Unreviewed, roll out r240220 due to date-format-xparb regression
[WebKit-https.git] / Source / JavaScriptCore / runtime / JSGlobalObject.cpp
1 /*
2  * Copyright (C) 2007-2019 Apple Inc. All rights reserved.
3  * Copyright (C) 2008 Cameron Zwarich (cwzwarich@uwaterloo.ca)
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *
9  * 1.  Redistributions of source code must retain the above copyright
10  *     notice, this list of conditions and the following disclaimer.
11  * 2.  Redistributions in binary form must reproduce the above copyright
12  *     notice, this list of conditions and the following disclaimer in the
13  *     documentation and/or other materials provided with the distribution.
14  * 3.  Neither the name of Apple Inc. ("Apple") nor the names of
15  *     its contributors may be used to endorse or promote products derived
16  *     from this software without specific prior written permission.
17  *
18  * THIS SOFTWARE IS PROVIDED BY APPLE AND ITS CONTRIBUTORS "AS IS" AND ANY
19  * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
20  * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
21  * DISCLAIMED. IN NO EVENT SHALL APPLE OR ITS CONTRIBUTORS BE LIABLE FOR ANY
22  * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
23  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
24  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
25  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
26  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
27  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
28  */
29
30 #include "config.h"
31 #include "JSGlobalObject.h"
32
33 #include "ArrayConstructor.h"
34 #include "ArrayIteratorPrototype.h"
35 #include "ArrayPrototype.h"
36 #include "AsyncFromSyncIteratorPrototype.h"
37 #include "AtomicsObject.h"
38 #include "AsyncFunctionConstructor.h"
39 #include "AsyncFunctionPrototype.h"
40 #include "AsyncGeneratorFunctionConstructor.h"
41 #include "AsyncGeneratorFunctionPrototype.h"
42 #include "AsyncGeneratorPrototype.h"
43 #include "AsyncIteratorPrototype.h"
44 #include "BigIntConstructor.h"
45 #include "BigIntObject.h"
46 #include "BigIntPrototype.h"
47 #include "BooleanConstructor.h"
48 #include "BooleanPrototype.h"
49 #include "BuiltinNames.h"
50 #include "CatchScope.h"
51 #include "ClonedArguments.h"
52 #include "CodeBlock.h"
53 #include "CodeBlockSetInlines.h"
54 #include "CodeCache.h"
55 #include "ConsoleObject.h"
56 #include "DateConstructor.h"
57 #include "DatePrototype.h"
58 #include "Debugger.h"
59 #include "DebuggerScope.h"
60 #include "DirectArguments.h"
61 #include "DirectEvalExecutable.h"
62 #include "ECMAScriptSpecInternalFunctions.h"
63 #include "Error.h"
64 #include "ErrorConstructor.h"
65 #include "ErrorPrototype.h"
66 #include "Exception.h"
67 #include "FunctionConstructor.h"
68 #include "FunctionPrototype.h"
69 #include "GeneratorFunctionConstructor.h"
70 #include "GeneratorFunctionPrototype.h"
71 #include "GeneratorPrototype.h"
72 #include "GetterSetter.h"
73 #include "HeapIterationScope.h"
74 #include "IndirectEvalExecutable.h"
75 #include "InspectorInstrumentationObject.h"
76 #include "Interpreter.h"
77 #include "IteratorPrototype.h"
78 #include "JSAPIWrapperObject.h"
79 #include "JSArrayBuffer.h"
80 #include "JSArrayBufferConstructor.h"
81 #include "JSArrayBufferPrototype.h"
82 #include "JSAsyncFunction.h"
83 #include "JSAsyncGeneratorFunction.h"
84 #include "JSBigInt.h"
85 #include "JSBoundFunction.h"
86 #include "JSCInlines.h"
87 #include "JSCallbackConstructor.h"
88 #include "JSCallbackFunction.h"
89 #include "JSCallbackObject.h"
90 #include "JSCustomGetterSetterFunction.h"
91 #include "JSDataView.h"
92 #include "JSDataViewPrototype.h"
93 #include "JSDollarVM.h"
94 #include "JSFunction.h"
95 #include "JSGeneratorFunction.h"
96 #include "JSGenericTypedArrayViewConstructorInlines.h"
97 #include "JSGenericTypedArrayViewInlines.h"
98 #include "JSGenericTypedArrayViewPrototypeInlines.h"
99 #include "JSGlobalObjectFunctions.h"
100 #include "JSInternalPromise.h"
101 #include "JSInternalPromiseConstructor.h"
102 #include "JSInternalPromisePrototype.h"
103 #include "JSLexicalEnvironment.h"
104 #include "JSLock.h"
105 #include "JSMap.h"
106 #include "JSMicrotask.h"
107 #include "JSModuleEnvironment.h"
108 #include "JSModuleLoader.h"
109 #include "JSModuleNamespaceObject.h"
110 #include "JSModuleRecord.h"
111 #include "JSNativeStdFunction.h"
112 #include "JSONObject.h"
113 #include "JSPromise.h"
114 #include "JSPromiseConstructor.h"
115 #include "JSPromisePrototype.h"
116 #include "JSSet.h"
117 #include "JSStringIterator.h"
118 #include "JSTypedArrayConstructors.h"
119 #include "JSTypedArrayPrototypes.h"
120 #include "JSTypedArrayViewConstructor.h"
121 #include "JSTypedArrayViewPrototype.h"
122 #include "JSTypedArrays.h"
123 #include "JSWeakMap.h"
124 #include "JSWeakSet.h"
125 #include "JSWebAssembly.h"
126 #include "JSWithScope.h"
127 #include "LazyClassStructureInlines.h"
128 #include "LazyPropertyInlines.h"
129 #include "Lookup.h"
130 #include "MapConstructor.h"
131 #include "MapIteratorPrototype.h"
132 #include "MapPrototype.h"
133 #include "MarkedSpaceInlines.h"
134 #include "MathObject.h"
135 #include "Microtask.h"
136 #include "NativeErrorConstructor.h"
137 #include "NativeErrorPrototype.h"
138 #include "NullGetterFunction.h"
139 #include "NullSetterFunction.h"
140 #include "NumberConstructor.h"
141 #include "NumberPrototype.h"
142 #include "ObjCCallbackFunction.h"
143 #include "ObjectConstructor.h"
144 #include "ObjectPropertyChangeAdaptiveWatchpoint.h"
145 #include "ObjectPropertyConditionSet.h"
146 #include "ObjectPrototype.h"
147 #include "ParserError.h"
148 #include "ProxyConstructor.h"
149 #include "ProxyObject.h"
150 #include "ProxyRevoke.h"
151 #include "ReflectObject.h"
152 #include "RegExpConstructor.h"
153 #include "RegExpMatchesArray.h"
154 #include "RegExpObject.h"
155 #include "RegExpPrototype.h"
156 #include "ScopedArguments.h"
157 #include "SetConstructor.h"
158 #include "SetIteratorPrototype.h"
159 #include "SetPrototype.h"
160 #include "StrictEvalActivation.h"
161 #include "StringConstructor.h"
162 #include "StringIteratorPrototype.h"
163 #include "StringPrototype.h"
164 #include "Symbol.h"
165 #include "SymbolConstructor.h"
166 #include "SymbolObject.h"
167 #include "SymbolPrototype.h"
168 #include "VariableWriteFireDetail.h"
169 #include "WeakGCMapInlines.h"
170 #include "WeakMapConstructor.h"
171 #include "WeakMapPrototype.h"
172 #include "WeakSetConstructor.h"
173 #include "WeakSetPrototype.h"
174 #include "WebAssemblyPrototype.h"
175 #include "WebAssemblyToJSCallee.h"
176 #include <wtf/RandomNumber.h>
177
178 #if ENABLE(INTL)
179 #include "IntlObject.h"
180 #include <unicode/ucol.h>
181 #include <unicode/udat.h>
182 #include <unicode/unum.h>
183 #endif // ENABLE(INTL)
184
185 #if ENABLE(REMOTE_INSPECTOR)
186 #include "JSGlobalObjectDebuggable.h"
187 #include "JSGlobalObjectInspectorController.h"
188 #endif
189
190 #ifdef JSC_GLIB_API_ENABLED
191 #include "JSCCallbackFunction.h"
192 #include "JSCWrapperMap.h"
193 #endif
194
195 namespace JSC {
196
197 static JSValue createProxyProperty(VM& vm, JSObject* object)
198 {
199     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
200     return ProxyConstructor::create(vm, ProxyConstructor::createStructure(vm, global, global->functionPrototype()));
201 }
202
203 static JSValue createJSONProperty(VM& vm, JSObject* object)
204 {
205     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
206     return JSONObject::create(vm, JSONObject::createStructure(vm, global, global->objectPrototype()));
207 }
208
209 static JSValue createMathProperty(VM& vm, JSObject* object)
210 {
211     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
212     return MathObject::create(vm, global, MathObject::createStructure(vm, global, global->objectPrototype()));
213 }
214
215 static JSValue createConsoleProperty(VM& vm, JSObject* object)
216 {
217     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
218     return ConsoleObject::create(vm, global, ConsoleObject::createStructure(vm, global, constructEmptyObject(global->globalExec())));
219 }
220
221 static EncodedJSValue JSC_HOST_CALL makeBoundFunction(ExecState* exec)
222 {
223     VM& vm = exec->vm();
224     JSGlobalObject* globalObject = exec->lexicalGlobalObject();
225
226     JSObject* target = asObject(exec->uncheckedArgument(0));
227     JSValue boundThis = exec->uncheckedArgument(1);
228     JSValue boundArgs = exec->uncheckedArgument(2);
229     JSValue length = exec->uncheckedArgument(3);
230     JSString* name = asString(exec->uncheckedArgument(4));
231
232     return JSValue::encode(JSBoundFunction::create(
233         vm, exec, globalObject, target, boundThis, boundArgs.isCell() ? jsCast<JSArray*>(boundArgs) : nullptr, length.asInt32(), name->value(exec)));
234 }
235
236 static EncodedJSValue JSC_HOST_CALL hasOwnLengthProperty(ExecState* exec)
