ThisTDZMode is no longer needed
[WebKit-https.git] / Source / JavaScriptCore / runtime / JSGlobalObject.cpp
1 /*
2  * Copyright (C) 2007-2009, 2014-2016 Apple Inc. All rights reserved.
3  * Copyright (C) 2008 Cameron Zwarich (cwzwarich@uwaterloo.ca)
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *
9  * 1.  Redistributions of source code must retain the above copyright
10  *     notice, this list of conditions and the following disclaimer.
11  * 2.  Redistributions in binary form must reproduce the above copyright
12  *     notice, this list of conditions and the following disclaimer in the
13  *     documentation and/or other materials provided with the distribution.
14  * 3.  Neither the name of Apple Inc. ("Apple") nor the names of
15  *     its contributors may be used to endorse or promote products derived
16  *     from this software without specific prior written permission.
17  *
18  * THIS SOFTWARE IS PROVIDED BY APPLE AND ITS CONTRIBUTORS "AS IS" AND ANY
19  * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
20  * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
21  * DISCLAIMED. IN NO EVENT SHALL APPLE OR ITS CONTRIBUTORS BE LIABLE FOR ANY
22  * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
23  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
24  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
25  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
26  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
27  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
28  */
29
30 #include "config.h"
31 #include "JSGlobalObject.h"
32
33 #include "ArrayConstructor.h"
34 #include "ArrayIteratorPrototype.h"
35 #include "ArrayPrototype.h"
36 #include "BooleanConstructor.h"
37 #include "BooleanPrototype.h"
38 #include "BuiltinNames.h"
39 #include "ClonedArguments.h"
40 #include "CodeBlock.h"
41 #include "CodeCache.h"
42 #include "ConsoleObject.h"
43 #include "DateConstructor.h"
44 #include "DatePrototype.h"
45 #include "Debugger.h"
46 #include "DebuggerScope.h"
47 #include "DirectArguments.h"
48 #include "ECMAScriptSpecInternalFunctions.h"
49 #include "Error.h"
50 #include "ErrorConstructor.h"
51 #include "ErrorPrototype.h"
52 #include "FunctionConstructor.h"
53 #include "FunctionPrototype.h"
54 #include "GeneratorFunctionConstructor.h"
55 #include "GeneratorFunctionPrototype.h"
56 #include "GeneratorPrototype.h"
57 #include "GetterSetter.h"
58 #include "HeapIterationScope.h"
59 #include "InspectorInstrumentationObject.h"
60 #include "Interpreter.h"
61 #include "IteratorPrototype.h"
62 #include "JSAPIWrapperObject.h"
63 #include "JSArrayBuffer.h"
64 #include "JSArrayBufferConstructor.h"
65 #include "JSArrayBufferPrototype.h"
66 #include "JSArrayIterator.h"
67 #include "JSBoundFunction.h"
68 #include "JSBoundSlotBaseFunction.h"
69 #include "JSCInlines.h"
70 #include "JSCallbackConstructor.h"
71 #include "JSCallbackFunction.h"
72 #include "JSCallbackObject.h"
73 #include "JSDataView.h"
74 #include "JSDataViewPrototype.h"
75 #include "JSDollarVM.h"
76 #include "JSDollarVMPrototype.h"
77 #include "JSFunction.h"
78 #include "JSGeneratorFunction.h"
79 #include "JSGenericTypedArrayViewConstructorInlines.h"
80 #include "JSGenericTypedArrayViewInlines.h"
81 #include "JSGenericTypedArrayViewPrototypeInlines.h"
82 #include "JSGlobalObjectFunctions.h"
83 #include "JSInternalPromise.h"
84 #include "JSInternalPromiseConstructor.h"
85 #include "JSInternalPromisePrototype.h"
86 #include "JSJob.h"
87 #include "JSLexicalEnvironment.h"
88 #include "JSLock.h"
89 #include "JSMap.h"
90 #include "JSMapIterator.h"
91 #include "JSModuleEnvironment.h"
92 #include "JSModuleNamespaceObject.h"
93 #include "JSModuleRecord.h"
94 #include "JSNativeStdFunction.h"
95 #include "JSONObject.h"
96 #include "JSPromise.h"
97 #include "JSPromiseConstructor.h"
98 #include "JSPromisePrototype.h"
99 #include "JSPropertyNameIterator.h"
100 #include "JSSet.h"
101 #include "JSSetIterator.h"
102 #include "JSStringIterator.h"
103 #include "JSTemplateRegistryKey.h"
104 #include "JSTypedArrayConstructors.h"
105 #include "JSTypedArrayPrototypes.h"
106 #include "JSTypedArrayViewConstructor.h"
107 #include "JSTypedArrayViewPrototype.h"
108 #include "JSTypedArrays.h"
109 #include "JSWASMModule.h"
110 #include "JSWeakMap.h"
111 #include "JSWeakSet.h"
112 #include "JSWithScope.h"
113 #include "LazyClassStructureInlines.h"
114 #include "LazyPropertyInlines.h"
115 #include "Lookup.h"
116 #include "MapConstructor.h"
117 #include "MapIteratorPrototype.h"
118 #include "MapPrototype.h"
119 #include "MathObject.h"
120 #include "Microtask.h"
121 #include "ModuleLoaderObject.h"
122 #include "NativeErrorConstructor.h"
123 #include "NativeErrorPrototype.h"
124 #include "NullGetterFunction.h"
125 #include "NullSetterFunction.h"
126 #include "NumberConstructor.h"
127 #include "NumberPrototype.h"
128 #include "ObjCCallbackFunction.h"
129 #include "ObjectConstructor.h"
130 #include "ObjectPrototype.h"
131 #include "ParserError.h"
132 #include "ProxyConstructor.h"
133 #include "ProxyObject.h"
134 #include "ProxyRevoke.h"
135 #include "ReflectObject.h"
136 #include "RegExpConstructor.h"
137 #include "RegExpMatchesArray.h"
138 #include "RegExpObject.h"
139 #include "RegExpPrototype.h"
140 #include "ScopedArguments.h"
141 #include "SetConstructor.h"
142 #include "SetIteratorPrototype.h"
143 #include "SetPrototype.h"
144 #include "StrictEvalActivation.h"
145 #include "StringConstructor.h"
146 #include "StringIteratorPrototype.h"
147 #include "StringPrototype.h"
148 #include "Symbol.h"
149 #include "SymbolConstructor.h"
150 #include "SymbolPrototype.h"
151 #include "VariableWriteFireDetail.h"
152 #include "WeakGCMapInlines.h"
153 #include "WeakMapConstructor.h"
154 #include "WeakMapPrototype.h"
155 #include "WeakSetConstructor.h"
156 #include "WeakSetPrototype.h"
157 #include <wtf/RandomNumber.h>
158
159 #if ENABLE(INTL)
160 #include "IntlObject.h"
161 #include <unicode/ucol.h>
162 #include <unicode/udat.h>
163 #include <unicode/unum.h>
164 #endif // ENABLE(INTL)
165
166 #if ENABLE(REMOTE_INSPECTOR)
167 #include "JSGlobalObjectDebuggable.h"
168 #include "JSGlobalObjectInspectorController.h"
169 #endif
170
171 #if ENABLE(WEB_REPLAY)
172 #include "EmptyInputCursor.h"
173 #include "JSReplayInputs.h"
174 #endif
175
176 namespace JSC {
177
178 static JSValue createProxyProperty(VM& vm, JSObject* object)
179 {
180     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
181     return ProxyConstructor::create(vm, ProxyConstructor::createStructure(vm, global, global->functionPrototype()));
182 }
183
184 static JSValue createJSONProperty(VM& vm, JSObject* object)
185 {
186     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
187     return JSONObject::create(vm, JSONObject::createStructure(vm, global, global->objectPrototype()));
188 }
189
190 static JSValue createMathProperty(VM& vm, JSObject* object)
191 {
192     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
193     return MathObject::create(vm, global, MathObject::createStructure(vm, global, global->objectPrototype()));
194 }
195
196 static JSValue createConsoleProperty(VM& vm, JSObject* object)
197 {
198     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
199     return ConsoleObject::create(vm, global, ConsoleObject::createStructure(vm, global, constructEmptyObject(global->globalExec())));
200 }
201
202 } // namespace JSC
203
204 #include "JSGlobalObject.lut.h"
205
206 namespace JSC {
207
208 const ClassInfo JSGlobalObject::s_info = { "GlobalObject", &Base::s_info, &globalObjectTable, CREATE_METHOD_TABLE(JSGlobalObject) };
209
210 const GlobalObjectMethodTable JSGlobalObject::s_globalObjectMethodTable = { &allowsAccessFrom, &supportsRichSourceInfo, &shouldInterruptScript, &javaScriptRuntimeFlags, nullptr, &shouldInterruptScriptBeforeTimeout, nullptr, nullptr, nullptr, nullptr, nullptr, nullptr };
211
212 /* Source for JSGlobalObject.lut.h
213 @begin globalObjectTable
214   parseFloat            globalFuncParseFloat                         DontEnum|Function 1
215   isNaN                 globalFuncIsNaN                              DontEnum|Function 1
216   isFinite              globalFuncIsFinite                           DontEnum|Function 1
217   escape                globalFuncEscape                             DontEnum|Function 1
218   unescape              globalFuncUnescape                           DontEnum|Function 1
219   decodeURI             globalFuncDecodeURI                          DontEnum|Function 1
220   decodeURIComponent    globalFuncDecodeURIComponent                 DontEnum|Function 1
221   encodeURI             globalFuncEncodeURI                          DontEnum|Function 1
222   encodeURIComponent    globalFuncEncodeURIComponent                 DontEnum|Function 1
223   EvalError             JSGlobalObject::m_evalErrorConstructor       DontEnum|CellProperty
224   ReferenceError        JSGlobalObject::m_referenceErrorConstructor  DontEnum|CellProperty
225   SyntaxError           JSGlobalObject::m_syntaxErrorConstructor     DontEnum|CellProperty
226   URIError              JSGlobalObject::m_URIErrorConstructor        DontEnum|CellProperty
227   Proxy                 createProxyProperty                          DontEnum|PropertyCallback
228   JSON                  createJSONProperty                           DontEnum|PropertyCallback
229   Math                  createMathProperty                           DontEnum|PropertyCallback
230   console               createConsoleProperty                        DontEnum|PropertyCallback
231   Int8Array             JSGlobalObject::m_typedArrayInt8             DontEnum|ClassStructure
232   Int16Array            JSGlobalObject::m_typedArrayInt16            DontEnum|ClassStructure
233   Int32Array            JSGlobalObject::m_typedArrayInt32            DontEnum|ClassStructure
234   Uint8Array            JSGlobalObject::m_typedArrayUint8            DontEnum|ClassStructure
235   Uint8ClampedArray     JSGlobalObject::m_typedArrayUint8Clamped     DontEnum|ClassStructure
236   Uint16Array           JSGlobalObject::m_typedArrayUint16           DontEnum|ClassStructure
237   Uint32Array           JSGlobalObject::m_typedArrayUint32           DontEnum|ClassStructure
238   Float32Array          JSGlobalObject::m_typedArrayFloat32          DontEnum|ClassStructure
239   Float64Array          JSGlobalObject::m_typedArrayFloat64          DontEnum|ClassStructure
240   DataView              JSGlobalObject::m_typedArrayDataView         DontEnum|ClassStructure
241   Set                   JSGlobalObject::m_setStructure               DontEnum|ClassStructure
242   Map                   JSGlobalObject::m_mapStructure               DontEnum|ClassStructure
