32_t fixed = numFixedSlots();
    if (slot < fixed) {
      return fixedSlots)slot]java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 32
    }
    return slots_[java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 0
  }

  const HeapSlot* getSlotAddressUnchecked(uint32_t slot) const {
ts();
    if (slot < fixed) {
      return fixedSlots(  slot;
    }
    return slots_ + (slot - fixed);
  }

  *getSlotAddressUnchecked( slot){
    uint32_t fixed = numFixedSlots();
    if                         char name){
      return fixedSlots() + slot;
    }
    eturn slots_ +(slot -fixed)java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
  }

  HeapSlot* getSlotsUnchecked() { return slots_; }

    oid =t)java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
    /*
  used    thejava.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
     * object, which may be necessary   }
     * slots (e.g. for callObjVarArray).
     */

    MOZ_ASSERT(slotInRange(slot, SENTINEL_ALLOWED));
    return getSlotAddressUnchecked(slot);
  }

  const HeapSlot* getSlotAddress(uint32_t slot) const {
    /*
     * This can be used to get the address of the end of the slots for the
     * object, which may be necessary when fetching zero-length arrays of
     * slots (e.g. for callObjVarArray).
     */

    MOZ_ASSERT(slotInRange(slot, SENTINEL_ALLOWED));
    return getSlotAddressUnchecked(slot);
  }

  MOZ_ALWAYS_INLINE HeapSlot& getSlotRef(uint32_t slot) {
    MOZ_ASSERT(slotInRange(slot));
    return *getSlotAddress(slot);
  }

  MOZ_ALWAYS_INLINE const HeapSlot& getSlotRef(uint32_t slot) const {
    MOZ_ASSERT(slotInRange(slot));
    return *getSlotAddress(slot);
  }

  // Check requirements on values stored to this object.
  MOZ_ALWAYS_INLINE void checkStoredValue(const Value& v) {
    MOZ_ASSERT(IsObjectValueInCompartment(v, compartment()));
    MOZ_ASSERT(AtomIsMarked(zoneFromAnyThread(), v));
    MOZ_ASSERT_IF(v.isMagic() && v.whyMagic() == JS_ELEMENTS_HOLE,
                  !denseElementsArePacked());
  }

  MOZ_ALWAYS_INLINE void setSlot(uint32_t slot, const Value& value) {
    MOZ_ASSERT(slotInRange(slot));
    checkStoredValue(value);
    getSlotRef(slot).set(this, HeapSlot::Slot, slot, value);
  }

  MOZ_ALWAYS_INLINE void initSlot(uint32_t slot, const Value& value) {
    MOZ_ASSERT(getSlot(slot).isUndefined());
    MOZ_ASSERT(slotInRange(slot));
    checkStoredValue(value);
    initSlotUnchecked(slot, value);
  }

  MOZ_ALWAYS_INLINE void initSlotUnchecked(uint32_t slot, const Value& value) {
    getSlotAddressUnchecked(slot)->init(this, HeapSlot::Slot, slot, value);
  }

  // Returns the GetterSetter for an accessor property.
  GetterSetter* getGetterSetter(uint32_t slot) const {
    return getSlot(slot).toGCThing()->as<GetterSetter>();
  }
  GetterSetter* getGetterSetter(PropertyInfo prop) const {
    MOZ_ASSERT(prop.isAccessorProperty());
    return getGetterSetter(prop.slot());
  }

  // Returns the (possibly nullptr) getter or setter object. |prop| and |slot|
  // must be (for) an accessor property.
  JSObject* getGetter(uint32_t slot) const {
    return getGetterSetter(slot)->getter();
  }
  JSObject* getGetter(PropertyInfo prop) const {
    return getGetterSetter(prop)->getter();
  }
  JSObject* getSetter(PropertyInfo prop) const {
    return getGetterSetter(prop)->setter();
  }

  // Returns true if the property has a non-nullptr getter or setter object.
  // |prop| can be any property.
  bool hasGetter(PropertyInfo prop) const {
    return prop.isAccessorProperty() && getGetter(prop);
  }
  bool hasSetter(PropertyInfo prop) const {
    return prop.isAccessorProperty() && getSetter(prop);
  }