237 {
238     VM& vm = exec->vm();
239     JSObject* target = asObject(exec->uncheckedArgument(0));
240     return JSValue::encode(jsBoolean(target->hasOwnProperty(exec, vm.propertyNames->length)));
241 }
242
243 #if !ASSERT_DISABLED
244 static EncodedJSValue JSC_HOST_CALL assertCall(ExecState* exec)
245 {
246     RELEASE_ASSERT(exec->argument(0).isBoolean());
247     if (exec->argument(0).asBoolean())
248         return JSValue::encode(jsUndefined());
249
250     bool iteratedOnce = false;
251     CodeBlock* codeBlock = nullptr;
252     unsigned line;
253     exec->iterate([&] (StackVisitor& visitor) {
254         if (!iteratedOnce) {
255             iteratedOnce = true;
256             return StackVisitor::Continue;
257         }
258
259         RELEASE_ASSERT(visitor->hasLineAndColumnInfo());
260         unsigned column;
261         visitor->computeLineAndColumn(line, column);
262         codeBlock = visitor->codeBlock();
263         return StackVisitor::Done;
264     });
265     RELEASE_ASSERT(!!codeBlock);
266     RELEASE_ASSERT_WITH_MESSAGE(false, "JS assertion failed at line %u in:\n%s\n", line, codeBlock->sourceCodeForTools().data());
267     return JSValue::encode(jsUndefined());
268 }
269 #endif
270
271 } // namespace JSC
272
273 #include "JSGlobalObject.lut.h"
274
275 namespace JSC {
276
277 const ClassInfo JSGlobalObject::s_info = { "GlobalObject", &Base::s_info, &globalObjectTable, nullptr, CREATE_METHOD_TABLE(JSGlobalObject) };
278
279 const GlobalObjectMethodTable JSGlobalObject::s_globalObjectMethodTable = {
280     &supportsRichSourceInfo,
281     &shouldInterruptScript,
282     &javaScriptRuntimeFlags,
283     nullptr, // queueTaskToEventLoop
284     &shouldInterruptScriptBeforeTimeout,
285     nullptr, // moduleLoaderImportModule
286     nullptr, // moduleLoaderResolve
287     nullptr, // moduleLoaderFetch
288     nullptr, // moduleLoaderCreateImportMetaProperties
289     nullptr, // moduleLoaderEvaluate
290     nullptr, // promiseRejectionTracker
291     nullptr, // defaultLanguage
292     nullptr, // compileStreaming
293     nullptr, // instantiateStreaming
294 };
295
296 /* Source for JSGlobalObject.lut.h
297 @begin globalObjectTable
298   isNaN                 JSBuiltin                                    DontEnum|Function 1
299   isFinite              JSBuiltin                                    DontEnum|Function 1
300   escape                globalFuncEscape                             DontEnum|Function 1
301   unescape              globalFuncUnescape                           DontEnum|Function 1
302   decodeURI             globalFuncDecodeURI                          DontEnum|Function 1
303   decodeURIComponent    globalFuncDecodeURIComponent                 DontEnum|Function 1
304   encodeURI             globalFuncEncodeURI                          DontEnum|Function 1
305   encodeURIComponent    globalFuncEncodeURIComponent                 DontEnum|Function 1
306   EvalError             JSGlobalObject::m_evalErrorConstructor       DontEnum|CellProperty
307   globalThis            JSGlobalObject::m_globalThis                 DontEnum|CellProperty
308   ReferenceError        JSGlobalObject::m_referenceErrorConstructor  DontEnum|CellProperty
309   SyntaxError           JSGlobalObject::m_syntaxErrorConstructor     DontEnum|CellProperty
310   URIError              JSGlobalObject::m_URIErrorConstructor        DontEnum|CellProperty
311   Proxy                 createProxyProperty                          DontEnum|PropertyCallback
312   JSON                  createJSONProperty                           DontEnum|PropertyCallback
313   Math                  createMathProperty                           DontEnum|PropertyCallback
314   console               createConsoleProperty                        DontEnum|PropertyCallback
315   Int8Array             JSGlobalObject::m_typedArrayInt8             DontEnum|ClassStructure
316   Int16Array            JSGlobalObject::m_typedArrayInt16            DontEnum|ClassStructure
317   Int32Array            JSGlobalObject::m_typedArrayInt32            DontEnum|ClassStructure
318   Uint8Array            JSGlobalObject::m_typedArrayUint8            DontEnum|ClassStructure
319   Uint8ClampedArray     JSGlobalObject::m_typedArrayUint8Clamped     DontEnum|ClassStructure
320   Uint16Array           JSGlobalObject::m_typedArrayUint16           DontEnum|ClassStructure
321   Uint32Array           JSGlobalObject::m_typedArrayUint32           DontEnum|ClassStructure
322   Float32Array          JSGlobalObject::m_typedArrayFloat32          DontEnum|ClassStructure
323   Float64Array          JSGlobalObject::m_typedArrayFloat64          DontEnum|ClassStructure
324   DataView              JSGlobalObject::m_typedArrayDataView         DontEnum|ClassStructure
325   Date                  JSGlobalObject::m_dateStructure              DontEnum|ClassStructure
326   Boolean               JSGlobalObject::m_booleanObjectStructure     DontEnum|ClassStructure
327   Number                JSGlobalObject::m_numberObjectStructure      DontEnum|ClassStructure
328   WeakMap               JSGlobalObject::m_weakMapStructure           DontEnum|ClassStructure
329   WeakSet               JSGlobalObject::m_weakSetStructure           DontEnum|ClassStructure
330 @end
331 */
332
333 static EncodedJSValue JSC_HOST_CALL enqueueJob(ExecState* exec)
334 {
335     VM& vm = exec->vm();
336     JSGlobalObject* globalObject = exec->lexicalGlobalObject();
337
338     JSValue job = exec->argument(0);
339     JSValue arguments = exec->argument(1);
340     ASSERT(arguments.inherits<JSArray>(vm));
341
342     globalObject->queueMicrotask(createJSMicrotask(vm, job, jsCast<JSArray*>(arguments)));
343
344     return JSValue::encode(jsUndefined());
345 }
346
347 JSGlobalObject::JSGlobalObject(VM& vm, Structure* structure, const GlobalObjectMethodTable* globalObjectMethodTable)
348     : Base(vm, structure, 0)
349     , m_vm(vm)
350     , m_masqueradesAsUndefinedWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
351     , m_havingABadTimeWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
352     , m_varInjectionWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
353     , m_weakRandom(Options::forceWeakRandomSeed() ? Options::forcedWeakRandomSeed() : static_cast<unsigned>(randomNumber() * (std::numeric_limits<unsigned>::max() + 1.0)))
354     , m_arrayIteratorProtocolWatchpoint(IsWatched)
355     , m_mapIteratorProtocolWatchpoint(IsWatched)
356     , m_setIteratorProtocolWatchpoint(IsWatched)
357     , m_stringIteratorProtocolWatchpoint(IsWatched)
358     , m_mapSetWatchpoint(IsWatched)
359     , m_setAddWatchpoint(IsWatched)
360     , m_arraySpeciesWatchpoint(ClearWatchpoint)
361     , m_numberToStringWatchpoint(IsWatched)
362     , m_runtimeFlags()
363     , m_globalObjectMethodTable(globalObjectMethodTable ? globalObjectMethodTable : &s_globalObjectMethodTable)
364 {
365 }
366
367 JSGlobalObject::~JSGlobalObject()
368 {
369 #if ENABLE(REMOTE_INSPECTOR)
370     m_inspectorController->globalObjectDestroyed();
371 #endif
372
373     if (m_debugger)
374         m_debugger->detach(this, Debugger::GlobalObjectIsDestructing);
375 }
376
377 void JSGlobalObject::destroy(JSCell* cell)
378 {
379     static_cast<JSGlobalObject*>(cell)->JSGlobalObject::~JSGlobalObject();
380 }
381
382 void JSGlobalObject::setGlobalThis(VM& vm, JSObject* globalThis)
383 {
384     m_globalThis.set(vm, this, globalThis);
385 }
386
387 static JSObject* getGetterById(ExecState* exec, JSObject* base, const Identifier& ident)
388 {
389     JSValue baseValue = JSValue(base);
390     PropertySlot slot(baseValue, PropertySlot::InternalMethodType::VMInquiry);
391     baseValue.getPropertySlot(exec, ident, slot);
392     return slot.getPureResult().toObject(exec);
393 }
394
395 void JSGlobalObject::init(VM& vm)
396 {
397     ASSERT(vm.currentThreadIsHoldingAPILock());
398     auto catchScope = DECLARE_CATCH_SCOPE(vm);
399
400     Base::setStructure(vm, Structure::toCacheableDictionaryTransition(vm, structure(vm)));
401
402     m_debugger = 0;
403
404 #if ENABLE(REMOTE_INSPECTOR)
405     m_inspectorController = std::make_unique<Inspector::JSGlobalObjectInspectorController>(*this);
406     m_inspectorDebuggable = std::make_unique<JSGlobalObjectDebuggable>(*this);
407     m_inspectorDebuggable->init();
408     m_consoleClient = m_inspectorController->consoleClient();
409 #endif
410
411     m_functionPrototype.set(vm, this, FunctionPrototype::create(vm, FunctionPrototype::createStructure(vm, this, jsNull()))); // The real prototype will be set once ObjectPrototype is created.
412     m_calleeStructure.set(vm, this, JSCallee::createStructure(vm, this, jsNull()));
413
414     m_globalLexicalEnvironment.set(vm, this, JSGlobalLexicalEnvironment::create(vm, JSGlobalLexicalEnvironment::createStructure(vm, this), this));
415     // Need to create the callee structure (above) before creating the callee.