243   Date                  JSGlobalObject::m_dateStructure              DontEnum|ClassStructure
244   Boolean               JSGlobalObject::m_booleanObjectStructure     DontEnum|ClassStructure
245   Number                JSGlobalObject::m_numberObjectStructure      DontEnum|ClassStructure
246   WeakMap               JSGlobalObject::m_weakMapStructure           DontEnum|ClassStructure
247   WeakSet               JSGlobalObject::m_weakSetStructure           DontEnum|ClassStructure
248 @end
249 */
250
251 static EncodedJSValue JSC_HOST_CALL getTemplateObject(ExecState* exec)
252 {
253     JSValue thisValue = exec->thisValue();
254     ASSERT(thisValue.inherits(JSTemplateRegistryKey::info()));
255     return JSValue::encode(exec->lexicalGlobalObject()->templateRegistry().getTemplateObject(exec, jsCast<JSTemplateRegistryKey*>(thisValue)->templateRegistryKey()));
256 }
257
258
259 static EncodedJSValue JSC_HOST_CALL enqueueJob(ExecState* exec)
260 {
261     VM& vm = exec->vm();
262     JSGlobalObject* globalObject = exec->lexicalGlobalObject();
263
264     JSValue job = exec->argument(0);
265     JSValue arguments = exec->argument(1);
266     ASSERT(arguments.inherits(JSArray::info()));
267
268     globalObject->queueMicrotask(createJSJob(vm, job, jsCast<JSArray*>(arguments)));
269
270     return JSValue::encode(jsUndefined());
271 }
272
273 JSGlobalObject::JSGlobalObject(VM& vm, Structure* structure, const GlobalObjectMethodTable* globalObjectMethodTable)
274     : Base(vm, structure, 0)
275     , m_vm(vm)
276 #if ENABLE(WEB_REPLAY)
277     , m_inputCursor(EmptyInputCursor::create())
278 #endif
279     , m_masqueradesAsUndefinedWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
280     , m_havingABadTimeWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
281     , m_varInjectionWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
282     , m_weakRandom(Options::forceWeakRandomSeed() ? Options::forcedWeakRandomSeed() : static_cast<unsigned>(randomNumber() * (std::numeric_limits<unsigned>::max() + 1.0)))
283     , m_templateRegistry(vm)
284     , m_evalEnabled(true)
285     , m_runtimeFlags()
286     , m_consoleClient(nullptr)
287     , m_globalObjectMethodTable(globalObjectMethodTable ? globalObjectMethodTable : &s_globalObjectMethodTable)
288 {
289 }
290
291 JSGlobalObject::~JSGlobalObject()
292 {
293 #if ENABLE(REMOTE_INSPECTOR)
294     m_inspectorController->globalObjectDestroyed();
295 #endif
296
297     if (m_debugger)
298         m_debugger->detach(this, Debugger::GlobalObjectIsDestructing);
299 }
300
301 void JSGlobalObject::destroy(JSCell* cell)
302 {
303     static_cast<JSGlobalObject*>(cell)->JSGlobalObject::~JSGlobalObject();
304 }
305
306 void JSGlobalObject::setGlobalThis(VM& vm, JSObject* globalThis)
307 {
308     m_globalThis.set(vm, this, globalThis);
309 }
310
311 static JSObject* getGetterById(ExecState* exec, JSObject* base, const Identifier& ident)
312 {
313     JSValue baseValue = JSValue(base);
314     PropertySlot slot(baseValue, PropertySlot::InternalMethodType::VMInquiry);
315     baseValue.getPropertySlot(exec, ident, slot);
316     return slot.getPureResult().toObject(exec);
317 }
318
319 void JSGlobalObject::init(VM& vm)
320 {
321     ASSERT(vm.currentThreadIsHoldingAPILock());
322
323     JSGlobalObject::globalExec()->init(0, 0, CallFrame::noCaller(), 0, 0);
324
325     m_debugger = 0;
326
327 #if ENABLE(REMOTE_INSPECTOR)
328     m_inspectorController = std::make_unique<Inspector::JSGlobalObjectInspectorController>(*this);
329     m_inspectorDebuggable = std::make_unique<JSGlobalObjectDebuggable>(*this);
330     m_inspectorDebuggable->init();
331     m_consoleClient = m_inspectorController->consoleClient();
332 #endif
333
334     ExecState* exec = JSGlobalObject::globalExec();
335
336     m_functionPrototype.set(vm, this, FunctionPrototype::create(vm, FunctionPrototype::createStructure(vm, this, jsNull()))); // The real prototype will be set once ObjectPrototype is created.
337     m_calleeStructure.set(vm, this, JSCallee::createStructure(vm, this, jsNull()));
338
339     m_globalLexicalEnvironment.set(vm, this, JSGlobalLexicalEnvironment::create(vm, JSGlobalLexicalEnvironment::createStructure(vm, this), this));
340     // Need to create the callee structure (above) before creating the callee.
341     m_globalCallee.set(vm, this, JSCallee::create(vm, this, globalScope()));
342     exec->setCallee(m_globalCallee.get());
343
344     m_functionStructure.set(vm, this, JSFunction::createStructure(vm, this, m_functionPrototype.get()));
345     m_boundSlotBaseFunctionStructure.initLater(
346         [] (const Initializer<Structure>& init) {
347             init.set(JSBoundSlotBaseFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
348         });
349     m_boundFunctionStructure.initLater(
350         [] (const Initializer<Structure>& init) {
351             init.set(JSBoundFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
352         });
353     m_getterSetterStructure.set(vm, this, GetterSetter::createStructure(vm, this, jsNull()));
354     m_nativeStdFunctionStructure.initLater(
355         [] (const Initializer<Structure>& init) {
356             init.set(JSNativeStdFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
357         });
358     m_namedFunctionStructure.initLater(
359         [] (const Initializer<Structure>& init) {
360             init.set(Structure::addPropertyTransition(init.vm, init.owner->m_functionStructure.get(), init.vm.propertyNames->name, DontDelete | ReadOnly | DontEnum, init.owner->m_functionNameOffset));
361         });
362     JSFunction* callFunction = 0;
363     JSFunction* applyFunction = 0;
364     JSFunction* hasInstanceSymbolFunction = 0;
365     m_functionPrototype->addFunctionProperties(exec, this, &callFunction, &applyFunction, &hasInstanceSymbolFunction);
366     m_callFunction.set(vm, this, callFunction);
367     m_applyFunction.set(vm, this, applyFunction);
368     m_arrayProtoValuesFunction.initLater(
369         [] (const Initializer<JSFunction>& init) {
370             init.set(JSFunction::createBuiltinFunction(init.vm, arrayPrototypeValuesCodeGenerator(init.vm), init.owner));
371         });
372     m_initializePromiseFunction.initLater(
373         [] (const Initializer<JSFunction>& init) {
374             init.set(JSFunction::createBuiltinFunction(init.vm, promiseOperationsInitializePromiseCodeGenerator(init.vm), init.owner));
375         });
376     m_newPromiseCapabilityFunction.set(vm, this, JSFunction::createBuiltinFunction(vm, promiseOperationsNewPromiseCapabilityCodeGenerator(vm), this));
377     m_functionProtoHasInstanceSymbolFunction.set(vm, this, hasInstanceSymbolFunction);
378     m_throwTypeErrorGetterSetter.initLater(
379         [] (const Initializer<GetterSetter>& init) {
380             JSFunction* thrower = JSFunction::create(init.vm, init.owner, 0, String(), globalFuncThrowTypeError);
381             GetterSetter* getterSetter = GetterSetter::create(init.vm, init.owner);
382             getterSetter->setGetter(init.vm, init.owner, thrower);
383             getterSetter->setSetter(init.vm, init.owner, thrower);
384             init.set(getterSetter);
385         });
386     m_throwTypeErrorCalleeAndCallerGetterSetter.initLater(
387         [] (const Initializer<GetterSetter>& init) {
388             JSFunction* thrower = JSFunction::create(init.vm, init.owner, 0, String(), globalFuncThrowTypeErrorCalleeAndCaller);
389             GetterSetter* getterSetter = GetterSetter::create(init.vm, init.owner);
390             getterSetter->setGetter(init.vm, init.owner, thrower);
391             getterSetter->setSetter(init.vm, init.owner, thrower);
392             init.set(getterSetter);
393         });
394     m_throwTypeErrorArgumentsAndCallerInStrictModeGetterSetter.initLater(
395         [] (const Initializer<GetterSetter>& init) {
396             JSFunction* thrower = JSFunction::create(init.vm, init.owner, 0, String(), globalFuncThrowTypeErrorArgumentsAndCallerInStrictMode);
397             GetterSetter* getterSetter = GetterSetter::create(init.vm, init.owner);
398             getterSetter->setGetter(init.vm, init.owner, thrower);
399             getterSetter->setSetter(init.vm, init.owner, thrower);
400             init.set(getterSetter);
401         });
402     m_throwTypeErrorArgumentsAndCallerInClassContextGetterSetter.initLater(
403         [] (const Initializer<GetterSetter>& init) {
404             JSFunction* thrower = JSFunction::create(init.vm, init.owner, 0, String(), globalFuncThrowTypeErrorArgumentsAndCallerInClassContext);
405             GetterSetter* getterSetter = GetterSetter::create(init.vm, init.owner);
406             getterSetter->setGetter(init.vm, init.owner, thrower);
407             getterSetter->setSetter(init.vm, init.owner, thrower);
408             init.set(getterSetter);
409         });
410     m_nullGetterFunction.set(vm, this, NullGetterFunction::create(vm, NullGetterFunction::createStructure(vm, this, m_functionPrototype.get())));
411     m_nullSetterFunction.set(vm, this, NullSetterFunction::create(vm, NullSetterFunction::createStructure(vm, this, m_functionPrototype.get())));
412     m_objectPrototype.set(vm, this, ObjectPrototype::create(vm, this, ObjectPrototype::createStructure(vm, this, jsNull())));
413     GetterSetter* protoAccessor = GetterSetter::create(vm, this);
414     protoAccessor->setGetter(vm, this, JSFunction::create(vm, this, 0, makeString("get ", vm.propertyNames->underscoreProto.string()), globalFuncProtoGetter));
415     protoAccessor->setSetter(vm, this, JSFunction::create(vm, this, 0, makeString("set ", vm.propertyNames->underscoreProto.string()), globalFuncProtoSetter));
416     m_objectPrototype->putDirectNonIndexAccessor(vm, vm.propertyNames->underscoreProto, protoAccessor, Accessor | DontEnum);
417     m_functionPrototype->structure()->setPrototypeWithoutTransition(vm, m_objectPrototype.get());
418     m_objectStructureForObjectConstructor.set(vm, this, vm.prototypeMap.emptyObjectStructureForPrototype(m_objectPrototype.get(), JSFinalObject::defaultInlineCapacity()));
419
420     m_speciesGetterSetter.set(vm, this, GetterSetter::create(vm, this));
421     m_speciesGetterSetter->setGetter(vm, this, JSFunction::createBuiltinFunction(vm, globalObjectSpeciesGetterCodeGenerator(vm), this, "get [Symbol.species]"));
422
423     m_typedArrayProto.initLater(
424         [] (const Initializer<JSTypedArrayViewPrototype>& init) {
425             init.set(JSTypedArrayViewPrototype::create(init.vm, init.owner, JSTypedArrayViewPrototype::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get())));
426             
427             // Make sure that the constructor gets initialized, too.