  // If the property has a non-nullptr getter/setter, return it as ObjectValue.
  // Else return |undefined|. |prop| must be an accessor property.
  Value getGetterValue(PropertyInfo prop) const {
    MOZ_ASSERT(prop.isAccessorProperty());
    if (JSObject* getterObj = getGetter(prop)) {
      return ObjectValue(*getterObj);
    }
    return UndefinedValue();
  }
  Value getSetterValue(PropertyInfo prop) const {
    MOZ_ASSERT(prop.isAccessorProperty());
    if (JSObject* setterObj = getSetter(prop)) {
      return ObjectValue(*setterObj);
    }
    return UndefinedValue();
  }

  [[nodiscard]] bool setUniqueId(JSRuntime* runtime, uint64_t uid);
  inline bool hasUniqueId() const { return getSlotsHeader()->hasUniqueId(); }
  inline uint64_t uniqueId() const { return getSlotsHeader()->uniqueId(); }
  inline uint64_t maybeUniqueId() const {
    return getSlotsHeader()->maybeUniqueId();
  }

  // MAX_FIXED_SLOTS is the biggest number of fixed slots our GC
  // size classes will give an object.
  static constexpr uint32_t MAX_FIXED_SLOTS =
      JS::shadow::NativeObject::MAX_FIXED_SLOTS;

 private:
  void prepareElementRangeForOverwrite(size_t start, size_t end) {
    MOZ_ASSERT(end <= getDenseInitializedLength());
    for (size_t i = start; i < end; i++) {
      elements_[i].destroy();
    }
  }

  /*
   * Trigger the write barrier on a range of slots that will no longer be
   * reachable.
   */

  void prepareSlotRangeForOverwrite(size_t start, size_t end) {
    for (size_t i = start; i < end; i++) {
      getSlotAddressUnchecked(i)->destroy();
    }
  }

  inline void shiftDenseElementsUnchecked(uint32_t count);

  // Like getSlotRef, but optimized for reserved slots. This relies on the fact
  // that the first reserved slots (up to MAX_FIXED_SLOTS) are always stored in
  // fixed slots. This lets the compiler optimize away the branch below when
  // |index| is a constant (after inlining).
  MOZ_ALWAYS_INLINE HeapSlot& getReservedSlotRef(uint32_t index) {
    MOZ_ASSERT(index < JSSLOT_FREE(getClass()));
    MOZ_ASSERT(slotIsFixed(index) == (index < MAX_FIXED_SLOTS));
    return index < MAX_FIXED_SLOTS ? fixedSlots()[index]
                                   : slots_[index - MAX_FIXED_SLOTS];
  }
  MOZ_ALWAYS_INLINE const HeapSlot& getReservedSlotRef(uint32_t index) const {
    MOZ_ASSERT(index < JSSLOT_FREE(getClass()));
    MOZ_ASSERT(slotIsFixed(index) == (index < MAX_FIXED_SLOTS));
    return index < MAX_FIXED_SLOTS ? fixedSlots()[index]
                                   : slots_[index - MAX_FIXED_SLOTS];
  }

 public:
  MOZ_ALWAYS_INLINE const Value& getReservedSlot(uint32_t index) const {
    return getReservedSlotRef(index);
  }
  MOZ_ALWAYS_INLINE void initReservedSlot(uint32_t index, const Value& v) {
    MOZ_ASSERT(getReservedSlot(index).isUndefined());
    checkStoredValue(v);
    getReservedSlotRef(index).init(this, HeapSlot::Slot, index, v);
  }
  MOZ_ALWAYS_INLINE void setReservedSlot(uint32_t index, const Value& v) {
    checkStoredValue(v);
    getReservedSlotRef(index).set(this, HeapSlot::Slot, index, v);
  }

  // For slots which are known to always be fixed, due to the way they are
  // allocated.

  HeapSlot& getFixedSlotRef(uint32_t slot) {
    MOZ_ASSERT(slotIsFixed(slot));
    return fixedSlots()[slot];
  }

  const Value& getFixedSlot(uint32_t slot) const {
    MOZ_ASSERT(slotIsFixed(slot));
    return fixedSlots()[slot];
  }

  const Value& getDynamicSlot(uint32_t dynamicSlotIndex) const {
    MOZ_ASSERT(dynamicSlotIndex < outOfLineNumDynamicSlots());
    return slots_[dynamicSlotIndex];
  }

  void setFixedSlot(uint32_t slot, const Value& value) {
    MOZ_ASSERT(slotIsFixed(slot));
    checkStoredValue(value);
    fixedSlots()[slot].set(this, HeapSlot::Slot, slot, value);
  }