416     JSCallee* globalCallee = JSCallee::create(vm, this, globalScope());
417     m_globalCallee.set(vm, this, globalCallee);
418
419     ExecState::initGlobalExec(JSGlobalObject::globalExec(), globalCallee);
420     ExecState* exec = JSGlobalObject::globalExec();
421
422     JSCallee* stackOverflowFrameCallee = JSCallee::create(vm, this, globalScope());
423     m_stackOverflowFrameCallee.set(vm, this, stackOverflowFrameCallee);
424
425     m_hostFunctionStructure.set(vm, this, JSFunction::createStructure(vm, this, m_functionPrototype.get()));
426
427     auto initFunctionStructures = [&] (FunctionStructures& structures) {
428         structures.strictFunctionStructure.set(vm, this, JSFunction::createStructure(vm, this, m_functionPrototype.get()));
429         structures.sloppyFunctionStructure.set(vm, this, JSFunction::createStructure(vm, this, m_functionPrototype.get()));
430         structures.arrowFunctionStructure.set(vm, this, JSFunction::createStructure(vm, this, m_functionPrototype.get()));
431     };
432     initFunctionStructures(m_builtinFunctions);
433     initFunctionStructures(m_ordinaryFunctions);
434
435     m_customGetterSetterFunctionStructure.initLater(
436         [] (const Initializer<Structure>& init) {
437             init.set(JSCustomGetterSetterFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
438         });
439     m_boundFunctionStructure.initLater(
440         [] (const Initializer<Structure>& init) {
441             init.set(JSBoundFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
442         });
443     m_getterSetterStructure.set(vm, this, GetterSetter::createStructure(vm, this, jsNull()));
444     m_nativeStdFunctionStructure.initLater(
445         [] (const Initializer<Structure>& init) {
446             init.set(JSNativeStdFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
447         });
448     JSFunction* callFunction = nullptr;
449     JSFunction* applyFunction = nullptr;
450     JSFunction* hasInstanceSymbolFunction = nullptr;
451     m_functionPrototype->addFunctionProperties(exec, this, &callFunction, &applyFunction, &hasInstanceSymbolFunction);
452     m_callFunction.set(vm, this, callFunction);
453     m_applyFunction.set(vm, this, applyFunction);
454     m_arrayProtoToStringFunction.initLater(
455         [] (const Initializer<JSFunction>& init) {
456             init.set(JSFunction::create(init.vm, init.owner, 0, init.vm.propertyNames->toString.string(), arrayProtoFuncToString, NoIntrinsic));
457         });
458     m_arrayProtoValuesFunction.initLater(
459         [] (const Initializer<JSFunction>& init) {
460             init.set(JSFunction::create(init.vm, arrayPrototypeValuesCodeGenerator(init.vm), init.owner));
461         });
462     m_initializePromiseFunction.initLater(
463         [] (const Initializer<JSFunction>& init) {
464             init.set(JSFunction::create(init.vm, promiseOperationsInitializePromiseCodeGenerator(init.vm), init.owner));
465         });
466
467     m_iteratorProtocolFunction.initLater(
468         [] (const Initializer<JSFunction>& init) {
469             init.set(JSFunction::create(init.vm, iteratorHelpersPerformIterationCodeGenerator(init.vm), init.owner));
470         });
471
472     m_promiseResolveFunction.initLater(
473         [] (const Initializer<JSFunction>& init) {
474             init.set(JSFunction::create(init.vm, promiseConstructorResolveCodeGenerator(init.vm), init.owner));
475         });
476
477     m_newPromiseCapabilityFunction.set(vm, this, JSFunction::create(vm, promiseOperationsNewPromiseCapabilityCodeGenerator(vm), this));
478     m_functionProtoHasInstanceSymbolFunction.set(vm, this, hasInstanceSymbolFunction);
479     m_throwTypeErrorGetterSetter.initLater(
480         [] (const Initializer<GetterSetter>& init) {
481             JSFunction* thrower = init.owner->throwTypeErrorFunction();
482             GetterSetter* getterSetter = GetterSetter::create(init.vm, init.owner, thrower, thrower);
483             init.set(getterSetter);
484         });
485
486     m_nullGetterFunction.set(vm, this, NullGetterFunction::create(vm, NullGetterFunction::createStructure(vm, this, m_functionPrototype.get())));
487     m_nullSetterFunction.set(vm, this, NullSetterFunction::create(vm, NullSetterFunction::createStructure(vm, this, m_functionPrototype.get())));
488     m_objectPrototype.set(vm, this, ObjectPrototype::create(vm, this, ObjectPrototype::createStructure(vm, this, jsNull())));
489     GetterSetter* protoAccessor = GetterSetter::create(vm, this,
490         JSFunction::create(vm, this, 0, makeString("get ", vm.propertyNames->underscoreProto.string()), globalFuncProtoGetter, UnderscoreProtoIntrinsic),
491         JSFunction::create(vm, this, 0, makeString("set ", vm.propertyNames->underscoreProto.string()), globalFuncProtoSetter));
492     m_objectPrototype->putDirectNonIndexAccessor(vm, vm.propertyNames->underscoreProto, protoAccessor, PropertyAttribute::Accessor | PropertyAttribute::DontEnum);
493     m_functionPrototype->structure(vm)->setPrototypeWithoutTransition(vm, m_objectPrototype.get());
494     m_objectStructureForObjectConstructor.set(vm, this, vm.structureCache.emptyObjectStructureForPrototype(this, m_objectPrototype.get(), JSFinalObject::defaultInlineCapacity()));
495     m_objectProtoValueOfFunction.set(vm, this, jsCast<JSFunction*>(objectPrototype()->getDirect(vm, vm.propertyNames->valueOf)));
496     
497     JSFunction* thrower = JSFunction::create(vm, this, 0, String(), globalFuncThrowTypeErrorArgumentsCalleeAndCaller);
498     GetterSetter* getterSetter = GetterSetter::create(vm, this, thrower, thrower);
499     m_throwTypeErrorArgumentsCalleeAndCallerGetterSetter.set(vm, this, getterSetter);
500     
501     m_functionPrototype->initRestrictedProperties(exec, this);
502
503     m_speciesGetterSetter.set(vm, this, GetterSetter::create(vm, this, JSFunction::create(vm, globalOperationsSpeciesGetterCodeGenerator(vm), this), nullptr));
504
505     m_typedArrayProto.initLater(
506         [] (const Initializer<JSTypedArrayViewPrototype>& init) {
507             init.set(JSTypedArrayViewPrototype::create(init.vm, init.owner, JSTypedArrayViewPrototype::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get())));
508             
509             // Make sure that the constructor gets initialized, too.
510             init.owner->m_typedArraySuperConstructor.get(init.owner);
511         });
512     m_typedArraySuperConstructor.initLater(
513         [] (const Initializer<JSTypedArrayViewConstructor>& init) {
514             JSTypedArrayViewPrototype* prototype = init.owner->m_typedArrayProto.get(init.owner);
515             JSTypedArrayViewConstructor* constructor = JSTypedArrayViewConstructor::create(init.vm, init.owner, JSTypedArrayViewConstructor::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()), prototype, init.owner->m_speciesGetterSetter.get());
516             prototype->putDirectWithoutTransition(init.vm, init.vm.propertyNames->constructor, constructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
517             init.set(constructor);
518         });
519     
520 #define INIT_TYPED_ARRAY_LATER(type) \
521     m_typedArray ## type.initLater( \
522         [] (LazyClassStructure::Initializer& init) { \
523             init.setPrototype(JS ## type ## ArrayPrototype::create(init.vm, init.global, JS ## type ## ArrayPrototype::createStructure(init.vm, init.global, init.global->m_typedArrayProto.get(init.global)))); \
524             init.setStructure(JS ## type ## Array::createStructure(init.vm, init.global, init.prototype)); \
525             init.setConstructor(JS ## type ## ArrayConstructor::create(init.vm, init.global, JS ## type ## ArrayConstructor::createStructure(init.vm, init.global, init.global->m_typedArraySuperConstructor.get(init.global)), init.prototype, #type "Array"_s, typedArrayConstructorAllocate ## type ## ArrayCodeGenerator(init.vm))); \
526             init.global->putDirectWithoutTransition(init.vm, init.vm.propertyNames->builtinNames().type ## ArrayPrivateName(), init.constructor, static_cast<unsigned>(PropertyAttribute::DontEnum)); \
527         });
528     FOR_EACH_TYPED_ARRAY_TYPE_EXCLUDING_DATA_VIEW(INIT_TYPED_ARRAY_LATER)
529 #undef INIT_TYPED_ARRAY_LATER
530     
531     m_typedArrayDataView.initLater(
532         [] (LazyClassStructure::Initializer& init) {
533             init.setPrototype(JSDataViewPrototype::create(init.vm, JSDataViewPrototype::createStructure(init.vm, init.global, init.global->m_objectPrototype.get())));
534             init.setStructure(JSDataView::createStructure(init.vm, init.global, init.prototype));
535             init.setConstructor(JSDataViewConstructor::create(init.vm, init.global, JSDataViewConstructor::createStructure(init.vm, init.global, init.global->m_functionPrototype.get()), init.prototype, "DataView"_s, nullptr));
536         });
537     
538     m_lexicalEnvironmentStructure.set(vm, this, JSLexicalEnvironment::createStructure(vm, this));
539     m_moduleEnvironmentStructure.initLater(
540         [] (const Initializer<Structure>& init) {
541             init.set(JSModuleEnvironment::createStructure(init.vm, init.owner));
542         });
543     m_strictEvalActivationStructure.set(vm, this, StrictEvalActivation::createStructure(vm, this, jsNull()));
544     m_debuggerScopeStructure.initLater(
545         [] (const Initializer<Structure>& init) {
546             init.set(DebuggerScope::createStructure(init.vm, init.owner));
547         });
548     m_withScopeStructure.initLater(
549         [] (const Initializer<Structure>& init) {
550             init.set(JSWithScope::createStructure(init.vm, init.owner, jsNull()));
551         });
552     
553     m_nullPrototypeObjectStructure.set(vm, this, JSFinalObject::createStructure(vm, this, jsNull(), JSFinalObject::defaultInlineCapacity()));
554     
555     m_callbackFunctionStructure.initLater(
556         [] (const Initializer<Structure>& init) {
557             init.set(JSCallbackFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
558         });
559     m_directArgumentsStructure.set(vm, this, DirectArguments::createStructure(vm, this, m_objectPrototype.get()));
560     m_scopedArgumentsStructure.set(vm, this, ScopedArguments::createStructure(vm, this, m_objectPrototype.get()));
561     m_clonedArgumentsStructure.set(vm, this, ClonedArguments::createStructure(vm, this, m_objectPrototype.get()));
562     m_callbackConstructorStructure.initLater(
563         [] (const Initializer<Structure>& init) {
564             init.set(JSCallbackConstructor::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
565         });
566     m_callbackObjectStructure.initLater(
567         [] (const Initializer<Structure>& init) {
568             init.set(JSCallbackObject<JSDestructibleObject>::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
569         });
570
571 #if JSC_OBJC_API_ENABLED
572     m_objcCallbackFunctionStructure.initLater(
573         [] (const Initializer<Structure>& init) {
574             init.set(ObjCCallbackFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
575         });
576     m_objcWrapperObjectStructure.initLater(
577         [] (const Initializer<Structure>& init) {
578             init.set(JSCallbackObject<JSAPIWrapperObject>::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
579         });
580 #endif
581 #ifdef JSC_GLIB_API_ENABLED
582     m_glibCallbackFunctionStructure.initLater(
583         [] (const Initializer<Structure>& init) {
584             init.set(JSCCallbackFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
585         });
586     m_glibWrapperObjectStructure.initLater(
587         [] (const Initializer<Structure>& init) {
588             init.set(JSCallbackObject<JSAPIWrapperObject>::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