428             init.owner->m_typedArraySuperConstructor.get(init.owner);
429         });
430     m_typedArraySuperConstructor.initLater(
431         [] (const Initializer<JSTypedArrayViewConstructor>& init) {
432             JSTypedArrayViewPrototype* prototype = init.owner->m_typedArrayProto.get(init.owner);
433             JSTypedArrayViewConstructor* constructor = JSTypedArrayViewConstructor::create(init.vm, init.owner, JSTypedArrayViewConstructor::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()), prototype, init.owner->m_speciesGetterSetter.get());
434             prototype->putDirectWithoutTransition(init.vm, init.vm.propertyNames->constructor, constructor, DontEnum);
435             init.set(constructor);
436         });
437     
438 #define INIT_TYPED_ARRAY_LATER(type) \
439     m_typedArray ## type.initLater( \
440         [] (LazyClassStructure::Initializer& init) { \
441             init.setPrototype(JS ## type ## ArrayPrototype::create(init.vm, init.global, JS ## type ## ArrayPrototype::createStructure(init.vm, init.global, init.global->m_typedArrayProto.get(init.global)))); \
442             init.setStructure(JS ## type ## Array::createStructure(init.vm, init.global, init.prototype)); \
443             init.setConstructor(JS ## type ## ArrayConstructor::create(init.vm, init.global, JS ## type ## ArrayConstructor::createStructure(init.vm, init.global, init.global->m_typedArraySuperConstructor.get(init.global)), init.prototype, ASCIILiteral(#type "Array"), typedArrayConstructorAllocate ## type ## ArrayCodeGenerator(init.vm))); \
444             init.global->putDirectWithoutTransition(init.vm, init.vm.propertyNames->type ## ArrayPrivateName, init.constructor, DontEnum); \
445         });
446     FOR_EACH_TYPED_ARRAY_TYPE_EXCLUDING_DATA_VIEW(INIT_TYPED_ARRAY_LATER)
447 #undef INIT_TYPED_ARRAY_LATER
448     
449     m_typedArrayDataView.initLater(
450         [] (LazyClassStructure::Initializer& init) {
451             init.setPrototype(JSDataViewPrototype::create(init.vm, JSDataViewPrototype::createStructure(init.vm, init.global, init.global->m_objectPrototype.get())));
452             init.setStructure(JSDataView::createStructure(init.vm, init.global, init.prototype));
453             init.setConstructor(JSDataViewConstructor::create(init.vm, init.global, JSDataViewConstructor::createStructure(init.vm, init.global, init.global->m_functionPrototype.get()), init.prototype, ASCIILiteral("DataView"), nullptr));
454         });
455     
456     m_lexicalEnvironmentStructure.set(vm, this, JSLexicalEnvironment::createStructure(vm, this));
457     m_moduleEnvironmentStructure.initLater(
458         [] (const Initializer<Structure>& init) {
459             init.set(JSModuleEnvironment::createStructure(init.vm, init.owner));
460         });
461     m_strictEvalActivationStructure.set(vm, this, StrictEvalActivation::createStructure(vm, this, jsNull()));
462     m_debuggerScopeStructure.initLater(
463         [] (const Initializer<Structure>& init) {
464             init.set(DebuggerScope::createStructure(init.vm, init.owner));
465         });
466     m_withScopeStructure.initLater(
467         [] (const Initializer<Structure>& init) {
468             init.set(JSWithScope::createStructure(init.vm, init.owner, jsNull()));
469         });
470     
471     m_nullPrototypeObjectStructure.initLater(
472         [] (const Initializer<Structure>& init) {
473             init.set(JSFinalObject::createStructure(init.vm, init.owner, jsNull(), JSFinalObject::defaultInlineCapacity()));
474         });
475     
476     m_callbackFunctionStructure.initLater(
477         [] (const Initializer<Structure>& init) {
478             init.set(JSCallbackFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
479         });
480     m_directArgumentsStructure.set(vm, this, DirectArguments::createStructure(vm, this, m_objectPrototype.get()));
481     m_scopedArgumentsStructure.set(vm, this, ScopedArguments::createStructure(vm, this, m_objectPrototype.get()));
482     m_clonedArgumentsStructure.set(vm, this, ClonedArguments::createStructure(vm, this, m_objectPrototype.get()));
483     m_callbackConstructorStructure.initLater(
484         [] (const Initializer<Structure>& init) {
485             init.set(JSCallbackConstructor::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
486         });
487     m_callbackObjectStructure.initLater(
488         [] (const Initializer<Structure>& init) {
489             init.set(JSCallbackObject<JSDestructibleObject>::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
490         });
491
492 #if JSC_OBJC_API_ENABLED
493     m_objcCallbackFunctionStructure.initLater(
494         [] (const Initializer<Structure>& init) {
495             init.set(ObjCCallbackFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
496         });
497     m_objcWrapperObjectStructure.initLater(
498         [] (const Initializer<Structure>& init) {
499             init.set(JSCallbackObject<JSAPIWrapperObject>::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
500         });
501 #endif
502     
503     m_arrayPrototype.set(vm, this, ArrayPrototype::create(vm, this, ArrayPrototype::createStructure(vm, this, m_objectPrototype.get())));
504     
505     m_originalArrayStructureForIndexingShape[UndecidedShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithUndecided));
506     m_originalArrayStructureForIndexingShape[Int32Shape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithInt32));
507     m_originalArrayStructureForIndexingShape[DoubleShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithDouble));
508     m_originalArrayStructureForIndexingShape[ContiguousShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithContiguous));
509     m_originalArrayStructureForIndexingShape[ArrayStorageShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithArrayStorage));
510     m_originalArrayStructureForIndexingShape[SlowPutArrayStorageShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithSlowPutArrayStorage));
511     for (unsigned i = 0; i < NumberOfIndexingShapes; ++i)
512         m_arrayStructureForIndexingShapeDuringAllocation[i] = m_originalArrayStructureForIndexingShape[i];
513
514     m_regExpPrototype.set(vm, this, RegExpPrototype::create(vm, this, RegExpPrototype::createStructure(vm, this, m_objectPrototype.get())));
515     m_regExpStructure.set(vm, this, RegExpObject::createStructure(vm, this, m_regExpPrototype.get()));
516     m_regExpMatchesArrayStructure.set(vm, this, createRegExpMatchesArrayStructure(vm, this));
517     m_regExpMatchesArraySlowPutStructure.set(vm, this, createRegExpMatchesArraySlowPutStructure(vm, this));
518
519     m_moduleRecordStructure.set(vm, this, JSModuleRecord::createStructure(vm, this, m_objectPrototype.get()));
520     m_moduleNamespaceObjectStructure.set(vm, this, JSModuleNamespaceObject::createStructure(vm, this, jsNull()));
521     {
522         bool isCallable = false;
523         m_proxyObjectStructure.set(vm, this, ProxyObject::createStructure(vm, this, m_objectPrototype.get(), isCallable));
524         isCallable = true;
525         m_callableProxyObjectStructure.set(vm, this, ProxyObject::createStructure(vm, this, m_objectPrototype.get(), isCallable));
526     }
527     m_proxyRevokeStructure.set(vm, this, ProxyRevoke::createStructure(vm, this, m_functionPrototype.get()));
528     
529 #if ENABLE(WEBASSEMBLY)
530     m_wasmModuleStructure.set(vm, this, JSWASMModule::createStructure(vm, this));
531 #endif
532
533     m_parseIntFunction.set(vm, this, JSFunction::create(vm, this, 2, vm.propertyNames->parseInt.string(), globalFuncParseInt, NoIntrinsic));
534     putDirectWithoutTransition(vm, vm.propertyNames->parseInt, m_parseIntFunction.get(), DontEnum);
535
536 #define CREATE_PROTOTYPE_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName) \
537 m_ ## lowerName ## Prototype.set(vm, this, capitalName##Prototype::create(vm, this, capitalName##Prototype::createStructure(vm, this, m_objectPrototype.get()))); \
538 m_ ## properName ## Structure.set(vm, this, instanceType::createStructure(vm, this, m_ ## lowerName ## Prototype.get()));
539     
540     FOR_EACH_SIMPLE_BUILTIN_TYPE(CREATE_PROTOTYPE_FOR_SIMPLE_TYPE)
541     
542 #undef CREATE_PROTOTYPE_FOR_SIMPLE_TYPE
543
544 #define CREATE_PROTOTYPE_FOR_LAZY_TYPE(capitalName, lowerName, properName, instanceType, jsName) \
545     m_ ## properName ## Structure.initLater(\
546         [] (LazyClassStructure::Initializer& init) { \
547             init.setPrototype(capitalName##Prototype::create(init.vm, init.global, capitalName##Prototype::createStructure(init.vm, init.global, init.global->m_objectPrototype.get()))); \
548             init.setStructure(instanceType::createStructure(init.vm, init.global, init.prototype)); \
549             init.setConstructor(capitalName ## Constructor::create(init.vm, capitalName ## Constructor::createStructure(init.vm, init.global, init.global->m_functionPrototype.get()), jsCast<capitalName ## Prototype*>(init.prototype), init.global->m_speciesGetterSetter.get())); \
550         });
551     
552     FOR_EACH_LAZY_BUILTIN_TYPE(CREATE_PROTOTYPE_FOR_LAZY_TYPE)
553     
554 #undef CREATE_PROTOTYPE_FOR_LAZY_TYPE
555     
556     m_iteratorPrototype.set(vm, this, IteratorPrototype::create(vm, this, IteratorPrototype::createStructure(vm, this, m_objectPrototype.get())));
557
558 #define CREATE_PROTOTYPE_FOR_DERIVED_ITERATOR_TYPE(capitalName, lowerName, properName, instanceType, jsName) \
559     m_ ## lowerName ## Structure.initLater( \
560         [] (const Initializer<Structure>& init) { \
561             JSObject* prototype = capitalName ## Prototype::create(init.vm, init.owner, capitalName ## Prototype::createStructure(init.vm, init.owner, init.owner->m_iteratorPrototype.get())); \
562             init.set(instanceType::createStructure(init.vm, init.owner, prototype)); \
563         });
564     FOR_EACH_BUILTIN_DERIVED_ITERATOR_TYPE(CREATE_PROTOTYPE_FOR_DERIVED_ITERATOR_TYPE)
565 #undef CREATE_PROTOTYPE_FOR_DERIVED_ITERATOR_TYPE
566
567     m_propertyNameIteratorStructure.set(vm, this, JSPropertyNameIterator::createStructure(vm, this, m_iteratorPrototype.get()));
568     m_generatorPrototype.set(vm, this, GeneratorPrototype::create(vm, this, GeneratorPrototype::createStructure(vm, this, m_iteratorPrototype.get())));
569     
570     // Constructors
571
572     ObjectConstructor* objectConstructor = ObjectConstructor::create(vm, this, ObjectConstructor::createStructure(vm, this, m_functionPrototype.get()), m_objectPrototype.get());
573     m_objectConstructor.set(vm, this, objectConstructor);
574
575     JSFunction* definePropertyFunction = m_objectConstructor->addDefineProperty(exec, this);
576     m_definePropertyFunction.set(vm, this, definePropertyFunction);
577
578     JSCell* functionConstructor = FunctionConstructor::create(vm, FunctionConstructor::createStructure(vm, this, m_functionPrototype.get()), m_functionPrototype.get());
579     JSObject* arrayConstructor = ArrayConstructor::create(vm, this, ArrayConstructor::createStructure(vm, this, m_functionPrototype.get()), m_arrayPrototype.get(), m_speciesGetterSetter.get());
580     
581     m_regExpConstructor.set(vm, this, RegExpConstructor::create(vm, RegExpConstructor::createStructure(vm, this, m_functionPrototype.get()), m_regExpPrototype.get(), m_speciesGetterSetter.get()));
582     
583 #define CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName) \