  // If a fixed slot never stores a GC thing then we can avoid
  // barrier cost by doing unbarriered sets.
  void setNeverGCThingFixedSlot(uint32_t slot, const Value& value) {
    MOZ_ASSERT(!value.isGCThing());
    MOZ_ASSERT(!fixedSlots()[slot].get().isGCThing());
    fixedSlots()[slot].unbarrieredSet(value);
  }

  void setDynamicSlot(uint32_t numFixed, uint32_t slot, const Value& value) {
    MOZ_ASSERT(numFixedSlots() == numFixed);
    MOZ_ASSERT(slot >= numFixed);
    MOZ_ASSERT(slot - numFixed < getSlotsHeader()->capacity());
    checkStoredValue(value);
    slots_[slot - numFixed].set(this, HeapSlot::Slot, slot, value);
  }

  void initFixedSlot(uint32_t slot, const Value& value) {
    MOZ_ASSERT(slotIsFixed(slot));
    checkStoredValue(value);
    fixedSlots()[slot].init(this, HeapSlot::Slot, slot, value);
  }

  void initDynamicSlot(uint32_t numFixed, uint32_t slot, const Value& value) {
    MOZ_ASSERT(numFixedSlots() == numFixed);
    MOZ_ASSERT(slot >= numFixed);
    MOZ_ASSERT(slot - numFixed < getSlotsHeader()->capacity());
    checkStoredValue(value);
    slots_[slot - numFixed].init(this, HeapSlot::Slot, slot, value);
  }

  template <typename T>
  T* maybePtrFromReservedSlot(uint32_t slot) const {
    Value v = getReservedSlot(slot);
    return v.isUndefined() ? nullptr : static_cast<T*>(v.toPrivate());
  }

  // Returns the address of a reserved fixed slot that stores a T* as
  // PrivateValue. Be very careful when using this because the object might be
  // moved in memory!
  template <typename T>
  T** addressOfFixedSlotPrivatePtr(size_t slot) {
    MOZ_ASSERT(slot < JSCLASS_RESERVED_SLOTS(getClass()));
    MOZ_ASSERT(slotIsFixed(slot));
    MOZ_ASSERT(getReservedSlot(slot).isDouble());
    void* addr = &getFixedSlotRef(slot);
    return reinterpret_cast<T**>(addr);
  }

  /*
   * Calculate the number of dynamic slots to allocate to cover the properties
   * in an object with the given number of fixed slots and slot span.
   */

  static MOZ_ALWAYS_INLINE uint32_t calculateDynamicSlots(uint32_t nfixed,
                                                          uint32_t span,
                                                          const JSClass* clasp);
  static MOZ_ALWAYS_INLINE uint32_t calculateDynamicSlots(SharedShape* shape);

  ObjectSlots* getSlotsHeader() const { return ObjectSlots::fromSlots(slots_); }

  /* Elements accessors. */

  // The maximum size, in sizeof(Value), of the allocation used for an
  // object's dense elements.  (This includes space used to store an
  // ObjectElements instance.)
  // |MAX_DENSE_ELEMENTS_ALLOCATION * sizeof(JS::Value)| shouldn't overflow
  // int32_t (see elementsSizeMustNotOverflow).
  static const uint32_t MAX_DENSE_ELEMENTS_ALLOCATION = (1 << 28) - 1;

  // The maximum number of usable dense elements in an object.
  static const uint32_t MAX_DENSE_ELEMENTS_COUNT =
      MAX_DENSE_ELEMENTS_ALLOCATION - ObjectElements::VALUES_PER_HEADER;

  static void elementsSizeMustNotOverflow() {
    static_assert(
        NativeObject::MAX_DENSE_ELEMENTS_COUNT <= INT32_MAX / sizeof(JS::Value),
        "every caller of this method require that an element "
        "count multiplied by sizeof(Value) can't overflow "
        "uint32_t (and sometimes int32_t ,too)");
  }

  ObjectElements* getElementsHeader() const {
    return ObjectElements::fromElements(elements_);
  }

  Value* unbarrieredElements() { return elements_->unbarrieredAddress(); }

  // Returns a pointer to the first element, including shifted elements.
  inline HeapSlot* unshiftedElements() const {
    return elements_ - getElementsHeader()->numShiftedElements();
  }