589         });
590 #endif
591     m_arrayPrototype.set(vm, this, ArrayPrototype::create(vm, this, ArrayPrototype::createStructure(vm, this, m_objectPrototype.get())));
592     
593     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(UndecidedShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithUndecided));
594     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(Int32Shape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithInt32));
595     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(DoubleShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithDouble));
596     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(ContiguousShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithContiguous));
597     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(ArrayStorageShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithArrayStorage));
598     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(SlowPutArrayStorageShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithSlowPutArrayStorage));
599     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(CopyOnWriteArrayWithInt32)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), CopyOnWriteArrayWithInt32));
600     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(CopyOnWriteArrayWithDouble)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), CopyOnWriteArrayWithDouble));
601     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(CopyOnWriteArrayWithContiguous)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), CopyOnWriteArrayWithContiguous));
602     for (unsigned i = 0; i < NumberOfArrayIndexingModes; ++i)
603         m_arrayStructureForIndexingShapeDuringAllocation[i] = m_originalArrayStructureForIndexingShape[i];
604
605     m_regExpPrototype.set(vm, this, RegExpPrototype::create(vm, this, RegExpPrototype::createStructure(vm, this, m_objectPrototype.get())));
606     m_regExpStructure.set(vm, this, RegExpObject::createStructure(vm, this, m_regExpPrototype.get()));
607     m_regExpMatchesArrayStructure.set(vm, this, createRegExpMatchesArrayStructure(vm, this));
608     m_regExpMatchesArrayWithGroupsStructure.set(vm, this, createRegExpMatchesArrayWithGroupsStructure(vm, this));
609
610     m_moduleRecordStructure.set(vm, this, JSModuleRecord::createStructure(vm, this, jsNull()));
611     m_moduleNamespaceObjectStructure.set(vm, this, JSModuleNamespaceObject::createStructure(vm, this, jsNull()));
612     {
613         bool isCallable = false;
614         m_proxyObjectStructure.set(vm, this, ProxyObject::createStructure(vm, this, jsNull(), isCallable));
615         isCallable = true;
616         m_callableProxyObjectStructure.set(vm, this, ProxyObject::createStructure(vm, this, jsNull(), isCallable));
617     }
618     m_proxyRevokeStructure.set(vm, this, ProxyRevoke::createStructure(vm, this, m_functionPrototype.get()));
619
620     m_parseIntFunction.set(vm, this, JSFunction::create(vm, this, 2, vm.propertyNames->parseInt.string(), globalFuncParseInt, ParseIntIntrinsic));
621     putDirectWithoutTransition(vm, vm.propertyNames->parseInt, m_parseIntFunction.get(), static_cast<unsigned>(PropertyAttribute::DontEnum));
622     m_parseFloatFunction.set(vm, this, JSFunction::create(vm, this, 1, vm.propertyNames->parseFloat.string(), globalFuncParseFloat, NoIntrinsic));
623     putDirectWithoutTransition(vm, vm.propertyNames->parseFloat, m_parseFloatFunction.get(), static_cast<unsigned>(PropertyAttribute::DontEnum));
624     
625     m_arrayBufferPrototype.set(vm, this, JSArrayBufferPrototype::create(vm, this, JSArrayBufferPrototype::createStructure(vm, this, m_objectPrototype.get()), ArrayBufferSharingMode::Default));
626     m_arrayBufferStructure.set(vm, this, JSArrayBuffer::createStructure(vm, this, m_arrayBufferPrototype.get()));
627 #if ENABLE(SHARED_ARRAY_BUFFER)
628     m_sharedArrayBufferPrototype.set(vm, this, JSArrayBufferPrototype::create(vm, this, JSArrayBufferPrototype::createStructure(vm, this, m_objectPrototype.get()), ArrayBufferSharingMode::Shared));
629     m_sharedArrayBufferStructure.set(vm, this, JSArrayBuffer::createStructure(vm, this, m_sharedArrayBufferPrototype.get()));
630 #endif
631
632     m_iteratorPrototype.set(vm, this, IteratorPrototype::create(vm, this, IteratorPrototype::createStructure(vm, this, m_objectPrototype.get())));
633     m_asyncIteratorPrototype.set(vm, this, AsyncIteratorPrototype::create(vm, this, AsyncIteratorPrototype::createStructure(vm, this, m_objectPrototype.get())));
634
635     m_generatorPrototype.set(vm, this, GeneratorPrototype::create(vm, this, GeneratorPrototype::createStructure(vm, this, m_iteratorPrototype.get())));
636     m_asyncGeneratorPrototype.set(vm, this, AsyncGeneratorPrototype::create(vm, this, AsyncGeneratorPrototype::createStructure(vm, this, m_asyncIteratorPrototype.get())));
637
638 #define CREATE_PROTOTYPE_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) do { \
639         m_ ## lowerName ## Prototype.set(vm, this, capitalName##Prototype::create(vm, this, capitalName##Prototype::createStructure(vm, this, m_ ## prototypeBase ## Prototype.get()))); \
640         m_ ## properName ## Structure.set(vm, this, instanceType::createStructure(vm, this, m_ ## lowerName ## Prototype.get())); \
641     } while (0);
642     
643     FOR_EACH_SIMPLE_BUILTIN_TYPE(CREATE_PROTOTYPE_FOR_SIMPLE_TYPE)
644
645     if (UNLIKELY(Options::useBigInt()))
646         FOR_BIG_INT_BUILTIN_TYPE_WITH_CONSTRUCTOR(CREATE_PROTOTYPE_FOR_SIMPLE_TYPE)
647
648     FOR_EACH_BUILTIN_DERIVED_ITERATOR_TYPE(CREATE_PROTOTYPE_FOR_SIMPLE_TYPE)
649     
650 #undef CREATE_PROTOTYPE_FOR_SIMPLE_TYPE
651
652 #define CREATE_PROTOTYPE_FOR_LAZY_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
653     m_ ## properName ## Structure.initLater(\
654         [] (LazyClassStructure::Initializer& init) { \
655             init.setPrototype(capitalName##Prototype::create(init.vm, init.global, capitalName##Prototype::createStructure(init.vm, init.global, init.global->m_ ## prototypeBase ## Prototype.get()))); \
656             init.setStructure(instanceType::createStructure(init.vm, init.global, init.prototype)); \
657             init.setConstructor(capitalName ## Constructor::create(init.vm, capitalName ## Constructor::createStructure(init.vm, init.global, init.global->m_functionPrototype.get()), jsCast<capitalName ## Prototype*>(init.prototype), init.global->m_speciesGetterSetter.get())); \
658         });
659     
660     FOR_EACH_LAZY_BUILTIN_TYPE(CREATE_PROTOTYPE_FOR_LAZY_TYPE)
661     
662 #undef CREATE_PROTOTYPE_FOR_LAZY_TYPE
663     
664     // Constructors
665
666     ObjectConstructor* objectConstructor = ObjectConstructor::create(vm, this, ObjectConstructor::createStructure(vm, this, m_functionPrototype.get()), m_objectPrototype.get());
667     m_objectConstructor.set(vm, this, objectConstructor);
668
669     JSFunction* throwTypeErrorFunction = JSFunction::create(vm, this, 0, String(), globalFuncThrowTypeError);
670     m_throwTypeErrorFunction.set(vm, this, throwTypeErrorFunction);
671
672     JSCell* functionConstructor = FunctionConstructor::create(vm, FunctionConstructor::createStructure(vm, this, m_functionPrototype.get()), m_functionPrototype.get());
673
674     ArrayConstructor* arrayConstructor = ArrayConstructor::create(vm, this, ArrayConstructor::createStructure(vm, this, m_functionPrototype.get()), m_arrayPrototype.get(), m_speciesGetterSetter.get());
675     m_arrayConstructor.set(vm, this, arrayConstructor);
676     
677     m_regExpConstructor.set(vm, this, RegExpConstructor::create(vm, RegExpConstructor::createStructure(vm, this, m_functionPrototype.get()), m_regExpPrototype.get(), m_speciesGetterSetter.get()));
678     
679     JSArrayBufferConstructor* arrayBufferConstructor = JSArrayBufferConstructor::create(vm, JSArrayBufferConstructor::createStructure(vm, this, m_functionPrototype.get()), m_arrayBufferPrototype.get(), m_speciesGetterSetter.get(), ArrayBufferSharingMode::Default);
680     m_arrayBufferPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, arrayBufferConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
681
682 #if ENABLE(SHARED_ARRAY_BUFFER)
683     JSArrayBufferConstructor* sharedArrayBufferConstructor = nullptr;
684     sharedArrayBufferConstructor = JSArrayBufferConstructor::create(vm, JSArrayBufferConstructor::createStructure(vm, this, m_functionPrototype.get()), m_sharedArrayBufferPrototype.get(), m_speciesGetterSetter.get(), ArrayBufferSharingMode::Shared);
685     m_sharedArrayBufferPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, sharedArrayBufferConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
686
687     AtomicsObject* atomicsObject = AtomicsObject::create(vm, this, AtomicsObject::createStructure(vm, this, m_objectPrototype.get()));
688 #endif
689
690 #define CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
691 capitalName ## Constructor* lowerName ## Constructor = capitalName ## Constructor::create(vm, capitalName ## Constructor::createStructure(vm, this, m_functionPrototype.get()), m_ ## lowerName ## Prototype.get(), m_speciesGetterSetter.get()); \
692 m_ ## lowerName ## Prototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, lowerName ## Constructor, static_cast<unsigned>(PropertyAttribute::DontEnum)); \
693
694     FOR_EACH_SIMPLE_BUILTIN_TYPE(CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE)
695     BigIntConstructor* bigIntConstructor = nullptr;
696     if (UNLIKELY(Options::useBigInt())) {
697         bigIntConstructor = BigIntConstructor::create(vm, BigIntConstructor::createStructure(vm, this, m_functionPrototype.get()), m_bigIntPrototype.get(), m_speciesGetterSetter.get());
698         m_bigIntPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, bigIntConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
699     }
700     
701 #undef CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE
702
703     m_errorConstructor.set(vm, this, errorConstructor);
704     m_promiseConstructor.set(vm, this, promiseConstructor);
705     m_internalPromiseConstructor.set(vm, this, internalPromiseConstructor);
706     
707     m_nativeErrorPrototypeStructure.set(vm, this, NativeErrorPrototype::createStructure(vm, this, m_errorPrototype.get()));
708     m_nativeErrorStructure.set(vm, this, NativeErrorConstructor::createStructure(vm, this, errorConstructor));
709     m_evalErrorConstructor.initLater(
710         [] (const Initializer<NativeErrorConstructor>& init) {
711             init.set(NativeErrorConstructor::create(init.vm, init.owner, init.owner->m_nativeErrorStructure.get(), init.owner->m_nativeErrorPrototypeStructure.get(), "EvalError"_s));
712         });
713     m_rangeErrorConstructor.set(vm, this, NativeErrorConstructor::create(vm, this, m_nativeErrorStructure.get(), m_nativeErrorPrototypeStructure.get(), "RangeError"_s));
714     m_referenceErrorConstructor.initLater(
715         [] (const Initializer<NativeErrorConstructor>& init) {
716             init.set(NativeErrorConstructor::create(init.vm, init.owner, init.owner->m_nativeErrorStructure.get(), init.owner->m_nativeErrorPrototypeStructure.get(), "ReferenceError"_s));
717         });
718     m_syntaxErrorConstructor.initLater(
719         [] (const Initializer<NativeErrorConstructor>& init) {
720             init.set(NativeErrorConstructor::create(init.vm, init.owner, init.owner->m_nativeErrorStructure.get(), init.owner->m_nativeErrorPrototypeStructure.get(), "SyntaxError"_s));
721         });
722     m_typeErrorConstructor.set(vm, this, NativeErrorConstructor::create(vm, this, m_nativeErrorStructure.get(), m_nativeErrorPrototypeStructure.get(), "TypeError"_s));
723     m_URIErrorConstructor.initLater(
724         [] (const Initializer<NativeErrorConstructor>& init) {