584 capitalName ## Constructor* lowerName ## Constructor = capitalName ## Constructor::create(vm, capitalName ## Constructor::createStructure(vm, this, m_functionPrototype.get()), m_ ## lowerName ## Prototype.get(), m_speciesGetterSetter.get()); \
585 m_ ## lowerName ## Prototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, lowerName ## Constructor, DontEnum); \
586
587     FOR_EACH_SIMPLE_BUILTIN_TYPE(CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE)
588     
589 #undef CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE
590
591     m_errorConstructor.set(vm, this, errorConstructor);
592     m_promiseConstructor.set(vm, this, promiseConstructor);
593     m_internalPromiseConstructor.set(vm, this, internalPromiseConstructor);
594     
595     m_nativeErrorPrototypeStructure.set(vm, this, NativeErrorPrototype::createStructure(vm, this, m_errorPrototype.get()));
596     m_nativeErrorStructure.set(vm, this, NativeErrorConstructor::createStructure(vm, this, m_functionPrototype.get()));
597     m_evalErrorConstructor.initLater(
598         [] (const Initializer<NativeErrorConstructor>& init) {
599             init.set(NativeErrorConstructor::create(init.vm, init.owner, init.owner->m_nativeErrorStructure.get(), init.owner->m_nativeErrorPrototypeStructure.get(), ASCIILiteral("EvalError")));
600         });
601     m_rangeErrorConstructor.set(vm, this, NativeErrorConstructor::create(vm, this, m_nativeErrorStructure.get(), m_nativeErrorPrototypeStructure.get(), ASCIILiteral("RangeError")));
602     m_referenceErrorConstructor.initLater(
603         [] (const Initializer<NativeErrorConstructor>& init) {
604             init.set(NativeErrorConstructor::create(init.vm, init.owner, init.owner->m_nativeErrorStructure.get(), init.owner->m_nativeErrorPrototypeStructure.get(), ASCIILiteral("ReferenceError")));
605         });
606     m_syntaxErrorConstructor.initLater(
607         [] (const Initializer<NativeErrorConstructor>& init) {
608             init.set(NativeErrorConstructor::create(init.vm, init.owner, init.owner->m_nativeErrorStructure.get(), init.owner->m_nativeErrorPrototypeStructure.get(), ASCIILiteral("SyntaxError")));
609         });
610     m_typeErrorConstructor.set(vm, this, NativeErrorConstructor::create(vm, this, m_nativeErrorStructure.get(), m_nativeErrorPrototypeStructure.get(), ASCIILiteral("TypeError")));
611     m_URIErrorConstructor.initLater(
612         [] (const Initializer<NativeErrorConstructor>& init) {
613             init.set(NativeErrorConstructor::create(init.vm, init.owner, init.owner->m_nativeErrorStructure.get(), init.owner->m_nativeErrorPrototypeStructure.get(), ASCIILiteral("URIError")));
614         });
615
616     m_generatorFunctionPrototype.set(vm, this, GeneratorFunctionPrototype::create(vm, GeneratorFunctionPrototype::createStructure(vm, this, m_functionPrototype.get())));
617     GeneratorFunctionConstructor* generatorFunctionConstructor = GeneratorFunctionConstructor::create(vm, GeneratorFunctionConstructor::createStructure(vm, this, functionConstructor), m_generatorFunctionPrototype.get());
618     m_generatorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, generatorFunctionConstructor, DontEnum);
619     m_generatorFunctionStructure.set(vm, this, JSGeneratorFunction::createStructure(vm, this, m_generatorFunctionPrototype.get()));
620
621     m_generatorPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_generatorFunctionPrototype.get(), DontEnum);
622     m_generatorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->prototype, m_generatorPrototype.get(), DontEnum);
623     
624     m_objectPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, objectConstructor, DontEnum);
625     m_functionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, functionConstructor, DontEnum);
626     m_arrayPrototype->setConstructor(vm, arrayConstructor, DontEnum);
627     m_regExpPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_regExpConstructor.get(), DontEnum);
628     
629     putDirectWithoutTransition(vm, vm.propertyNames->Object, objectConstructor, DontEnum);
630     putDirectWithoutTransition(vm, vm.propertyNames->Function, functionConstructor, DontEnum);
631     putDirectWithoutTransition(vm, vm.propertyNames->Array, arrayConstructor, DontEnum);
632     putDirectWithoutTransition(vm, vm.propertyNames->RegExp, m_regExpConstructor.get(), DontEnum);
633     putDirectWithoutTransition(vm, vm.propertyNames->RangeError, m_rangeErrorConstructor.get(), DontEnum);
634     putDirectWithoutTransition(vm, vm.propertyNames->TypeError, m_typeErrorConstructor.get(), DontEnum);
635
636     putDirectWithoutTransition(vm, vm.propertyNames->ObjectPrivateName, objectConstructor, DontEnum | DontDelete | ReadOnly);
637     putDirectWithoutTransition(vm, vm.propertyNames->ArrayPrivateName, arrayConstructor, DontEnum | DontDelete | ReadOnly);
638
639 #define PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName) \
640 putDirectWithoutTransition(vm, vm.propertyNames-> jsName, lowerName ## Constructor, DontEnum); \
641
642     FOR_EACH_SIMPLE_BUILTIN_TYPE_WITH_CONSTRUCTOR(PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE)
643
644 #undef PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE
645     m_iteratorResultObjectStructure.set(vm, this, createIteratorResultObjectStructure(vm, *this));
646     
647     m_evalFunction.set(vm, this, JSFunction::create(vm, this, 1, vm.propertyNames->eval.string(), globalFuncEval));
648     putDirectWithoutTransition(vm, vm.propertyNames->eval, m_evalFunction.get(), DontEnum);
649     
650 #if ENABLE(INTL)
651     IntlObject* intl = IntlObject::create(vm, this, IntlObject::createStructure(vm, this, m_objectPrototype.get()));
652     putDirectWithoutTransition(vm, vm.propertyNames->Intl, intl, DontEnum);
653 #endif // ENABLE(INTL)
654     ReflectObject* reflectObject = ReflectObject::create(vm, this, ReflectObject::createStructure(vm, this, m_objectPrototype.get()));
655     putDirectWithoutTransition(vm, vm.propertyNames->Reflect, reflectObject, DontEnum);
656
657     m_moduleLoader.set(vm, this, ModuleLoaderObject::create(vm, this, ModuleLoaderObject::createStructure(vm, this, m_objectPrototype.get())));
658     if (Options::exposeInternalModuleLoader())
659         putDirectWithoutTransition(vm, vm.propertyNames->Loader, m_moduleLoader.get(), DontEnum);
660
661     JSFunction* builtinLog = JSFunction::create(vm, this, 1, vm.propertyNames->emptyIdentifier.string(), globalFuncBuiltinLog);
662
663     JSFunction* privateFuncAbs = JSFunction::create(vm, this, 0, String(), mathProtoFuncAbs, AbsIntrinsic);
664     JSFunction* privateFuncFloor = JSFunction::create(vm, this, 0, String(), mathProtoFuncFloor, FloorIntrinsic);
665     JSFunction* privateFuncIsFinite = JSFunction::create(vm, this, 0, String(), globalFuncIsFinite);
666     JSFunction* privateFuncIsNaN = JSFunction::create(vm, this, 0, String(), globalFuncIsNaN);
667     JSFunction* privateFuncTrunc = JSFunction::create(vm, this, 0, String(), mathProtoFuncTrunc, TruncIntrinsic);
668
669     JSFunction* privateFuncGetTemplateObject = JSFunction::create(vm, this, 0, String(), getTemplateObject);
670     JSFunction* privateFuncToLength = JSFunction::createBuiltinFunction(vm, globalObjectToLengthCodeGenerator(vm), this);
671     JSFunction* privateFuncToInteger = JSFunction::createBuiltinFunction(vm, globalObjectToIntegerCodeGenerator(vm), this);
672     JSFunction* privateFuncTypedArrayLength = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncLength);
673     JSFunction* privateFuncTypedArrayGetOriginalConstructor = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncGetOriginalConstructor);
674     JSFunction* privateFuncTypedArraySort = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncSort);
675     JSFunction* privateFuncIsBoundFunction = JSFunction::create(vm, this, 0, String(), isBoundFunction);
676     JSFunction* privateFuncHasInstanceBoundFunction = JSFunction::create(vm, this, 0, String(), hasInstanceBoundFunction);
677     JSFunction* privateFuncInstanceOf = JSFunction::create(vm, this, 0, String(), objectPrivateFuncInstanceOf);
678     JSFunction* privateFuncThisTimeValue = JSFunction::create(vm, this, 0, String(), dateProtoFuncGetTime);
679     JSFunction* privateFuncThisNumberValue = JSFunction::create(vm, this, 0, String(), numberProtoFuncValueOf);
680     JSFunction* privateFuncIsArrayConstructor = JSFunction::create(vm, this, 0, String(), arrayConstructorPrivateFuncIsArrayConstructor);
681
682     JSObject* arrayIteratorPrototype = ArrayIteratorPrototype::create(vm, this, ArrayIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
683     JSFunction* privateFuncCreateArrayIterator = JSFunction::createBuiltinFunction(vm, arrayPrototypeCreateArrayIteratorConstructorCodeGenerator(vm), this);
684     privateFuncCreateArrayIterator->putDirect(vm, vm.propertyNames->prototype, arrayIteratorPrototype);
685     JSFunction* privateFuncArrayIteratorValueNext = JSFunction::createBuiltinFunction(vm, arrayIteratorPrototypeArrayIteratorValueNextCodeGenerator(vm), this);
686     JSFunction* privateFuncArrayIteratorKeyNext = JSFunction::createBuiltinFunction(vm, arrayIteratorPrototypeArrayIteratorKeyNextCodeGenerator(vm), this);
687     JSFunction* privateFuncArrayIteratorKeyValueNext = JSFunction::createBuiltinFunction(vm, arrayIteratorPrototypeArrayIteratorKeyValueNextCodeGenerator(vm), this);
688
689     JSObject* regExpProtoFlagsGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->flags);
690     JSObject* regExpProtoGlobalGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->global);
691     m_regExpProtoGlobalGetter.set(vm, this, regExpProtoGlobalGetterObject);
692     JSObject* regExpProtoIgnoreCaseGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->ignoreCase);
693     JSObject* regExpProtoMultilineGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->multiline);
694     JSObject* regExpProtoSourceGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->source);
695     JSObject* regExpProtoStickyGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->sticky);
696     JSObject* regExpProtoUnicodeGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->unicode);
697     m_regExpProtoUnicodeGetter.set(vm, this, regExpProtoUnicodeGetterObject);
698     JSObject* builtinRegExpExec = asObject(m_regExpPrototype->getDirect(vm, vm.propertyNames->exec).asCell());
699     m_regExpProtoExec.set(vm, this, builtinRegExpExec);
700     JSObject* regExpSymbolReplace = asObject(m_regExpPrototype->getDirect(vm, vm.propertyNames->replaceSymbol).asCell());
701     m_regExpProtoSymbolReplace.set(vm, this, regExpSymbolReplace);
702
703     GlobalPropertyInfo staticGlobals[] = {
704         GlobalPropertyInfo(vm.propertyNames->NaN, jsNaN(), DontEnum | DontDelete | ReadOnly),
705         GlobalPropertyInfo(vm.propertyNames->Infinity, jsNumber(std::numeric_limits<double>::infinity()), DontEnum | DontDelete | ReadOnly),
706         GlobalPropertyInfo(vm.propertyNames->undefinedKeyword, jsUndefined(), DontEnum | DontDelete | ReadOnly),
707         GlobalPropertyInfo(vm.propertyNames->ObjectPrivateName, objectConstructor, DontEnum | DontDelete | ReadOnly),
708         GlobalPropertyInfo(vm.propertyNames->ownEnumerablePropertyKeysPrivateName, JSFunction::create(vm, this, 0, String(), ownEnumerablePropertyKeys), DontEnum | DontDelete | ReadOnly),