  // Like getElementsHeader, but returns a pointer to the unshifted header.
  // This is mainly useful for free()ing dynamic elements: the pointer
  // returned here is the one we got from malloc.
  void* getUnshiftedElementsHeader() const {
    return getElementsHeader()->getUnshiftedHeader();
  }

  uint32_t unshiftedIndex(uint32_t index) const {
    return index + getElementsHeader()->numShiftedElements();
  }

  /* Accessors for elements. */
  bool ensureElements(JSContext* cx, uint32_t capacity) {
    MOZ_ASSERT(isExtensible());
    if (capacity > getDenseCapacity()) {
      return growElements(cx, capacity);
    }
    return true;
  }

  // Try to shift |count| dense elements, see the "Shifted elements" comment.
  inline bool tryShiftDenseElements(uint32_t count);

  // Try to make space for |count| dense elements at the start of the array.
  bool tryUnshiftDenseElements(uint32_t count);

  // Move the elements header and all shifted elements to the start of the
  // allocated elements space, so that numShiftedElements is 0 afterwards.
  void moveShiftedElements();

  // If this object has many shifted elements call moveShiftedElements.
  void maybeMoveShiftedElements();

  static bool goodElementsAllocationAmount(JSContext* cx, uint32_t reqAllocated,
                                           uint32_t length,
                                           uint32_t* goodAmount);
  bool growElements(JSContext* cx, uint32_t newcap);
  void shrinkElements(JSContext* cx, uint32_t cap);

 private:
  // Run a post write barrier that encompasses multiple contiguous elements in a
  // single step.
  inline void elementsRangePostWriteBarrier(uint32_t start, uint32_t count);

  inline bool canMoveElementsHeader() const;

 public:
  void shrinkCapacityToInitializedLength(JSContext* cx);

 private:
  void setDenseInitializedLengthInternal(uint32_t length) {
    MOZ_ASSERT(length <= getDenseCapacity());
    MOZ_ASSERT(!denseElementsAreFrozen());
    prepareElementRangeForOverwrite(length,
                                    getElementsHeader()->initializedLength);
    getElementsHeader()->initializedLength = length;
  }

 public:
  void setDenseInitializedLength(uint32_t length) {
    MOZ_ASSERT(isExtensible());
    setDenseInitializedLengthInternal(length);
  }

  void setDenseInitializedLengthMaybeNonExtensible(JSContext* cx,
                                                   uint32_t length) {
    setDenseInitializedLengthInternal(length);
    if (!isExtensible()) {
      shrinkCapacityToInitializedLength(cx);
    }
  }

  inline void ensureDenseInitializedLength(uint32_t index, uint32_t extra);

  void setDenseElement(uint32_t index, const Value& val) {
    MOZ_ASSERT_IF(val.isMagic(), val.whyMagic() != JS_ELEMENTS_HOLE);
    setDenseElementUnchecked(index, val);
  }

  void initDenseElement(uint32_t index, const Value& val) {
    MOZ_ASSERT(!val.isMagic(JS_ELEMENTS_HOLE));
    initDenseElementUnchecked(index, val);
  }

 private:
  // Note: 'Unchecked' here means we don't assert |val| isn't the hole
  // MagicValue.
  void initDenseElementUnchecked(uint32_t index, const Value& val) {
    MOZ_ASSERT(index < getDenseInitializedLength());
    MOZ_ASSERT(isExtensible());
    checkStoredValue(val);
    elements_[index].init(this, HeapSlot::Element, unshiftedIndex(index), val);
  }
  void setDenseElementUnchecked(uint32_t index, const Value& val) {
    MOZ_ASSERT(index < getDenseInitializedLength());
    MOZ_ASSERT(!denseElementsAreFrozen());
    checkStoredValue(val);
    elements_[index].set(this, HeapSlot::Element, unshiftedIndex(index), val);
  }

  // Mark the dense elements as possibly containing holes.
  inline void markDenseElementsNotPacked();

 public:
  inline void initDenseElementHole(uint32_t index);
  inline void setDenseElementHole(uint32_t index);
  inline void removeDenseElementForSparseIndex(uint32_t index);

  inline void copyDenseElements(uint32_t dstStart, const Value* src,
                                uint32_t count);

  inline void initDenseElements(const Value* src, uint32_t count);
  inline void initDenseElements(IteratorProperty* src, uint32_t count);
  inline void initDenseElements(NativeObject* src, uint32_t srcStart,
                                uint32_t count);