725             init.set(NativeErrorConstructor::create(init.vm, init.owner, init.owner->m_nativeErrorStructure.get(), init.owner->m_nativeErrorPrototypeStructure.get(), "URIError"_s));
726         });
727
728     m_generatorFunctionPrototype.set(vm, this, GeneratorFunctionPrototype::create(vm, GeneratorFunctionPrototype::createStructure(vm, this, m_functionPrototype.get())));
729     GeneratorFunctionConstructor* generatorFunctionConstructor = GeneratorFunctionConstructor::create(vm, GeneratorFunctionConstructor::createStructure(vm, this, functionConstructor), m_generatorFunctionPrototype.get());
730     m_generatorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, generatorFunctionConstructor, PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
731     m_generatorFunctionStructure.set(vm, this, JSGeneratorFunction::createStructure(vm, this, m_generatorFunctionPrototype.get()));
732
733     m_generatorPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_generatorFunctionPrototype.get(), PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
734     m_generatorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->prototype, m_generatorPrototype.get(), PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
735
736     m_asyncFunctionPrototype.set(vm, this, AsyncFunctionPrototype::create(vm, AsyncFunctionPrototype::createStructure(vm, this, m_functionPrototype.get())));
737     AsyncFunctionConstructor* asyncFunctionConstructor = AsyncFunctionConstructor::create(vm, AsyncFunctionConstructor::createStructure(vm, this, functionConstructor), m_asyncFunctionPrototype.get());
738     m_asyncFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, asyncFunctionConstructor, PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
739     m_asyncFunctionStructure.set(vm, this, JSAsyncFunction::createStructure(vm, this, m_asyncFunctionPrototype.get()));
740
741     m_asyncGeneratorFunctionPrototype.set(vm, this, AsyncGeneratorFunctionPrototype::create(vm, AsyncGeneratorFunctionPrototype::createStructure(vm, this, m_functionPrototype.get())));
742     AsyncGeneratorFunctionConstructor* asyncGeneratorFunctionConstructor = AsyncGeneratorFunctionConstructor::create(vm, AsyncGeneratorFunctionConstructor::createStructure(vm, this, functionConstructor), m_asyncGeneratorFunctionPrototype.get());
743     m_asyncGeneratorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, asyncGeneratorFunctionConstructor, PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
744     m_asyncGeneratorFunctionStructure.set(vm, this, JSAsyncGeneratorFunction::createStructure(vm, this, m_asyncGeneratorFunctionPrototype.get()));
745
746     m_asyncGeneratorPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_asyncGeneratorFunctionPrototype.get(), PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
747     m_asyncGeneratorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->prototype, m_asyncGeneratorPrototype.get(), PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
748     
749     
750     m_objectPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, objectConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
751     m_functionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, functionConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
752     m_arrayPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, arrayConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
753     m_regExpPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_regExpConstructor.get(), static_cast<unsigned>(PropertyAttribute::DontEnum));
754     
755     putDirectWithoutTransition(vm, vm.propertyNames->Object, objectConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
756     putDirectWithoutTransition(vm, vm.propertyNames->Function, functionConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
757     putDirectWithoutTransition(vm, vm.propertyNames->Array, arrayConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
758     putDirectWithoutTransition(vm, vm.propertyNames->RegExp, m_regExpConstructor.get(), static_cast<unsigned>(PropertyAttribute::DontEnum));
759     putDirectWithoutTransition(vm, vm.propertyNames->RangeError, m_rangeErrorConstructor.get(), static_cast<unsigned>(PropertyAttribute::DontEnum));
760     putDirectWithoutTransition(vm, vm.propertyNames->TypeError, m_typeErrorConstructor.get(), static_cast<unsigned>(PropertyAttribute::DontEnum));
761
762     putDirectWithoutTransition(vm, vm.propertyNames->builtinNames().ObjectPrivateName(), objectConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly);
763     putDirectWithoutTransition(vm, vm.propertyNames->builtinNames().ArrayPrivateName(), arrayConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly);
764
765     putDirectWithoutTransition(vm, vm.propertyNames->ArrayBuffer, arrayBufferConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
766 #if ENABLE(SHARED_ARRAY_BUFFER)
767     putDirectWithoutTransition(vm, vm.propertyNames->SharedArrayBuffer, sharedArrayBufferConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
768     putDirectWithoutTransition(vm, Identifier::fromString(exec, "Atomics"), atomicsObject, static_cast<unsigned>(PropertyAttribute::DontEnum));
769 #endif
770
771 #define PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
772 putDirectWithoutTransition(vm, vm.propertyNames-> jsName, lowerName ## Constructor, static_cast<unsigned>(PropertyAttribute::DontEnum)); \
773
774     FOR_EACH_SIMPLE_BUILTIN_TYPE_WITH_CONSTRUCTOR(PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE)
775     if (UNLIKELY(Options::useBigInt()))
776         FOR_BIG_INT_BUILTIN_TYPE_WITH_CONSTRUCTOR(PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE)
777
778 #undef PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE
779     m_iteratorResultObjectStructure.set(vm, this, createIteratorResultObjectStructure(vm, *this));
780     
781     m_evalFunction.set(vm, this, JSFunction::create(vm, this, 1, vm.propertyNames->eval.string(), globalFuncEval));
782     putDirectWithoutTransition(vm, vm.propertyNames->eval, m_evalFunction.get(), static_cast<unsigned>(PropertyAttribute::DontEnum));
783     
784 #if ENABLE(INTL)
785     IntlObject* intl = IntlObject::create(vm, this, IntlObject::createStructure(vm, this, m_objectPrototype.get()));
786     putDirectWithoutTransition(vm, vm.propertyNames->Intl, intl, static_cast<unsigned>(PropertyAttribute::DontEnum));
787 #endif // ENABLE(INTL)
788     ReflectObject* reflectObject = ReflectObject::create(vm, this, ReflectObject::createStructure(vm, this, m_objectPrototype.get()));
789     putDirectWithoutTransition(vm, vm.propertyNames->Reflect, reflectObject, static_cast<unsigned>(PropertyAttribute::DontEnum));
790
791     m_moduleLoader.initLater(
792         [] (const Initializer<JSModuleLoader>& init) {
793             auto catchScope = DECLARE_CATCH_SCOPE(init.vm);
794             init.set(JSModuleLoader::create(init.owner->globalExec(), init.vm, init.owner, JSModuleLoader::createStructure(init.vm, init.owner, jsNull())));
795             catchScope.releaseAssertNoException();
796         });
797     if (Options::exposeInternalModuleLoader())
798         putDirectWithoutTransition(vm, vm.propertyNames->Loader, moduleLoader(), static_cast<unsigned>(PropertyAttribute::DontEnum));
799
800     JSFunction* builtinLog = JSFunction::create(vm, this, 1, vm.propertyNames->emptyIdentifier.string(), globalFuncBuiltinLog);
801     JSFunction* builtinDescribe = JSFunction::create(vm, this, 1, vm.propertyNames->emptyIdentifier.string(), globalFuncBuiltinDescribe);
802
803     JSFunction* privateFuncAbs = JSFunction::create(vm, this, 0, String(), mathProtoFuncAbs, AbsIntrinsic);
804     JSFunction* privateFuncFloor = JSFunction::create(vm, this, 0, String(), mathProtoFuncFloor, FloorIntrinsic);
805     JSFunction* privateFuncTrunc = JSFunction::create(vm, this, 0, String(), mathProtoFuncTrunc, TruncIntrinsic);
806
807     JSFunction* privateFuncGetOwnPropertyNames = JSFunction::create(vm, this, 0, String(), objectConstructorGetOwnPropertyNames);
808     JSFunction* privateFuncPropertyIsEnumerable = JSFunction::create(vm, this, 0, String(), globalFuncPropertyIsEnumerable);
809     JSFunction* privateFuncImportModule = JSFunction::create(vm, this, 0, String(), globalFuncImportModule);
810     JSFunction* privateFuncTypedArrayLength = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncLength);
811     JSFunction* privateFuncTypedArrayGetOriginalConstructor = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncGetOriginalConstructor);
812     JSFunction* privateFuncTypedArraySort = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncSort);
813     JSFunction* privateFuncIsTypedArrayView = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncIsTypedArrayView, IsTypedArrayViewIntrinsic);
814     JSFunction* privateFuncTypedArraySubarrayCreate = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncSubarrayCreate);
815     JSFunction* privateFuncIsBoundFunction = JSFunction::create(vm, this, 0, String(), isBoundFunction);
816     JSFunction* privateFuncHasInstanceBoundFunction = JSFunction::create(vm, this, 0, String(), hasInstanceBoundFunction);
817     JSFunction* privateFuncInstanceOf = JSFunction::create(vm, this, 0, String(), objectPrivateFuncInstanceOf);
818     JSFunction* privateFuncThisTimeValue = JSFunction::create(vm, this, 0, String(), dateProtoFuncGetTime);
819     JSFunction* privateFuncThisNumberValue = JSFunction::create(vm, this, 0, String(), numberProtoFuncValueOf);
820     JSFunction* privateFuncIsArrayConstructor = JSFunction::create(vm, this, 0, String(), arrayConstructorPrivateFuncIsArrayConstructor);
821     JSFunction* privateFuncIsArraySlow = JSFunction::create(vm, this, 0, String(), arrayConstructorPrivateFuncIsArraySlow);
822     JSFunction* privateFuncConcatMemcpy = JSFunction::create(vm, this, 0, String(), arrayProtoPrivateFuncConcatMemcpy);
823     JSFunction* privateFuncAppendMemcpy = JSFunction::create(vm, this, 0, String(), arrayProtoPrivateFuncAppendMemcpy);
824     JSFunction* privateFuncMapBucketHead = JSFunction::create(vm, this, 0, String(), mapPrivateFuncMapBucketHead, JSMapBucketHeadIntrinsic);
825     JSFunction* privateFuncMapBucketNext = JSFunction::create(vm, this, 0, String(), mapPrivateFuncMapBucketNext, JSMapBucketNextIntrinsic);
826     JSFunction* privateFuncMapBucketKey = JSFunction::create(vm, this, 0, String(), mapPrivateFuncMapBucketKey, JSMapBucketKeyIntrinsic);
827     JSFunction* privateFuncMapBucketValue = JSFunction::create(vm, this, 0, String(), mapPrivateFuncMapBucketValue, JSMapBucketValueIntrinsic);
828     JSFunction* privateFuncSetBucketHead = JSFunction::create(vm, this, 0, String(), setPrivateFuncSetBucketHead, JSSetBucketHeadIntrinsic);
829     JSFunction* privateFuncSetBucketNext = JSFunction::create(vm, this, 0, String(), setPrivateFuncSetBucketNext, JSSetBucketNextIntrinsic);
830     JSFunction* privateFuncSetBucketKey = JSFunction::create(vm, this, 0, String(), setPrivateFuncSetBucketKey, JSSetBucketKeyIntrinsic);
831
832     JSObject* regExpProtoFlagsGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->flags);
833     catchScope.assertNoException();
834     JSObject* regExpProtoGlobalGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->global);
835     catchScope.assertNoException();
836     m_regExpProtoGlobalGetter.set(vm, this, regExpProtoGlobalGetterObject);
837     JSObject* regExpProtoIgnoreCaseGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->ignoreCase);
838     catchScope.assertNoException();
839     JSObject* regExpProtoMultilineGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->multiline);
840     catchScope.assertNoException();
841     JSObject* regExpProtoSourceGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->source);