709         GlobalPropertyInfo(vm.propertyNames->getTemplateObjectPrivateName, privateFuncGetTemplateObject, DontEnum | DontDelete | ReadOnly),
710         GlobalPropertyInfo(vm.propertyNames->enqueueJobPrivateName, JSFunction::create(vm, this, 0, String(), enqueueJob), DontEnum | DontDelete | ReadOnly),
711         GlobalPropertyInfo(vm.propertyNames->ErrorPrivateName, m_errorConstructor.get(), DontEnum | DontDelete | ReadOnly),
712         GlobalPropertyInfo(vm.propertyNames->RangeErrorPrivateName, m_rangeErrorConstructor.get(), DontEnum | DontDelete | ReadOnly),
713         GlobalPropertyInfo(vm.propertyNames->TypeErrorPrivateName, m_typeErrorConstructor.get(), DontEnum | DontDelete | ReadOnly),
714         GlobalPropertyInfo(vm.propertyNames->typedArrayLengthPrivateName, privateFuncTypedArrayLength, DontEnum | DontDelete | ReadOnly),
715         GlobalPropertyInfo(vm.propertyNames->typedArrayGetOriginalConstructorPrivateName, privateFuncTypedArrayGetOriginalConstructor, DontEnum | DontDelete | ReadOnly),
716         GlobalPropertyInfo(vm.propertyNames->typedArraySortPrivateName, privateFuncTypedArraySort, DontEnum | DontDelete | ReadOnly),
717         GlobalPropertyInfo(vm.propertyNames->isBoundFunctionPrivateName, privateFuncIsBoundFunction, DontEnum | DontDelete | ReadOnly),
718         GlobalPropertyInfo(vm.propertyNames->hasInstanceBoundFunctionPrivateName, privateFuncHasInstanceBoundFunction, DontEnum | DontDelete | ReadOnly),
719         GlobalPropertyInfo(vm.propertyNames->instanceOfPrivateName, privateFuncInstanceOf, DontEnum | DontDelete | ReadOnly),
720         GlobalPropertyInfo(vm.propertyNames->BuiltinLogPrivateName, builtinLog, DontEnum | DontDelete | ReadOnly),
721         GlobalPropertyInfo(vm.propertyNames->ArrayPrivateName, arrayConstructor, DontEnum | DontDelete | ReadOnly),
722         GlobalPropertyInfo(vm.propertyNames->NumberPrivateName, numberConstructor, DontEnum | DontDelete | ReadOnly),
723         GlobalPropertyInfo(vm.propertyNames->RegExpPrivateName, m_regExpConstructor.get(), DontEnum | DontDelete | ReadOnly),
724         GlobalPropertyInfo(vm.propertyNames->StringPrivateName, stringConstructor, DontEnum | DontDelete | ReadOnly),
725         GlobalPropertyInfo(vm.propertyNames->absPrivateName, privateFuncAbs, DontEnum | DontDelete | ReadOnly),
726         GlobalPropertyInfo(vm.propertyNames->floorPrivateName, privateFuncFloor, DontEnum | DontDelete | ReadOnly),
727         GlobalPropertyInfo(vm.propertyNames->truncPrivateName, privateFuncTrunc, DontEnum | DontDelete | ReadOnly),
728         GlobalPropertyInfo(vm.propertyNames->isFinitePrivateName, privateFuncIsFinite, DontEnum | DontDelete | ReadOnly),
729         GlobalPropertyInfo(vm.propertyNames->isNaNPrivateName, privateFuncIsNaN, DontEnum | DontDelete | ReadOnly),
730         GlobalPropertyInfo(vm.propertyNames->PromisePrivateName, promiseConstructor, DontEnum | DontDelete | ReadOnly),
731         GlobalPropertyInfo(vm.propertyNames->ReflectPrivateName, reflectObject, DontEnum | DontDelete | ReadOnly),
732         GlobalPropertyInfo(vm.propertyNames->InternalPromisePrivateName, internalPromiseConstructor, DontEnum | DontDelete | ReadOnly),
733
734         GlobalPropertyInfo(vm.propertyNames->repeatCharacterPrivateName, JSFunction::create(vm, this, 2, String(), stringProtoFuncRepeatCharacter), DontEnum | DontDelete | ReadOnly),
735         GlobalPropertyInfo(vm.propertyNames->builtinNames().repeatSlowPathPrivateName(), JSFunction::createBuiltinFunction(vm, stringPrototypeRepeatSlowPathCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
736         GlobalPropertyInfo(vm.propertyNames->builtinNames().repeatCharactersSlowPathPrivateName(), JSFunction::createBuiltinFunction(vm, stringPrototypeRepeatCharactersSlowPathCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
737
738         GlobalPropertyInfo(vm.propertyNames->isSetPrivateName, JSFunction::create(vm, this, 1, String(), privateFuncIsSet), DontEnum | DontDelete | ReadOnly),
739         GlobalPropertyInfo(vm.propertyNames->SetIteratorPrivateName, JSFunction::create(vm, this, 1, String(), privateFuncSetIterator), DontEnum | DontDelete | ReadOnly),
740         GlobalPropertyInfo(vm.propertyNames->setIteratorNextPrivateName, JSFunction::create(vm, this, 0, String(), privateFuncSetIteratorNext), DontEnum | DontDelete | ReadOnly),
741         GlobalPropertyInfo(vm.propertyNames->isMapPrivateName, JSFunction::create(vm, this, 1, String(), privateFuncIsMap), DontEnum | DontDelete | ReadOnly),
742         GlobalPropertyInfo(vm.propertyNames->isArrayPrivateName, arrayConstructor->getDirect(vm, vm.propertyNames->isArray), DontEnum | DontDelete | ReadOnly),
743         GlobalPropertyInfo(vm.propertyNames->isArrayConstructorPrivateName, privateFuncIsArrayConstructor, DontEnum | DontDelete | ReadOnly),
744         GlobalPropertyInfo(vm.propertyNames->MapIteratorPrivateName, JSFunction::create(vm, this, 1, String(), privateFuncMapIterator), DontEnum | DontDelete | ReadOnly),
745         GlobalPropertyInfo(vm.propertyNames->mapIteratorNextPrivateName, JSFunction::create(vm, this, 0, String(), privateFuncMapIteratorNext), DontEnum | DontDelete | ReadOnly),
746         GlobalPropertyInfo(vm.propertyNames->builtinNames().arrayIteratorValueNextPrivateName(), privateFuncArrayIteratorValueNext, DontEnum | DontDelete | ReadOnly),
747         GlobalPropertyInfo(vm.propertyNames->builtinNames().arrayIteratorKeyNextPrivateName(), privateFuncArrayIteratorKeyNext, DontEnum | DontDelete | ReadOnly),
748         GlobalPropertyInfo(vm.propertyNames->builtinNames().arrayIteratorKeyValueNextPrivateName(), privateFuncArrayIteratorKeyValueNext, DontEnum | DontDelete | ReadOnly),
749         GlobalPropertyInfo(vm.propertyNames->builtinNames().createArrayIteratorPrivateName(), privateFuncCreateArrayIterator, DontEnum | DontDelete | ReadOnly),
750
751         GlobalPropertyInfo(vm.propertyNames->builtinNames().toLengthPrivateName(), privateFuncToLength, DontEnum | DontDelete | ReadOnly),
752         GlobalPropertyInfo(vm.propertyNames->builtinNames().toIntegerPrivateName(), privateFuncToInteger, DontEnum | DontDelete | ReadOnly),
753         GlobalPropertyInfo(vm.propertyNames->builtinNames().isDictionaryPrivateName(), JSFunction::createBuiltinFunction(vm, globalObjectIsDictionaryCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
754         GlobalPropertyInfo(vm.propertyNames->builtinNames().isPromisePrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsIsPromiseCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
755         GlobalPropertyInfo(vm.propertyNames->builtinNames().newPromiseReactionPrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsNewPromiseReactionCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
756         GlobalPropertyInfo(vm.propertyNames->builtinNames().newPromiseCapabilityPrivateName(), m_newPromiseCapabilityFunction.get(), DontEnum | DontDelete | ReadOnly),
757         GlobalPropertyInfo(vm.propertyNames->builtinNames().triggerPromiseReactionsPrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsTriggerPromiseReactionsCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
758         GlobalPropertyInfo(vm.propertyNames->builtinNames().rejectPromisePrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsRejectPromiseCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
759         GlobalPropertyInfo(vm.propertyNames->builtinNames().fulfillPromisePrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsFulfillPromiseCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
760         GlobalPropertyInfo(vm.propertyNames->builtinNames().createResolvingFunctionsPrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsCreateResolvingFunctionsCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
761         GlobalPropertyInfo(vm.propertyNames->builtinNames().promiseReactionJobPrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsPromiseReactionJobCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
762         GlobalPropertyInfo(vm.propertyNames->builtinNames().promiseResolveThenableJobPrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsPromiseResolveThenableJobCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
763         GlobalPropertyInfo(vm.propertyNames->builtinNames().InspectorInstrumentationPrivateName(), InspectorInstrumentationObject::create(vm, this, InspectorInstrumentationObject::createStructure(vm, this, m_objectPrototype.get())), DontEnum | DontDelete | ReadOnly),
764         GlobalPropertyInfo(vm.propertyNames->MapPrivateName, mapConstructor, DontEnum | DontDelete | ReadOnly),
765         GlobalPropertyInfo(vm.propertyNames->builtinNames().generatorResumePrivateName(), JSFunction::createBuiltinFunction(vm, generatorPrototypeGeneratorResumeCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
766         GlobalPropertyInfo(vm.propertyNames->builtinNames().thisTimeValuePrivateName(), privateFuncThisTimeValue, DontEnum | DontDelete | ReadOnly),
767         GlobalPropertyInfo(vm.propertyNames->builtinNames().thisNumberValuePrivateName(), privateFuncThisNumberValue, DontEnum | DontDelete | ReadOnly),
768 #if ENABLE(INTL)
769         GlobalPropertyInfo(vm.propertyNames->builtinNames().CollatorPrivateName(), intl->getDirect(vm, vm.propertyNames->Collator), DontEnum | DontDelete | ReadOnly),
770         GlobalPropertyInfo(vm.propertyNames->builtinNames().DateTimeFormatPrivateName(), intl->getDirect(vm, vm.propertyNames->DateTimeFormat), DontEnum | DontDelete | ReadOnly),
771         GlobalPropertyInfo(vm.propertyNames->builtinNames().NumberFormatPrivateName(), intl->getDirect(vm, vm.propertyNames->NumberFormat), DontEnum | DontDelete | ReadOnly),
772 #endif // ENABLE(INTL)
773
774         GlobalPropertyInfo(vm.propertyNames->isConstructorPrivateName, JSFunction::create(vm, this, 1, String(), esSpecIsConstructor, NoIntrinsic), DontEnum | DontDelete | ReadOnly),
775         GlobalPropertyInfo(vm.propertyNames->isRegExpObjectPrivateName, JSFunction::create(vm, this, 1, String(), esSpecIsRegExpObject, IsRegExpObjectIntrinsic), DontEnum | DontDelete | ReadOnly),
776         GlobalPropertyInfo(vm.propertyNames->builtinNames().speciesConstructorPrivateName(), JSFunction::createBuiltinFunction(vm, globalObjectSpeciesConstructorCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
777
778         GlobalPropertyInfo(vm.propertyNames->regExpProtoFlagsGetterPrivateName, regExpProtoFlagsGetterObject, DontEnum | DontDelete | ReadOnly),
779         GlobalPropertyInfo(vm.propertyNames->regExpProtoGlobalGetterPrivateName, regExpProtoGlobalGetterObject, DontEnum | DontDelete | ReadOnly),
780         GlobalPropertyInfo(vm.propertyNames->regExpProtoIgnoreCaseGetterPrivateName, regExpProtoIgnoreCaseGetterObject, DontEnum | DontDelete | ReadOnly),
781         GlobalPropertyInfo(vm.propertyNames->regExpProtoMultilineGetterPrivateName, regExpProtoMultilineGetterObject, DontEnum | DontDelete | ReadOnly),
782         GlobalPropertyInfo(vm.propertyNames->regExpProtoSourceGetterPrivateName, regExpProtoSourceGetterObject, DontEnum | DontDelete | ReadOnly),
783         GlobalPropertyInfo(vm.propertyNames->regExpProtoStickyGetterPrivateName, regExpProtoStickyGetterObject, DontEnum | DontDelete | ReadOnly),
784         GlobalPropertyInfo(vm.propertyNames->regExpProtoUnicodeGetterPrivateName, regExpProtoUnicodeGetterObject, DontEnum | DontDelete | ReadOnly),
785
786         // RegExp.prototype helpers.