  // Copy the first `count` dense elements from `src` to `this`, starting at
  // `destStart`. The initialized length must already include the new elements.
  inline void initDenseElementRange(uint32_t destStart, NativeObject* src,
                                    uint32_t count);

  // Store the Values in the range [begin, end) as elements of this array.
  //
  // Preconditions: This must be a boring ArrayObject with dense initialized
  // length 0: no shifted elements, no frozen elements, no fixed "length", not
  // indexed, not inextensible, not copy-on-write. Existing capacity is
  // optional.
  //
  // This runs write barriers but does not update types. `end - begin` must
  // return the size of the range, which must be >= 0 and fit in an int32_t.
  template <typename Iter>
  [[nodiscard]] inline bool initDenseElementsFromRange(JSContext* cx,
                                                       Iter begin, Iter end);

  inline void moveDenseElements(uint32_t dstStart, uint32_t srcStart,
                                uint32_t count);
  inline void reverseDenseElementsNoPreBarrier(uint32_t length);

  inline DenseElementResult setOrExtendDenseElements(JSContext* cx,
                                                     uint32_t start,
                                                     const Value* vp,
                                                     uint32_t count);

  bool denseElementsAreSealed() const {
    return getElementsHeader()->isSealed();
  }
  bool denseElementsAreFrozen() const {
    return hasFlag(ObjectFlag::FrozenElements);
  }

  bool denseElementsArePacked() const {
    return getElementsHeader()->isPacked();
  }

  void markDenseElementsMaybeInIteration() {
    getElementsHeader()->markMaybeInIteration();
  }

  // Return whether the object's dense elements might be in the midst of for-in
  // iteration. We rely on this to be able to safely delete or move dense array
  // elements without worrying about updating in-progress iterators.
  // See bug 690622.
  //
  // Note that it's fine to return false if this object is on the prototype of
  // another object: SuppressDeletedProperty only suppresses properties deleted
  // from the iterated object itself.
  inline bool denseElementsHaveMaybeInIterationFlag();
  inline bool denseElementsMaybeInIteration();

  // Ensures that the object can hold at least index + extra elements. This
  // returns DenseElement_Success on success, DenseElement_Failed on failure
  // to grow the array, or DenseElement_Incomplete when the object is too
  // sparse to grow (this includes the case of index + extra overflow). In
  // the last two cases the object is kept intact.
  inline DenseElementResult ensureDenseElements(JSContext* cx, uint32_t index,
                                                uint32_t extra);

  inline DenseElementResult extendDenseElements(JSContext* cx,
                                                uint32_t requiredCapacity,
                                                uint32_t extra);

  /* Small objects are dense, no matter what. */
  static const uint32_t MIN_SPARSE_INDEX = 1000;

  /*
   * Element storage for an object will be sparse if fewer than 1/8 indexes
   * are filled in.
   */

  static const unsigned SPARSE_DENSITY_RATIO = 8;

  /*
   * Check if after growing the object's elements will be too sparse.
   * newElementsHint is an estimated number of elements to be added.
   */

  bool willBeSparseElements(uint32_t requiredCapacity,
                            uint32_t newElementsHint);

  /*
   * After adding a sparse index to obj, see if it should be converted to use
   * dense elements.
   */

  static DenseElementResult maybeDensifySparseElements(
      JSContext* cx, Handle<NativeObject*> obj);
  static bool densifySparseElements(JSContext* cx, Handle<NativeObject*> obj);

  inline HeapSlot* fixedElements() const {
    static_assert(2 * sizeof(Value) == sizeof(ObjectElements),
                  "when elements are stored inline, the first two "
                  "slots will hold the ObjectElements header");
    return &fixedSlots()[2];
  }

#ifdef DEBUG
  bool canHaveNonEmptyElements();
#endif

  void setEmptyElements() { elements_ = emptyObjectElements; }

  void initFixedElements(gc::AllocKind kind, uint32_t length);