842     catchScope.assertNoException();
843     JSObject* regExpProtoStickyGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->sticky);
844     catchScope.assertNoException();
845     JSObject* regExpProtoUnicodeGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->unicode);
846     catchScope.assertNoException();
847     m_regExpProtoUnicodeGetter.set(vm, this, regExpProtoUnicodeGetterObject);
848     JSObject* builtinRegExpExec = asObject(m_regExpPrototype->getDirect(vm, vm.propertyNames->exec).asCell());
849     m_regExpProtoExec.set(vm, this, builtinRegExpExec);
850     JSObject* regExpSymbolReplace = asObject(m_regExpPrototype->getDirect(vm, vm.propertyNames->replaceSymbol).asCell());
851     m_regExpProtoSymbolReplace.set(vm, this, regExpSymbolReplace);
852
853 #define CREATE_PRIVATE_GLOBAL_FUNCTION(name, code) JSFunction* name ## PrivateFunction = JSFunction::create(vm, code ## CodeGenerator(vm), this);
854     JSC_FOREACH_BUILTIN_FUNCTION_PRIVATE_GLOBAL_NAME(CREATE_PRIVATE_GLOBAL_FUNCTION)
855 #undef CREATE_PRIVATE_GLOBAL_FUNCTION
856
857     JSObject* arrayIteratorPrototype = ArrayIteratorPrototype::create(vm, this, ArrayIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
858     createArrayIteratorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, arrayIteratorPrototype);
859
860     JSObject* asyncFromSyncIteratorPrototype = AsyncFromSyncIteratorPrototype::create(vm, this, AsyncFromSyncIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
861     AsyncFromSyncIteratorConstructorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, asyncFromSyncIteratorPrototype);
862
863     JSObject* mapIteratorPrototype = MapIteratorPrototype::create(vm, this, MapIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
864     createMapIteratorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, mapIteratorPrototype);
865
866     JSObject* setIteratorPrototype = SetIteratorPrototype::create(vm, this, SetIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
867     createSetIteratorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, setIteratorPrototype);
868
869     GlobalPropertyInfo staticGlobals[] = {
870 #define INIT_PRIVATE_GLOBAL(name, code) GlobalPropertyInfo(vm.propertyNames->builtinNames().name ## PrivateName(), name ## PrivateFunction, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
871         JSC_FOREACH_BUILTIN_FUNCTION_PRIVATE_GLOBAL_NAME(INIT_PRIVATE_GLOBAL)
872 #undef INIT_PRIVATE_GLOBAL
873         GlobalPropertyInfo(vm.propertyNames->NaN, jsNaN(), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
874         GlobalPropertyInfo(vm.propertyNames->Infinity, jsNumber(std::numeric_limits<double>::infinity()), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
875         GlobalPropertyInfo(vm.propertyNames->undefinedKeyword, jsUndefined(), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
876         GlobalPropertyInfo(vm.propertyNames->builtinNames().getOwnPropertyNamesPrivateName(), privateFuncGetOwnPropertyNames, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
877         GlobalPropertyInfo(vm.propertyNames->builtinNames().propertyIsEnumerablePrivateName(), privateFuncPropertyIsEnumerable, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
878         GlobalPropertyInfo(vm.propertyNames->builtinNames().importModulePrivateName(), privateFuncImportModule, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
879         GlobalPropertyInfo(vm.propertyNames->builtinNames().enqueueJobPrivateName(), JSFunction::create(vm, this, 0, String(), enqueueJob), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
880         GlobalPropertyInfo(vm.propertyNames->builtinNames().ErrorPrivateName(), m_errorConstructor.get(), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
881         GlobalPropertyInfo(vm.propertyNames->builtinNames().RangeErrorPrivateName(), m_rangeErrorConstructor.get(), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
882         GlobalPropertyInfo(vm.propertyNames->builtinNames().TypeErrorPrivateName(), m_typeErrorConstructor.get(), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
883         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArrayLengthPrivateName(), privateFuncTypedArrayLength, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
884         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArrayGetOriginalConstructorPrivateName(), privateFuncTypedArrayGetOriginalConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
885         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArraySortPrivateName(), privateFuncTypedArraySort, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
886         GlobalPropertyInfo(vm.propertyNames->builtinNames().isTypedArrayViewPrivateName(), privateFuncIsTypedArrayView, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
887         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArraySubarrayCreatePrivateName(), privateFuncTypedArraySubarrayCreate, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
888         GlobalPropertyInfo(vm.propertyNames->builtinNames().isBoundFunctionPrivateName(), privateFuncIsBoundFunction, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
889         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasInstanceBoundFunctionPrivateName(), privateFuncHasInstanceBoundFunction, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
890         GlobalPropertyInfo(vm.propertyNames->builtinNames().instanceOfPrivateName(), privateFuncInstanceOf, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
891         GlobalPropertyInfo(vm.propertyNames->builtinNames().BuiltinLogPrivateName(), builtinLog, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
892         GlobalPropertyInfo(vm.propertyNames->builtinNames().BuiltinDescribePrivateName(), builtinDescribe, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
893         GlobalPropertyInfo(vm.propertyNames->builtinNames().NumberPrivateName(), numberConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
894         GlobalPropertyInfo(vm.propertyNames->builtinNames().RegExpPrivateName(), m_regExpConstructor.get(), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
895         GlobalPropertyInfo(vm.propertyNames->builtinNames().StringPrivateName(), stringConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
896         GlobalPropertyInfo(vm.propertyNames->builtinNames().absPrivateName(), privateFuncAbs, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
897         GlobalPropertyInfo(vm.propertyNames->builtinNames().floorPrivateName(), privateFuncFloor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
898         GlobalPropertyInfo(vm.propertyNames->builtinNames().truncPrivateName(), privateFuncTrunc, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
899         GlobalPropertyInfo(vm.propertyNames->builtinNames().PromisePrivateName(), promiseConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
900         GlobalPropertyInfo(vm.propertyNames->builtinNames().ReflectPrivateName(), reflectObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
901         GlobalPropertyInfo(vm.propertyNames->builtinNames().InternalPromisePrivateName(), internalPromiseConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
902
903         GlobalPropertyInfo(vm.propertyNames->builtinNames().repeatCharacterPrivateName(), JSFunction::create(vm, this, 2, String(), stringProtoFuncRepeatCharacter), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
904         GlobalPropertyInfo(vm.propertyNames->builtinNames().isArrayPrivateName(), arrayConstructor->getDirect(vm, vm.propertyNames->isArray), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
905         GlobalPropertyInfo(vm.propertyNames->builtinNames().isArraySlowPrivateName(), privateFuncIsArraySlow, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
906         GlobalPropertyInfo(vm.propertyNames->builtinNames().isArrayConstructorPrivateName(), privateFuncIsArrayConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
907         GlobalPropertyInfo(vm.propertyNames->builtinNames().concatMemcpyPrivateName(), privateFuncConcatMemcpy, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
908         GlobalPropertyInfo(vm.propertyNames->builtinNames().appendMemcpyPrivateName(), privateFuncAppendMemcpy, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
909
910         GlobalPropertyInfo(vm.propertyNames->builtinNames().hostPromiseRejectionTrackerPrivateName(), JSFunction::create(vm, this, 2, String(), globalFuncHostPromiseRejectionTracker), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
911         GlobalPropertyInfo(vm.propertyNames->builtinNames().InspectorInstrumentationPrivateName(), InspectorInstrumentationObject::create(vm, this, InspectorInstrumentationObject::createStructure(vm, this, m_objectPrototype.get())), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
912         GlobalPropertyInfo(vm.propertyNames->builtinNames().MapPrivateName(), mapConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
913         GlobalPropertyInfo(vm.propertyNames->builtinNames().SetPrivateName(), setConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
914         GlobalPropertyInfo(vm.propertyNames->builtinNames().thisTimeValuePrivateName(), privateFuncThisTimeValue, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
915         GlobalPropertyInfo(vm.propertyNames->builtinNames().thisNumberValuePrivateName(), privateFuncThisNumberValue, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
916 #if ENABLE(INTL)
917         GlobalPropertyInfo(vm.propertyNames->builtinNames().CollatorPrivateName(), intl->getDirect(vm, vm.propertyNames->Collator), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
918         GlobalPropertyInfo(vm.propertyNames->builtinNames().DateTimeFormatPrivateName(), intl->getDirect(vm, vm.propertyNames->DateTimeFormat), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
919         GlobalPropertyInfo(vm.propertyNames->builtinNames().NumberFormatPrivateName(), intl->getDirect(vm, vm.propertyNames->NumberFormat), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
920         GlobalPropertyInfo(vm.propertyNames->builtinNames().PluralRulesPrivateName(), intl->getDirect(vm, vm.propertyNames->PluralRules), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
921 #endif // ENABLE(INTL)
922
923         GlobalPropertyInfo(vm.propertyNames->builtinNames().isConstructorPrivateName(), JSFunction::create(vm, this, 1, String(), esSpecIsConstructor, NoIntrinsic), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
924
925         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoFlagsGetterPrivateName(), regExpProtoFlagsGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
926         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoGlobalGetterPrivateName(), regExpProtoGlobalGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
927         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoIgnoreCaseGetterPrivateName(), regExpProtoIgnoreCaseGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
928         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoMultilineGetterPrivateName(), regExpProtoMultilineGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
929         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoSourceGetterPrivateName(), regExpProtoSourceGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
930         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoStickyGetterPrivateName(), regExpProtoStickyGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
931         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoUnicodeGetterPrivateName(), regExpProtoUnicodeGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
932
933         // RegExp.prototype helpers.