787         GlobalPropertyInfo(vm.propertyNames->regExpBuiltinExecPrivateName, builtinRegExpExec, DontEnum | DontDelete | ReadOnly),
788         GlobalPropertyInfo(vm.propertyNames->regExpCreatePrivateName, JSFunction::create(vm, this, 2, String(), esSpecRegExpCreate, NoIntrinsic), DontEnum | DontDelete | ReadOnly),
789         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasObservableSideEffectsForRegExpMatchPrivateName(), JSFunction::createBuiltinFunction(vm, regExpPrototypeHasObservableSideEffectsForRegExpMatchCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
790         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasObservableSideEffectsForRegExpSplitPrivateName(), JSFunction::createBuiltinFunction(vm, regExpPrototypeHasObservableSideEffectsForRegExpSplitCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
791         GlobalPropertyInfo(vm.propertyNames->builtinNames().advanceStringIndexPrivateName(), JSFunction::createBuiltinFunction(vm, regExpPrototypeAdvanceStringIndexCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
792         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpExecPrivateName(), JSFunction::createBuiltinFunction(vm, regExpPrototypeRegExpExecCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
793         GlobalPropertyInfo(vm.propertyNames->regExpMatchFastPrivateName, JSFunction::create(vm, this, 1, String(), regExpProtoFuncMatchFast), DontEnum | DontDelete | ReadOnly),
794         GlobalPropertyInfo(vm.propertyNames->regExpSearchFastPrivateName, JSFunction::create(vm, this, 1, String(), regExpProtoFuncSearchFast), DontEnum | DontDelete | ReadOnly),
795         GlobalPropertyInfo(vm.propertyNames->regExpSplitFastPrivateName, JSFunction::create(vm, this, 2, String(), regExpProtoFuncSplitFast), DontEnum | DontDelete | ReadOnly),
796         GlobalPropertyInfo(vm.propertyNames->regExpPrototypeSymbolReplacePrivateName, m_regExpPrototype->getDirect(vm, vm.propertyNames->replaceSymbol), DontEnum | DontDelete | ReadOnly),
797         GlobalPropertyInfo(vm.propertyNames->regExpTestFastPrivateName, JSFunction::create(vm, this, 1, String(), regExpProtoFuncTestFast, RegExpTestFastIntrinsic), DontEnum | DontDelete | ReadOnly),
798
799         // String.prototype helpers.
800         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasObservableSideEffectsForStringReplacePrivateName(), JSFunction::createBuiltinFunction(vm, stringPrototypeHasObservableSideEffectsForStringReplaceCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
801         GlobalPropertyInfo(vm.propertyNames->stringIncludesInternalPrivateName, JSFunction::create(vm, this, 1, String(), builtinStringIncludesInternal), DontEnum | DontDelete | ReadOnly),
802         GlobalPropertyInfo(vm.propertyNames->stringSplitFastPrivateName, JSFunction::create(vm, this, 2, String(), stringProtoFuncSplitFast), DontEnum | DontDelete | ReadOnly),
803         GlobalPropertyInfo(vm.propertyNames->stringSubstrInternalPrivateName, JSFunction::create(vm, this, 2, String(), builtinStringSubstrInternal), DontEnum | DontDelete | ReadOnly),
804     };
805     addStaticGlobals(staticGlobals, WTF_ARRAY_LENGTH(staticGlobals));
806     
807     m_specialPointers[Special::CallFunction] = m_callFunction.get();
808     m_specialPointers[Special::ApplyFunction] = m_applyFunction.get();
809     m_specialPointers[Special::ObjectConstructor] = objectConstructor;
810     m_specialPointers[Special::ArrayConstructor] = arrayConstructor;
811
812     m_linkTimeConstants[static_cast<unsigned>(LinkTimeConstant::DefinePropertyFunction)] = m_definePropertyFunction.get();
813
814     if (UNLIKELY(Options::useDollarVM())) {
815         JSDollarVMPrototype* dollarVMPrototype = JSDollarVMPrototype::create(vm, this, JSDollarVMPrototype::createStructure(vm, this, m_objectPrototype.get()));
816         m_dollarVMStructure.set(vm, this, JSDollarVM::createStructure(vm, this, dollarVMPrototype));
817         JSDollarVM* dollarVM = JSDollarVM::create(vm, m_dollarVMStructure.get());
818
819         GlobalPropertyInfo extraStaticGlobals[] = {
820             GlobalPropertyInfo(vm.propertyNames->builtinNames().dollarVMPrivateName(), dollarVM, DontEnum | DontDelete | ReadOnly),
821         };
822         addStaticGlobals(extraStaticGlobals, WTF_ARRAY_LENGTH(extraStaticGlobals));
823
824         putDirectWithoutTransition(vm, Identifier::fromString(exec, "$vm"), dollarVM, DontEnum);
825     }
826
827     resetPrototype(vm, getPrototypeDirect());
828 }
829
830 bool JSGlobalObject::put(JSCell* cell, ExecState* exec, PropertyName propertyName, JSValue value, PutPropertySlot& slot)
831 {
832     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(cell);
833     ASSERT(!Heap::heap(value) || Heap::heap(value) == Heap::heap(thisObject));
834
835     if (UNLIKELY(isThisValueAltered(slot, thisObject)))
836         return ordinarySetSlow(exec, thisObject, propertyName, value, slot.thisValue(), slot.isStrictMode());
837
838     bool shouldThrowReadOnlyError = slot.isStrictMode();
839     bool ignoreReadOnlyErrors = false;
840     bool putResult = false;
841     if (symbolTablePutTouchWatchpointSet(thisObject, exec, propertyName, value, shouldThrowReadOnlyError, ignoreReadOnlyErrors, putResult))
842         return putResult;
843     return Base::put(thisObject, exec, propertyName, value, slot);
844 }
845
846 bool JSGlobalObject::defineOwnProperty(JSObject* object, ExecState* exec, PropertyName propertyName, const PropertyDescriptor& descriptor, bool shouldThrow)
847 {
848     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(object);
849     PropertySlot slot(thisObject, PropertySlot::InternalMethodType::VMInquiry);
850     // silently ignore attempts to add accessors aliasing vars.
851     if (descriptor.isAccessorDescriptor() && symbolTableGet(thisObject, propertyName, slot))
852         return false;
853     return Base::defineOwnProperty(thisObject, exec, propertyName, descriptor, shouldThrow);
854 }
855
856 void JSGlobalObject::addGlobalVar(const Identifier& ident)
857 {
858     ConcurrentJITLocker locker(symbolTable()->m_lock);
859     SymbolTableEntry entry = symbolTable()->get(locker, ident.impl());
860     if (!entry.isNull())
861         return;
862     
863     ScopeOffset offset = symbolTable()->takeNextScopeOffset(locker);
864     SymbolTableEntry newEntry(VarOffset(offset), 0);
865     newEntry.prepareToWatch();
866     symbolTable()->add(locker, ident.impl(), WTFMove(newEntry));
867     
868     ScopeOffset offsetForAssert = addVariables(1, jsUndefined());
869     RELEASE_ASSERT(offsetForAssert == offset);
870 }
871
872 void JSGlobalObject::addFunction(ExecState* exec, const Identifier& propertyName)
873 {
874     VM& vm = exec->vm();
875     removeDirect(vm, propertyName); // Newly declared functions overwrite existing properties.
876     addGlobalVar(propertyName);
877 }
878
879 void JSGlobalObject::setGlobalScopeExtension(JSScope* scope)
880 {
881     m_globalScopeExtension.set(vm(), this, scope);
882 }
883
884 void JSGlobalObject::clearGlobalScopeExtension()
885 {
886     m_globalScopeExtension.clear();
887 }
888
889 static inline JSObject* lastInPrototypeChain(JSObject* object)
890 {
891     JSObject* o = object;
892     while (o->getPrototypeDirect().isObject())
893         o = asObject(o->getPrototypeDirect());
894     return o;
895 }
896
897 // Private namespace for helpers for JSGlobalObject::haveABadTime()
898 namespace {
899
900 class ObjectsWithBrokenIndexingFinder : public MarkedBlock::VoidFunctor {
901 public:
902     ObjectsWithBrokenIndexingFinder(MarkedArgumentBuffer&, JSGlobalObject*);
903     IterationStatus operator()(JSCell*);
904
905 private:
906     void visit(JSCell*);
907
908     MarkedArgumentBuffer& m_foundObjects;
909     JSGlobalObject* m_globalObject;
910 };
911
912 ObjectsWithBrokenIndexingFinder::ObjectsWithBrokenIndexingFinder(
913     MarkedArgumentBuffer& foundObjects, JSGlobalObject* globalObject)
914     : m_foundObjects(foundObjects)
915     , m_globalObject(globalObject)
916 {
917 }
918
919 inline bool hasBrokenIndexing(JSObject* object)
920 {
921     // This will change if we have more indexing types.