  // Update the elements pointer to use the fixed elements storage. The caller
  // is responsible for initializing the elements themselves and setting the
  // FIXED flag.
  void setFixedElements(uint32_t numShifted = 0) {
    MOZ_ASSERT(canHaveNonEmptyElements());
    elements_ = fixedElements() + numShifted;
  }

  inline bool hasDynamicElements() const {
    return IsNativeObjectDynamicElements(elements_);
  }

  inline bool hasFixedElements() const {
    bool fixed = IsNativeObjectFixedElements(elements_);
    MOZ_ASSERT_IF(fixed, unshiftedElements() == fixedElements());
    return fixed;
  }

  inline bool hasEmptyElements() const {
    return IsNativeObjectEmptyElements(elements_);
  }

  /*
   * Get a pointer to the unused data in the object's allocation immediately
   * following this object, for use with objects which allocate a larger size
   * class than they need and store non-elements data inline.
   */

  inline uint8_t* fixedData(size_t nslots) const;

  inline void privatePreWriteBarrier(HeapSlot* pprivate);

  // The methods below are used to store GC things in a reserved slot as
  // PrivateValues. This is done to bypass the normal tracing code (debugger
  // objects use this to store cross-compartment pointers).
  //
  // WARNING: make sure you REALLY need this and you know what you're doing
  // before using these methods!
  void setReservedSlotGCThingAsPrivate(uint32_t slot, gc::Cell* cell) {
#ifdef DEBUG
    if (IsMarkedBlack(this)) {
      JS::AssertCellIsNotGray(cell);
    }
#endif
    HeapSlot* pslot = getSlotAddress(slot);
    Cell* prev = nullptr;
    if (!pslot->isUndefined()) {
      prev = static_cast<gc::Cell*>(pslot->toPrivate());
      privatePreWriteBarrier(pslot);
    }
    setReservedSlotGCThingAsPrivateUnbarriered(slot, cell);
    gc::PostWriteBarrierCell(this, prev, cell);
  }
  void setReservedSlotGCThingAsPrivateUnbarriered(uint32_t slot,
                                                  gc::Cell* cell) {
    MOZ_ASSERT(slot < JSCLASS_RESERVED_SLOTS(getClass()));
    MOZ_ASSERT(cell);
    getReservedSlotRef(slot).unbarrieredSet(PrivateValue(cell));
  }
  void clearReservedSlotGCThingAsPrivate(uint32_t slot) {
    MOZ_ASSERT(slot < JSCLASS_RESERVED_SLOTS(getClass()));
    HeapSlot* pslot = &getReservedSlotRef(slot);
    if (!pslot->isUndefined()) {
      privatePreWriteBarrier(pslot);
      pslot->unbarrieredSet(UndefinedValue());
    }
  }

  // This is equivalent to |setReservedSlot(slot, PrivateValue(v))| but it
  // avoids GC barriers. Use this only when storing a private value in a
  // reserved slot that never holds a GC thing.
  void setReservedSlotPrivateUnbarriered(uint32_t slot, void* v) {
    MOZ_ASSERT(slot < JSCLASS_RESERVED_SLOTS(getClass()));
    MOZ_ASSERT(getReservedSlot(slot).isUndefined() ||
               getReservedSlot(slot).isDouble());
    getReservedSlotRef(slot).unbarrieredSet(PrivateValue(v));
  }

  // Like setReservedSlotPrivateUnbarriered but for PrivateUint32Value.
  void setReservedSlotPrivateUint32Unbarriered(uint32_t slot, uint32_t u) {
    MOZ_ASSERT(slot < JSCLASS_RESERVED_SLOTS(getClass()));
    MOZ_ASSERT(getReservedSlot(slot).isUndefined() ||
               getReservedSlot(slot).isInt32());
    getReservedSlotRef(slot).unbarrieredSet(PrivateUint32Value(u));
  }

  /* Return the allocKind we would use if we were to tenure this object. */
  inline js::gc::AllocKind allocKindForTenure() const;

  // Native objects are never wrappers, so a native object always has a realm
  // and global.
  JS::Realm* realm() const { return nonCCWRealm(); }
  inline js::GlobalObject& global() const;

  TaggedSlotOffset getTaggedSlotOffset(size_t slot) const {
    MOZ_ASSERT(slot < slotSpan());
    uint32_t nfixed = numFixedSlots();
    if (slot < nfixed) {
      return TaggedSlotOffset(getFixedSlotOffset(slot),
                              /* isFixedSlot = */ true);
    }
    return TaggedSlotOffset((slot - nfixed) * sizeof(Value),
                            /* isFixedSlot = */ false);
  }

  bool hasUnpreservedWrapper() const {
    return getClass()->preservesWrapper() &&
           !shape()->hasObjectFlag(ObjectFlag::HasPreservedWrapper);
  }