934         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpBuiltinExecPrivateName(), builtinRegExpExec, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
935         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpCreatePrivateName(), JSFunction::create(vm, this, 2, String(), esSpecRegExpCreate, NoIntrinsic), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
936         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpMatchFastPrivateName(), JSFunction::create(vm, this, 1, String(), regExpProtoFuncMatchFast, RegExpMatchFastIntrinsic), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
937         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpSearchFastPrivateName(), JSFunction::create(vm, this, 1, String(), regExpProtoFuncSearchFast), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
938         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpSplitFastPrivateName(), JSFunction::create(vm, this, 2, String(), regExpProtoFuncSplitFast), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
939         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpPrototypeSymbolReplacePrivateName(), m_regExpPrototype->getDirect(vm, vm.propertyNames->replaceSymbol), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
940         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpTestFastPrivateName(), JSFunction::create(vm, this, 1, String(), regExpProtoFuncTestFast, RegExpTestFastIntrinsic), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
941
942         // String.prototype helpers.
943         GlobalPropertyInfo(vm.propertyNames->builtinNames().stringIncludesInternalPrivateName(), JSFunction::create(vm, this, 1, String(), builtinStringIncludesInternal), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
944         GlobalPropertyInfo(vm.propertyNames->builtinNames().stringSplitFastPrivateName(), JSFunction::create(vm, this, 2, String(), stringProtoFuncSplitFast), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
945         GlobalPropertyInfo(vm.propertyNames->builtinNames().stringSubstrInternalPrivateName(), JSFunction::create(vm, this, 2, String(), builtinStringSubstrInternal), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
946
947         // Function prototype helpers.
948         GlobalPropertyInfo(vm.propertyNames->builtinNames().makeBoundFunctionPrivateName(), JSFunction::create(vm, this, 5, String(), makeBoundFunction), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
949         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasOwnLengthPropertyPrivateName(), JSFunction::create(vm, this, 1, String(), hasOwnLengthProperty), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
950
951         // Map and Set helpers.
952         GlobalPropertyInfo(vm.propertyNames->builtinNames().mapBucketHeadPrivateName(), privateFuncMapBucketHead, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
953         GlobalPropertyInfo(vm.propertyNames->builtinNames().mapBucketNextPrivateName(), privateFuncMapBucketNext, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
954         GlobalPropertyInfo(vm.propertyNames->builtinNames().mapBucketKeyPrivateName(), privateFuncMapBucketKey, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
955         GlobalPropertyInfo(vm.propertyNames->builtinNames().mapBucketValuePrivateName(), privateFuncMapBucketValue, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
956         GlobalPropertyInfo(vm.propertyNames->builtinNames().setBucketHeadPrivateName(), privateFuncSetBucketHead, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
957         GlobalPropertyInfo(vm.propertyNames->builtinNames().setBucketNextPrivateName(), privateFuncSetBucketNext, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
958         GlobalPropertyInfo(vm.propertyNames->builtinNames().setBucketKeyPrivateName(), privateFuncSetBucketKey, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
959 #if ENABLE(WEBASSEMBLY) && ENABLE(WEBASSEMBLY_STREAMING_API)
960         // WebAssembly Streaming API
961         GlobalPropertyInfo(vm.propertyNames->builtinNames().webAssemblyCompileStreamingInternalPrivateName(), JSFunction::create(vm, this, 1, String(), webAssemblyCompileStreamingInternal), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
962         GlobalPropertyInfo(vm.propertyNames->builtinNames().webAssemblyInstantiateStreamingInternalPrivateName(), JSFunction::create(vm, this, 1, String(), webAssemblyInstantiateStreamingInternal), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
963 #endif
964 #if !ASSERT_DISABLED
965         GlobalPropertyInfo(vm.propertyNames->builtinNames().assertPrivateName(), JSFunction::create(vm, this, 1, String(), assertCall), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
966 #endif
967     };
968     addStaticGlobals(staticGlobals, WTF_ARRAY_LENGTH(staticGlobals));
969     
970     m_specialPointers[Special::CallFunction] = m_callFunction.get();
971     m_specialPointers[Special::ApplyFunction] = m_applyFunction.get();
972     m_specialPointers[Special::ObjectConstructor] = objectConstructor;
973     m_specialPointers[Special::ArrayConstructor] = arrayConstructor;
974
975     m_linkTimeConstants[static_cast<unsigned>(LinkTimeConstant::ThrowTypeErrorFunction)] = m_throwTypeErrorFunction.get();
976
977     if (UNLIKELY(Options::useDollarVM()))
978         exposeDollarVM(vm);
979
980 #if ENABLE(WEBASSEMBLY)
981     if (Options::useWebAssembly()) {
982         auto* webAssemblyPrototype = WebAssemblyPrototype::create(vm, this, WebAssemblyPrototype::createStructure(vm, this, m_objectPrototype.get()));
983         m_webAssemblyStructure.set(vm, this, JSWebAssembly::createStructure(vm, this, webAssemblyPrototype));
984         m_webAssemblyModuleRecordStructure.set(vm, this, WebAssemblyModuleRecord::createStructure(vm, this, m_objectPrototype.get()));
985         m_webAssemblyFunctionStructure.set(vm, this, WebAssemblyFunction::createStructure(vm, this, m_functionPrototype.get()));
986         m_webAssemblyWrapperFunctionStructure.set(vm, this, WebAssemblyWrapperFunction::createStructure(vm, this, m_functionPrototype.get()));
987         m_webAssemblyToJSCalleeStructure.set(vm, this, WebAssemblyToJSCallee::createStructure(vm, this, jsNull()));
988         auto* webAssembly = JSWebAssembly::create(vm, this, m_webAssemblyStructure.get());
989         putDirectWithoutTransition(vm, Identifier::fromString(exec, "WebAssembly"), webAssembly, static_cast<unsigned>(PropertyAttribute::DontEnum));
990
991 #define CREATE_WEBASSEMBLY_CONSTRUCTOR(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) do { \
992         typedef capitalName ## Prototype Prototype; \
993         typedef capitalName ## Constructor Constructor; \
994         typedef JS ## capitalName JSObj; \
995         auto* base = m_ ## prototypeBase ## Prototype.get(); \
996         auto* prototype = Prototype::create(vm, this, Prototype::createStructure(vm, this, base)); \
997         auto* structure = JSObj::createStructure(vm, this, prototype); \
998         auto* constructor = Constructor::create(vm, Constructor::createStructure(vm, this, this->functionPrototype()), prototype); \
999         prototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, constructor, static_cast<unsigned>(PropertyAttribute::DontEnum)); \
1000         m_ ## lowerName ## Prototype.set(vm, this, prototype); \
1001         m_ ## properName ## Structure.set(vm, this, structure); \
1002         webAssembly->putDirectWithoutTransition(vm, Identifier::fromString(this->globalExec(), #jsName), constructor, static_cast<unsigned>(PropertyAttribute::DontEnum)); \
1003     } while (0);
1004
1005         FOR_EACH_WEBASSEMBLY_CONSTRUCTOR_TYPE(CREATE_WEBASSEMBLY_CONSTRUCTOR)
1006
1007 #undef CREATE_WEBASSEMBLY_CONSTRUCTOR
1008     }
1009 #endif // ENABLE(WEBASSEMBLY)
1010
1011     {
1012         ExecState* exec = globalExec();
1013
1014         auto setupAdaptiveWatchpoint = [&] (JSObject* base, const Identifier& ident) -> ObjectPropertyCondition {
1015             // Performing these gets should not throw.