922     IndexingType type = object->indexingType();
923     // This could be made obviously more efficient, but isn't made so right now, because
924     // we expect this to be an unlikely slow path anyway.
925     return hasUndecided(type) || hasInt32(type) || hasDouble(type) || hasContiguous(type) || hasArrayStorage(type);
926 }
927
928 inline void ObjectsWithBrokenIndexingFinder::visit(JSCell* cell)
929 {
930     if (!cell->isObject())
931         return;
932     
933     JSObject* object = asObject(cell);
934
935     // Run this filter first, since it's cheap, and ought to filter out a lot of objects.
936     if (!hasBrokenIndexing(object))
937         return;
938     
939     // We only want to have a bad time in the affected global object, not in the entire
940     // VM. But we have to be careful, since there may be objects that claim to belong to
941     // a different global object that have prototypes from our global object.
942     bool foundGlobalObject = false;
943     for (JSObject* current = object; ;) {
944         if (current->globalObject() == m_globalObject) {
945             foundGlobalObject = true;
946             break;
947         }
948         
949         JSValue prototypeValue = current->getPrototypeDirect();
950         if (prototypeValue.isNull())
951             break;
952         current = asObject(prototypeValue);
953     }
954     if (!foundGlobalObject)
955         return;
956     
957     m_foundObjects.append(object);
958 }
959
960 IterationStatus ObjectsWithBrokenIndexingFinder::operator()(JSCell* cell)
961 {
962     visit(cell);
963     return IterationStatus::Continue;
964 }
965
966 } // end private namespace for helpers for JSGlobalObject::haveABadTime()
967
968 void JSGlobalObject::haveABadTime(VM& vm)
969 {
970     ASSERT(&vm == &this->vm());
971     
972     if (isHavingABadTime())
973         return;
974     
975     // Make sure that all allocations or indexed storage transitions that are inlining
976     // the assumption that it's safe to transition to a non-SlowPut array storage don't
977     // do so anymore.
978     m_havingABadTimeWatchpoint->fireAll("Having a bad time");
979     ASSERT(isHavingABadTime()); // The watchpoint is what tells us that we're having a bad time.
980     
981     // Make sure that all JSArray allocations that load the appropriate structure from
982     // this object now load a structure that uses SlowPut.
983     for (unsigned i = 0; i < NumberOfIndexingShapes; ++i)
984         m_arrayStructureForIndexingShapeDuringAllocation[i].set(vm, this, originalArrayStructureForIndexingType(ArrayWithSlowPutArrayStorage));
985
986     // Same for any special array structures.
987     m_regExpMatchesArrayStructure.set(vm, this, m_regExpMatchesArraySlowPutStructure.get());
988     
989     // Make sure that all objects that have indexed storage switch to the slow kind of
990     // indexed storage.
991     MarkedArgumentBuffer foundObjects; // Use MarkedArgumentBuffer because switchToSlowPutArrayStorage() may GC.
992     ObjectsWithBrokenIndexingFinder finder(foundObjects, this);
993     {
994         HeapIterationScope iterationScope(vm.heap);
995         vm.heap.objectSpace().forEachLiveCell(iterationScope, finder);
996     }
997     while (!foundObjects.isEmpty()) {
998         JSObject* object = asObject(foundObjects.last());
999         foundObjects.removeLast();
1000         ASSERT(hasBrokenIndexing(object));
1001         object->switchToSlowPutArrayStorage(vm);
1002     }
1003 }
1004
1005 bool JSGlobalObject::objectPrototypeIsSane()
1006 {
1007     return !hasIndexedProperties(m_objectPrototype->indexingType())
1008         && m_objectPrototype->getPrototypeDirect().isNull();
1009 }
1010
1011 bool JSGlobalObject::arrayPrototypeChainIsSane()
1012 {
1013     return !hasIndexedProperties(m_arrayPrototype->indexingType())
1014         && m_arrayPrototype->getPrototypeDirect() == m_objectPrototype.get()
1015         && objectPrototypeIsSane();
1016 }
1017
1018 bool JSGlobalObject::stringPrototypeChainIsSane()
1019 {
1020     return !hasIndexedProperties(m_stringPrototype->indexingType())
1021         && m_stringPrototype->getPrototypeDirect() == m_objectPrototype.get()
1022         && objectPrototypeIsSane();
1023 }
1024
1025 // Set prototype, and also insert the object prototype at the end of the chain.
1026 void JSGlobalObject::resetPrototype(VM& vm, JSValue prototype)
1027 {
1028     setPrototypeDirect(vm, prototype);
1029
1030     JSObject* oldLastInPrototypeChain = lastInPrototypeChain(this);
1031     JSObject* objectPrototype = m_objectPrototype.get();
1032     if (oldLastInPrototypeChain != objectPrototype)
1033         oldLastInPrototypeChain->setPrototypeDirect(vm, objectPrototype);
1034
1035     // Whenever we change the prototype of the global object, we need to create a new JSProxy with the correct prototype.
1036     setGlobalThis(vm, JSProxy::create(vm, JSProxy::createStructure(vm, this, prototype, PureForwardingProxyType), this));
1037 }
1038
1039 void JSGlobalObject::visitChildren(JSCell* cell, SlotVisitor& visitor)
1040
1041     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(cell);
1042     ASSERT_GC_OBJECT_INHERITS(thisObject, info());
1043     Base::visitChildren(thisObject, visitor);
1044
1045     visitor.append(&thisObject->m_globalThis);
1046
1047     visitor.append(&thisObject->m_globalLexicalEnvironment);
1048     visitor.append(&thisObject->m_globalScopeExtension);
1049     visitor.append(&thisObject->m_globalCallee);
1050     visitor.append(&thisObject->m_regExpConstructor);
1051     visitor.append(&thisObject->m_errorConstructor);
1052     visitor.append(&thisObject->m_nativeErrorPrototypeStructure);
1053     visitor.append(&thisObject->m_nativeErrorStructure);
1054     thisObject->m_evalErrorConstructor.visit(visitor);
1055     visitor.append(&thisObject->m_rangeErrorConstructor);
1056     thisObject->m_referenceErrorConstructor.visit(visitor);
1057     thisObject->m_syntaxErrorConstructor.visit(visitor);
1058     visitor.append(&thisObject->m_typeErrorConstructor);
1059     thisObject->m_URIErrorConstructor.visit(visitor);
1060     visitor.append(&thisObject->m_objectConstructor);
1061     visitor.append(&thisObject->m_promiseConstructor);
1062
1063     visitor.append(&thisObject->m_nullGetterFunction);
1064     visitor.append(&thisObject->m_nullSetterFunction);
1065
1066     visitor.append(&thisObject->m_parseIntFunction);
1067     visitor.append(&thisObject->m_evalFunction);
1068     visitor.append(&thisObject->m_callFunction);
1069     visitor.append(&thisObject->m_applyFunction);
1070     visitor.append(&thisObject->m_definePropertyFunction);
1071     thisObject->m_arrayProtoValuesFunction.visit(visitor);
1072     thisObject->m_initializePromiseFunction.visit(visitor);
1073     visitor.append(&thisObject->m_newPromiseCapabilityFunction);
1074     visitor.append(&thisObject->m_functionProtoHasInstanceSymbolFunction);
1075     thisObject->m_throwTypeErrorGetterSetter.visit(visitor);
1076     thisObject->m_throwTypeErrorCalleeAndCallerGetterSetter.visit(visitor);
1077     thisObject->m_throwTypeErrorArgumentsAndCallerInStrictModeGetterSetter.visit(visitor);
1078     thisObject->m_throwTypeErrorArgumentsAndCallerInClassContextGetterSetter.visit(visitor);
1079     visitor.append(&thisObject->m_moduleLoader);
1080
1081     visitor.append(&thisObject->m_objectPrototype);
1082     visitor.append(&thisObject->m_functionPrototype);
1083     visitor.append(&thisObject->m_arrayPrototype);
1084     visitor.append(&thisObject->m_errorPrototype);
1085     visitor.append(&thisObject->m_iteratorPrototype);
1086     visitor.append(&thisObject->m_generatorFunctionPrototype);
1087     visitor.append(&thisObject->m_generatorPrototype);
1088
1089     thisObject->m_debuggerScopeStructure.visit(visitor);
1090     thisObject->m_withScopeStructure.visit(visitor);
1091     visitor.append(&thisObject->m_strictEvalActivationStructure);
1092     visitor.append(&thisObject->m_lexicalEnvironmentStructure);
1093     thisObject->m_moduleEnvironmentStructure.visit(visitor);
1094     visitor.append(&thisObject->m_directArgumentsStructure);
1095     visitor.append(&thisObject->m_scopedArgumentsStructure);
1096     visitor.append(&thisObject->m_clonedArgumentsStructure);
1097     visitor.append(&thisObject->m_objectStructureForObjectConstructor);
1098     for (unsigned i = 0; i < NumberOfIndexingShapes; ++i)
1099         visitor.append(&thisObject->m_originalArrayStructureForIndexingShape[i]);
1100     for (unsigned i = 0; i < NumberOfIndexingShapes; ++i)
1101         visitor.append(&thisObject->m_arrayStructureForIndexingShapeDuringAllocation[i]);
1102     thisObject->m_callbackConstructorStructure.visit(visitor);
1103     thisObject->m_callbackFunctionStructure.visit(visitor);
1104     thisObject->m_callbackObjectStructure.visit(visitor);
1105     visitor.append(&thisObject->m_propertyNameIteratorStructure);
1106 #if JSC_OBJC_API_ENABLED
1107     thisObject->m_objcCallbackFunctionStructure.visit(visitor);
1108     thisObject->m_objcWrapperObjectStructure.visit(visitor);
1109 #endif
1110     thisObject->m_nullPrototypeObjectStructure.visit(visitor);
1111     visitor.append(&thisObject->m_errorStructure);
1112     visitor.append(&thisObject->m_calleeStructure);
1113     visitor.append(&thisObject->m_functionStructure);
1114     thisObject->m_boundSlotBaseFunctionStructure.visit(visitor);
1115     thisObject->m_boundFunctionStructure.visit(visitor);
1116     visitor.append(&thisObject->m_getterSetterStructure);
1117     thisObject->m_nativeStdFunctionStructure.visit(visitor);
1118     thisObject->m_namedFunctionStructure.visit(visitor);
1119     visitor.append(&thisObject->m_symbolObjectStructure);
1120     visitor.append(&thisObject->m_regExpStructure);
1121     visitor.append(&thisObject->m_generatorFunctionStructure);
1122     visitor.append(&thisObject->m_iteratorResultObjectStructure);
1123     visitor.append(&thisObject->m_regExpMatchesArrayStructure);
1124     visitor.append(&thisObject->m_regExpMatchesArraySlowPutStructure);
1125     visitor.append(&thisObject->m_moduleRecordStructure);