  /* JIT Accessors */
  static size_t offsetOfElements() { return offsetof(NativeObject, elements_); }
  static size_t offsetOfFixedElements() {
    return sizeof(NativeObject) + sizeof(ObjectElements);
  }

  static constexpr size_t getFixedSlotOffset(size_t slot) {
    MOZ_ASSERT(slot < MAX_FIXED_SLOTS);
    return sizeof(NativeObject) + slot * sizeof(Value);
  }
  static constexpr size_t getFixedSlotIndexFromOffset(size_t offset) {
    MOZ_ASSERT(offset >= sizeof(NativeObject));
    offset -= sizeof(NativeObject);
    MOZ_ASSERT(offset % sizeof(Value) == 0);
    MOZ_ASSERT(offset / sizeof(Value) < MAX_FIXED_SLOTS);
    return offset / sizeof(Value);
  }
  static constexpr size_t getDynamicSlotIndexFromOffset(size_t offset) {
    MOZ_ASSERT(offset % sizeof(Value) == 0);
    return offset / sizeof(Value);
  }
  static size_t offsetOfSlots() { return offsetof(NativeObject, slots_); }
};

inline void NativeObject::privatePreWriteBarrier(HeapSlot* pprivate) {
  JS::shadow::Zone* shadowZone = this->shadowZoneFromAnyThread();
  if (shadowZone->needsMarkingBarrier() && pprivate->get().toPrivate() &&
      getClass()->hasTrace()) {
    getClass()->doTrace(shadowZone->barrierTracer(), this);
  }
}

/*** Standard internal methods **********************************************/

/*
 * These functions should follow the algorithms in ES2025 section 10.1
 * ("Ordinary Object Internal Methods").
 *
 * Many native objects are not "ordinary" in ES2025, so these functions also
 * have to serve some of the special needs of Arrays (10.4.2), Strings (10.4.3),
 * and so on.
 */


extern bool NativeDefineProperty(JSContext* cx, Handle<NativeObject*> obj,
                                 HandleId id,
                                 Handle<JS::PropertyDescriptor> desc,
                                 ObjectOpResult& result);

extern bool NativeDefineDataProperty(JSContext* cx, Handle<NativeObject*> obj,
                                     HandleId id, HandleValue value,
                                     unsigned attrs, ObjectOpResult& result);

/* If the result out-param is omitted, throw on failure. */

extern bool NativeDefineAccessorProperty(JSContext* cx,
                                         Handle<NativeObject*> obj, HandleId id,
                                         HandleObject getter,
                                         HandleObject setter, unsigned attrs);

extern bool NativeDefineDataProperty(JSContext* cx, Handle<NativeObject*> obj,
                                     HandleId id, HandleValue value,
                                     unsigned attrs);

extern bool NativeDefineDataProperty(JSContext* cx, Handle<NativeObject*> obj,
                                     PropertyName* name, HandleValue value,
                                     unsigned attrs);

extern bool NativeHasProperty(JSContext* cx, Handle<NativeObject*> obj,
                              HandleId id, bool* foundp);

extern bool NativeGetOwnPropertyDescriptor(
    JSContext* cx, Handle<NativeObject*> obj, HandleId id,
    MutableHandle<mozilla::Maybe<JS::PropertyDescriptor>> desc);

extern bool NativeGetProperty(JSContext* cx, Handle<NativeObject*> obj,
                              HandleValue receiver, HandleId id,
                              MutableHandleValue vp);

extern bool NativeGetPropertyNoGC(JSContext* cx, NativeObject* obj,
                                  const Value& receiver, jsid id, Value* vp);

inline bool NativeGetProperty(JSContext* cx, Handle<NativeObject*> obj,
                              HandleId id, MutableHandleValue vp) {
  RootedValue receiver(cx, ObjectValue(*obj));
  return NativeGetProperty(cx, obj, receiver, id, vp);
}

extern bool NativeGetElement(JSContext* cx, Handle<NativeObject*> obj,
                             HandleValue receiver, int32_t index,
                             MutableHandleValue vp);

bool GetSparseElementHelper(JSContext* cx, Handle<NativeObject*> obj,
                            int32_t int_id, MutableHandleValue result);

bool AddOrUpdateSparseElementHelper(JSContext* cx, Handle<NativeObject*> obj,
                                    int32_t int_id, HandleValue v, bool strict);

