Commit 15ad628
deps: V8: cherry-pick c795f5948568
Original commit message:
[immutable-array-buffer] Fix check order in TypedArray.prototype.set
According to the spec, TypedArray.prototype.set checks
IsImmutableBuffer(target.[[ViewedArrayBuffer]]) before converting
the offset argument to integer and before reading from the source
object.
Additionally, when setting from a TypedArray source, reading from an
immutable source TypedArray is permitted, so the source array should
be validated using TypedArrayAccessMode::kRead rather than kWrite.
Drive-By: Add a fast case for Smi indices where the steps are not
observable and we can fold all checks.
TAG=agy
CONV=94aa3be8-9990-41fe-a565-c62e3daa9a42
Bug: 450237486
Change-Id: I21790be90cde9a96ba7c1f573f034016d9c29850
Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8252528
Reviewed-by: Igor Sheludko <ishell@chromium.org>
Commit-Queue: Igor Sheludko <ishell@chromium.org>
Auto-Submit: Olivier Flückiger <olivf@chromium.org>
Cr-Commit-Position: refs/heads/main@{#109366}
Refs: v8/v8@c795f59
PR-URL: #66380
Reviewed-By: Richard Lau <richard.lau@ibm.com>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
Signed-off-by: Joyee Cheung <joyeec9h3@gmail.com>1 parent 070a2a4 commit 15ad628
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
47 | | - | |
| 47 | + | |
48 | 48 | | |
49 | 49 | | |
50 | 50 | | |
| |||
0 commit comments