1126     visitor.append(&thisObject->m_moduleNamespaceObjectStructure);
1127     visitor.append(&thisObject->m_dollarVMStructure);
1128     visitor.append(&thisObject->m_proxyObjectStructure);
1129     visitor.append(&thisObject->m_callableProxyObjectStructure);
1130     visitor.append(&thisObject->m_proxyRevokeStructure);
1131 #if ENABLE(WEBASSEMBLY)
1132     visitor.append(&thisObject->m_wasmModuleStructure);
1133 #endif
1134
1135 #define VISIT_SIMPLE_TYPE(CapitalName, lowerName, properName, instanceType, jsName) \
1136     visitor.append(&thisObject->m_ ## lowerName ## Prototype); \
1137     visitor.append(&thisObject->m_ ## properName ## Structure); \
1138
1139     FOR_EACH_SIMPLE_BUILTIN_TYPE(VISIT_SIMPLE_TYPE)
1140
1141 #undef VISIT_SIMPLE_TYPE
1142
1143 #define VISIT_LAZY_TYPE(CapitalName, lowerName, properName, instanceType, jsName) \
1144     thisObject->m_ ## properName ## Structure.visit(visitor);
1145     
1146     FOR_EACH_LAZY_BUILTIN_TYPE(VISIT_LAZY_TYPE)
1147     FOR_EACH_BUILTIN_DERIVED_ITERATOR_TYPE(VISIT_LAZY_TYPE)
1148
1149 #undef VISIT_LAZY_TYPE
1150
1151     for (unsigned i = NUMBER_OF_TYPED_ARRAY_TYPES; i--;)
1152         thisObject->lazyTypedArrayStructure(indexToTypedArrayType(i)).visit(visitor);
1153     
1154     visitor.append(&thisObject->m_speciesGetterSetter);
1155     thisObject->m_typedArrayProto.visit(visitor);
1156     thisObject->m_typedArraySuperConstructor.visit(visitor);
1157 }
1158
1159 JSValue JSGlobalObject::toThis(JSCell*, ExecState* exec, ECMAMode ecmaMode)
1160 {
1161     if (ecmaMode == StrictMode)
1162         return jsUndefined();
1163     return exec->globalThisValue();
1164 }
1165
1166 ExecState* JSGlobalObject::globalExec()
1167 {
1168     return CallFrame::create(m_globalCallFrame);
1169 }
1170
1171 void JSGlobalObject::addStaticGlobals(GlobalPropertyInfo* globals, int count)
1172 {
1173     ScopeOffset startOffset = addVariables(count, jsUndefined());
1174
1175     for (int i = 0; i < count; ++i) {
1176         GlobalPropertyInfo& global = globals[i];
1177         ASSERT(global.attributes & DontDelete);
1178         
1179         WatchpointSet* watchpointSet = nullptr;
1180         WriteBarrierBase<Unknown>* variable = nullptr;
1181         {
1182             ConcurrentJITLocker locker(symbolTable()->m_lock);
1183             ScopeOffset offset = symbolTable()->takeNextScopeOffset(locker);
1184             RELEASE_ASSERT(offset = startOffset + i);
1185             SymbolTableEntry newEntry(VarOffset(offset), global.attributes);
1186             newEntry.prepareToWatch();
1187             watchpointSet = newEntry.watchpointSet();
1188             symbolTable()->add(locker, global.identifier.impl(), WTFMove(newEntry));
1189             variable = &variableAt(offset);
1190         }
1191         symbolTablePutTouchWatchpointSet(vm(), this, global.identifier, global.value, variable, watchpointSet);
1192     }
1193 }
1194
1195 bool JSGlobalObject::getOwnPropertySlot(JSObject* object, ExecState* exec, PropertyName propertyName, PropertySlot& slot)
1196 {
1197     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(object);
1198     if (getStaticPropertySlot<JSGlobalObject, Base>(exec, globalObjectTable, thisObject, propertyName, slot))
1199         return true;
1200     return symbolTableGet(thisObject, propertyName, slot);
1201 }
1202
1203 void JSGlobalObject::clearRareData(JSCell* cell)
1204 {
1205     jsCast<JSGlobalObject*>(cell)->m_rareData = nullptr;
1206 }
1207
1208 void slowValidateCell(JSGlobalObject* globalObject)
1209 {
1210     RELEASE_ASSERT(globalObject->isGlobalObject());
1211     ASSERT_GC_OBJECT_INHERITS(globalObject, JSGlobalObject::info());
1212 }
1213
1214 UnlinkedProgramCodeBlock* JSGlobalObject::createProgramCodeBlock(CallFrame* callFrame, ProgramExecutable* executable, JSObject** exception)
1215 {
1216     ParserError error;
1217     JSParserStrictMode strictMode = executable->isStrictMode() ? JSParserStrictMode::Strict : JSParserStrictMode::NotStrict;
1218     DebuggerMode debuggerMode = hasInteractiveDebugger() ? DebuggerOn : DebuggerOff;
1219     UnlinkedProgramCodeBlock* unlinkedCodeBlock = vm().codeCache()->getProgramCodeBlock(
1220         vm(), executable, executable->source(), JSParserBuiltinMode::NotBuiltin, strictMode, 
1221         debuggerMode, error);
1222
1223     if (hasDebugger())
1224         debugger()->sourceParsed(callFrame, executable->source().provider(), error.line(), error.message());
1225
1226     if (error.isValid()) {
1227         *exception = error.toErrorObject(this, executable->source());
1228         return nullptr;
1229     }
1230     
1231     return unlinkedCodeBlock;
1232 }
1233
1234 UnlinkedEvalCodeBlock* JSGlobalObject::createEvalCodeBlock(CallFrame* callFrame, EvalExecutable* executable, const VariableEnvironment* variablesUnderTDZ)
1235 {
1236     ParserError error;
1237     JSParserStrictMode strictMode = executable->isStrictMode() ? JSParserStrictMode::Strict : JSParserStrictMode::NotStrict;
1238     DebuggerMode debuggerMode = hasInteractiveDebugger() ? DebuggerOn : DebuggerOff;
1239     EvalContextType evalContextType = executable->executableInfo().evalContextType();
1240     
1241     UnlinkedEvalCodeBlock* unlinkedCodeBlock = vm().codeCache()->getEvalCodeBlock(
1242         vm(), executable, executable->source(), JSParserBuiltinMode::NotBuiltin, strictMode, debuggerMode, error, evalContextType, variablesUnderTDZ);
1243
1244     if (hasDebugger())
1245         debugger()->sourceParsed(callFrame, executable->source().provider(), error.line(), error.message());
1246
1247     if (error.isValid()) {
1248         throwVMError(callFrame, error.toErrorObject(this, executable->source()));
1249         return nullptr;
1250     }
1251
1252     return unlinkedCodeBlock;
1253 }
1254
1255 UnlinkedModuleProgramCodeBlock* JSGlobalObject::createModuleProgramCodeBlock(CallFrame* callFrame, ModuleProgramExecutable* executable)
1256 {
1257     ParserError error;
1258     DebuggerMode debuggerMode = hasInteractiveDebugger() ? DebuggerOn : DebuggerOff;
1259     UnlinkedModuleProgramCodeBlock* unlinkedCodeBlock = vm().codeCache()->getModuleProgramCodeBlock(
1260         vm(), executable, executable->source(), JSParserBuiltinMode::NotBuiltin, debuggerMode, error);
1261
1262     if (hasDebugger())
1263         debugger()->sourceParsed(callFrame, executable->source().provider(), error.line(), error.message());
1264
1265     if (error.isValid()) {
1266         throwVMError(callFrame, error.toErrorObject(this, executable->source()));
1267         return nullptr;
1268     }
1269
1270     return unlinkedCodeBlock;
1271 }
1272
1273 void JSGlobalObject::setRemoteDebuggingEnabled(bool enabled)
1274 {
1275 #if ENABLE(REMOTE_INSPECTOR)
1276     m_inspectorDebuggable->setRemoteDebuggingAllowed(enabled);
1277 #else
1278     UNUSED_PARAM(enabled);
1279 #endif
1280 }
1281
1282 bool JSGlobalObject::remoteDebuggingEnabled() const
1283 {
1284 #if ENABLE(REMOTE_INSPECTOR)
1285     return m_inspectorDebuggable->remoteDebuggingAllowed();
1286 #else
1287     return false;
1288 #endif
1289 }
1290
1291 #if ENABLE(WEB_REPLAY)
1292 void JSGlobalObject::setInputCursor(PassRefPtr<InputCursor> prpCursor)
1293 {
1294     m_inputCursor = prpCursor;
1295     ASSERT(m_inputCursor);
1296
1297     InputCursor& cursor = inputCursor();
1298     // Save or set the random seed. This performed here rather than the constructor
1299     // to avoid threading the input cursor through all the abstraction layers.
1300     if (cursor.isCapturing())
1301         cursor.appendInput<SetRandomSeed>(m_weakRandom.seed());
1302     else if (cursor.isReplaying()) {
1303         if (SetRandomSeed* input = cursor.fetchInput<SetRandomSeed>())
1304             m_weakRandom.setSeed(static_cast<unsigned>(input->randomSeed()));
1305     }
1306 }
1307 #endif
1308
1309 void JSGlobalObject::setName(const String& name)
1310 {
1311     m_name = name;
1312
1313 #if ENABLE(REMOTE_INSPECTOR)
1314     m_inspectorDebuggable->update();
1315 #endif
1316 }
1317
1318 # if ENABLE(INTL)
1319 const HashSet<String>& JSGlobalObject::intlCollatorAvailableLocales()
1320 {
1321     if (m_intlCollatorAvailableLocales.isEmpty()) {
1322         int32_t count = ucol_countAvailable();
1323         for (int32_t i = 0; i < count; ++i) {
1324             String locale(ucol_getAvailable(i));
1325             convertICULocaleToBCP47LanguageTag(locale);
1326             m_intlCollatorAvailableLocales.add(locale);
1327         }
1328     }
1329     return m_intlCollatorAvailableLocales;
1330 }
1331
1332 const HashSet<String>& JSGlobalObject::intlDateTimeFormatAvailableLocales()
1333 {
1334     if (m_intlDateTimeFormatAvailableLocales.isEmpty()) {
1335         int32_t count = udat_countAvailable();
1336         for (int32_t i = 0; i < count; ++i) {
1337             String locale(udat_getAvailable(i));
1338             convertICULocaleToBCP47LanguageTag(locale);
1339             m_intlDateTimeFormatAvailableLocales.add(locale);
1340         }
1341     }
1342     return m_intlDateTimeFormatAvailableLocales;
1343 }
1344
1345 const HashSet<String>& JSGlobalObject::intlNumberFormatAvailableLocales()
1346 {
1347     if (m_intlNumberFormatAvailableLocales.isEmpty()) {
1348         int32_t count = unum_countAvailable();
1349         for (int32_t i = 0; i < count; ++i) {
1350             String locale(unum_getAvailable(i));
1351             convertICULocaleToBCP47LanguageTag(locale);
1352             m_intlNumberFormatAvailableLocales.add(locale);
1353         }
1354     }
1355     return m_intlNumberFormatAvailableLocales;
1356 }
1357 #endif // ENABLE(INTL)
1358
1359 void JSGlobalObject::queueMicrotask(Ref<Microtask>&& task)
1360 {
1361     if (globalObjectMethodTable()->queueTaskToEventLoop) {
1362         globalObjectMethodTable()->queueTaskToEventLoop(this, WTFMove(task));
1363         return;
1364     }
1365
1366     vm().queueMicrotask(this, WTFMove(task));
1367 }
1368
1369 bool JSGlobalObject::hasDebugger() const
1370
1371     return m_debugger;
1372 }
1373
1374 bool JSGlobalObject::hasInteractiveDebugger() const 
1375
1376     return m_debugger && m_debugger->isInteractivelyDebugging();
1377 }
1378
1379 } // namespace JSC