/*
 * Indicates whether an assignment operation is qualified (`x.y = 0`) or
 * unqualified (`y = 0`). In strict mode, the latter is an error if no such
 * variable already exists.
 *
 * Used as an argument to NativeSetProperty.
 */

enum QualifiedBool { Unqualified = 0, Qualified = 1 };

template <QualifiedBool Qualified>
extern bool NativeSetProperty(JSContext* cx, Handle<NativeObject*> obj,
                              HandleId id, HandleValue v, HandleValue receiver,
                              ObjectOpResult& result);

extern bool NativeSetElement(JSContext* cx, Handle<NativeObject*> obj,
                             uint32_t index, HandleValue v,
                             HandleValue receiver, ObjectOpResult& result);

extern bool NativeDeleteProperty(JSContext* cx, Handle<NativeObject*> obj,
                                 HandleId id, ObjectOpResult& result);

/*** SpiderMonkey nonstandard internal methods ******************************/

template <AllowGC allowGC>
extern bool NativeLookupOwnProperty(
    JSContext* cx, typename MaybeRooted<NativeObject*, allowGC>::HandleType obj,
    typename MaybeRooted<jsid, allowGC>::HandleType id, PropertyResult* propp);

/*
 * Get a property from `receiver`, after having already done a lookup and found
 * the property on a native object `obj`.
 *
 * `prop` must be present in obj's shape.
 */

extern bool NativeGetExistingProperty(JSContext* cx, HandleObject receiver,
                                      Handle<NativeObject*> obj, HandleId id,
                                      PropertyInfo prop, MutableHandleValue vp);

/* * */

extern bool GetNameBoundInEnvironment(JSContext* cx, HandleObject env,
                                      HandleId id, MutableHandleValue vp);

/* namespace js */

template <>
inline bool JSObject::is<js::NativeObject>() const {
  return shape()->isNative();
}

namespace js {

// Alternate to JSObject::as<NativeObject>() that tolerates null pointers.
inline NativeObject* MaybeNativeObject(JSObject* obj) {
  return obj ? &obj->as<NativeObject>() : nullptr;
}

// Defined in NativeObject-inl.h.
bool IsPackedArray(JSObject* obj);

// Initialize an object's reserved slot with a private value pointing to
// malloc-allocated memory and associate the memory with the object.
//
// This call should be matched with a call to JS::GCContext::free_/delete_ in
// the object's finalizer to free the memory and update the memory accounting.

inline void InitReservedSlot(NativeObject* obj, uint32_t slot, void* ptr,
                             size_t nbytes, MemoryUse use) {
  AddCellMemory(obj, nbytes, use);
  obj->initReservedSlot(slot, PrivateValue(ptr));
}
template <typename T>
inline void InitReservedSlot(NativeObject* obj, uint32_t slot, T* ptr,
                             MemoryUse use) {
  InitReservedSlot(obj, slot, ptr, sizeof(T), use);
}

inline void InitBufferSlot(NativeObject* obj, uint32_t slot, void* buffer) {
  MOZ_ASSERT_IF(
      buffer, gc::IsNurseryOwned(obj->zone(), buffer) == IsInsideNursery(obj));
  obj->initReservedSlot(slot, PrivateValue(buffer));
}

inline void TraceBufferSlot(JSTracer* trc, NativeObject* obj, uint32_t slot,
                            const char* name) {
  Value value = obj->getSlot(slot);
  if (value.isUndefined()) {
    return;
  }

  void* buffer = value.toPrivate();
  TraceBufferEdge(trc, &buffer, name);
  if (buffer != value.toPrivate()) {
    obj->setSlot(slot, PrivateValue(buffer));
  }
}

}  // namespace js

#endif /* vm_NativeObject_h */

Messung V0.5 in Prozent
C=90 H=98 G=94

¤ Dauer der Verarbeitung: 0.41 Sekunden  ¤

*© Formatika GbR, Deutschland






Wurzel

Suchen

PVS Prover

Isabelle Prover

NIST Cobol Testsuite

Cephes Mathematical Library

Vienna Development Method

Haftungshinweis

Die Informationen auf dieser Webseite wurden nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit, noch Qualität der bereit gestellten Informationen zugesichert.

Bemerkung:

Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.