1016             PropertySlot slot(base, PropertySlot::InternalMethodType::Get);
1017             bool result = base->getOwnPropertySlot(base, exec, ident, slot);
1018             ASSERT_UNUSED(result, result);
1019             catchScope.assertNoException();
1020             RELEASE_ASSERT(slot.isCacheableValue());
1021             JSValue functionValue = slot.getValue(exec, ident);
1022             catchScope.assertNoException();
1023             ASSERT(jsDynamicCast<JSFunction*>(vm, functionValue));
1024
1025             ObjectPropertyCondition condition = generateConditionForSelfEquivalence(m_vm, nullptr, base, ident.impl());
1026             RELEASE_ASSERT(condition.requiredValue() == functionValue);
1027
1028             bool isWatchable = condition.isWatchable(PropertyCondition::EnsureWatchability);
1029             RELEASE_ASSERT(isWatchable); // We allow this to install the necessary watchpoints.
1030
1031             return condition;
1032         };
1033
1034         {
1035             ObjectPropertyCondition condition = setupAdaptiveWatchpoint(arrayIteratorPrototype, m_vm.propertyNames->next);
1036             m_arrayIteratorPrototypeNext = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(condition, m_arrayIteratorProtocolWatchpoint);
1037             m_arrayIteratorPrototypeNext->install(vm);
1038         }
1039         {
1040             ObjectPropertyCondition condition = setupAdaptiveWatchpoint(this->arrayPrototype(), m_vm.propertyNames->iteratorSymbol);
1041             m_arrayPrototypeSymbolIteratorWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(condition, m_arrayIteratorProtocolWatchpoint);
1042             m_arrayPrototypeSymbolIteratorWatchpoint->install(vm);
1043         }
1044
1045         {
1046             ObjectPropertyCondition condition = setupAdaptiveWatchpoint(mapIteratorPrototype, m_vm.propertyNames->next);
1047             m_mapIteratorPrototypeNextWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(condition, m_mapIteratorProtocolWatchpoint);
1048             m_mapIteratorPrototypeNextWatchpoint->install(vm);
1049         }
1050         {
1051             ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_mapPrototype.get(), m_vm.propertyNames->iteratorSymbol);
1052             m_mapPrototypeSymbolIteratorWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(condition, m_mapIteratorProtocolWatchpoint);
1053             m_mapPrototypeSymbolIteratorWatchpoint->install(vm);
1054         }
1055
1056         {
1057             ObjectPropertyCondition condition = setupAdaptiveWatchpoint(setIteratorPrototype, m_vm.propertyNames->next);
1058             m_setIteratorPrototypeNextWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(condition, m_setIteratorProtocolWatchpoint);
1059             m_setIteratorPrototypeNextWatchpoint->install(vm);
1060         }
1061         {
1062             ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_setPrototype.get(), m_vm.propertyNames->iteratorSymbol);
1063             m_setPrototypeSymbolIteratorWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(condition, m_setIteratorProtocolWatchpoint);
1064             m_setPrototypeSymbolIteratorWatchpoint->install(vm);
1065         }
1066
1067         {
1068             ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_stringIteratorPrototype.get(), m_vm.propertyNames->next);
1069             m_stringIteratorPrototypeNextWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(condition, m_stringIteratorProtocolWatchpoint);
1070             m_stringIteratorPrototypeNextWatchpoint->install(vm);
1071         }
1072         {
1073             ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_stringPrototype.get(), m_vm.propertyNames->iteratorSymbol);
1074             m_stringPrototypeSymbolIteratorWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(condition, m_stringIteratorProtocolWatchpoint);
1075             m_stringPrototypeSymbolIteratorWatchpoint->install(vm);
1076         }
1077
1078         {
1079             ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_mapPrototype.get(), m_vm.propertyNames->set);
1080             m_mapPrototypeSetWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(condition, m_mapSetWatchpoint);
1081             m_mapPrototypeSetWatchpoint->install(vm);
1082         }
1083
1084         {
1085             ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_setPrototype.get(), m_vm.propertyNames->add);
1086             m_setPrototypeAddWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(condition, m_setAddWatchpoint);
1087             m_setPrototypeAddWatchpoint->install(vm);
1088         }
1089
1090         {
1091             ObjectPropertyCondition condition = setupAdaptiveWatchpoint(numberPrototype(), m_vm.propertyNames->toString);
1092             m_numberPrototypeToStringWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(condition, m_numberToStringWatchpoint);
1093             m_numberPrototypeToStringWatchpoint->install(vm);
1094             m_numberProtoToStringFunction.set(vm, this, jsCast<JSFunction*>(numberPrototype()->getDirect(vm, vm.propertyNames->toString)));
1095         }
1096     }
1097
1098     resetPrototype(vm, getPrototypeDirect(vm));
1099 }
1100
1101 bool JSGlobalObject::put(JSCell* cell, ExecState* exec, PropertyName propertyName, JSValue value, PutPropertySlot& slot)
1102 {
1103     VM& vm = exec->vm();
1104     auto scope = DECLARE_THROW_SCOPE(vm);
1105     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(cell);
1106     ASSERT(!Heap::heap(value) || Heap::heap(value) == Heap::heap(thisObject));
1107
1108     if (UNLIKELY(isThisValueAltered(slot, thisObject)))
1109         RELEASE_AND_RETURN(scope, ordinarySetSlow(exec, thisObject, propertyName, value, slot.thisValue(), slot.isStrictMode()));
1110
1111     bool shouldThrowReadOnlyError = slot.isStrictMode();
1112     bool ignoreReadOnlyErrors = false;
1113     bool putResult = false;
1114     bool done = symbolTablePutTouchWatchpointSet(thisObject, exec, propertyName, value, shouldThrowReadOnlyError, ignoreReadOnlyErrors, putResult);
1115     EXCEPTION_ASSERT((!!scope.exception() == (done && !putResult)) || !shouldThrowReadOnlyError);
1116     if (done)
1117         return putResult;
1118     RELEASE_AND_RETURN(scope, Base::put(thisObject, exec, propertyName, value, slot));
1119 }
1120
1121 bool JSGlobalObject::defineOwnProperty(JSObject* object, ExecState* exec, PropertyName propertyName, const PropertyDescriptor& descriptor, bool shouldThrow)
1122 {
1123     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(object);
1124     PropertySlot slot(thisObject, PropertySlot::InternalMethodType::VMInquiry);
1125     // silently ignore attempts to add accessors aliasing vars.
1126     if (descriptor.isAccessorDescriptor() && symbolTableGet(thisObject, propertyName, slot))
1127         return false;
1128     return Base::defineOwnProperty(thisObject, exec, propertyName, descriptor, shouldThrow);
1129 }
1130
1131 void JSGlobalObject::addGlobalVar(const Identifier& ident)
1132 {
1133     ConcurrentJSLocker locker(symbolTable()->m_lock);
1134     SymbolTableEntry entry = symbolTable()->get(locker, ident.impl());
1135     if (!entry.isNull())
1136         return;
1137     
1138     ScopeOffset offset = symbolTable()->takeNextScopeOffset(locker);
1139     SymbolTableEntry newEntry(VarOffset(offset), 0);
1140     newEntry.prepareToWatch();
1141     symbolTable()->add(locker, ident.impl(), WTFMove(newEntry));
1142     
1143     ScopeOffset offsetForAssert = addVariables(1, jsUndefined());
1144     RELEASE_ASSERT(offsetForAssert == offset);
1145 }
1146
1147 void JSGlobalObject::addFunction(ExecState* exec, const Identifier& propertyName)
1148 {
1149     VM& vm = exec->vm();
1150     VM::DeletePropertyModeScope scope(vm, VM::DeletePropertyMode::IgnoreConfigurable);
1151     methodTable(vm)->deleteProperty(this, exec, propertyName);
1152     addGlobalVar(propertyName);
1153 }
1154
1155 void JSGlobalObject::setGlobalScopeExtension(JSScope* scope)
1156 {
1157     m_globalScopeExtension.set(vm(), this, scope);
1158 }
1159
1160 void JSGlobalObject::clearGlobalScopeExtension()
1161 {
1162     m_globalScopeExtension.clear();
1163 }
1164
1165 static inline JSObject* lastInPrototypeChain(VM& vm, JSObject* object)
1166 {
1167     JSObject* o = object;
1168     while (o->getPrototypeDirect(vm).isObject())
1169         o = asObject(o->getPrototypeDirect(vm));
1170     return o;
1171 }
1172
1173 // Private namespace for helpers for JSGlobalObject::haveABadTime()
1174 namespace {
1175
1176 class GlobalObjectDependencyFinder : public MarkedBlock::VoidFunctor {
1177 public:
1178     GlobalObjectDependencyFinder(VM& vm)
1179         : m_vm(vm)
1180     { }
1181
1182     IterationStatus operator()(HeapCell*, HeapCell::Kind) const;
1183
1184     void addDependency(JSGlobalObject* key, JSGlobalObject* dependent);
1185     HashSet<JSGlobalObject*>* dependentsFor(JSGlobalObject* key);
1186
1187 private:
1188     void visit(JSObject*);
1189
1190     VM& m_vm;
1191     HashMap<JSGlobalObject*, HashSet<JSGlobalObject*>> m_dependencies;
1192 };
1193
1194 inline void GlobalObjectDependencyFinder::addDependency(JSGlobalObject* key, JSGlobalObject* dependent)
1195 {
1196     auto keyResult = m_dependencies.add(key, HashSet<JSGlobalObject*>());
1197     keyResult.iterator->value.add(dependent);
1198 }
1199
1200 inline HashSet<JSGlobalObject*>* GlobalObjectDependencyFinder::dependentsFor(JSGlobalObject* key)
1201 {
1202     auto iterator = m_dependencies.find(key);
1203     if (iterator == m_dependencies.end())
1204         return nullptr;
1205     return &iterator->value;
1206 }
1207
1208 inline void GlobalObjectDependencyFinder::visit(JSObject* object)
1209 {
1210     VM& vm = m_vm;
1211
1212     if (!object->mayBePrototype())
1213         return;
1214
1215     JSObject* current = object;
1216     JSGlobalObject* objectGlobalObject = object->globalObject(vm);
1217     do {
1218         JSValue prototypeValue = current->getPrototypeDirect(vm);
1219         if (prototypeValue.isNull())
1220             return;
1221         current = asObject(prototypeValue);
1222
1223         JSGlobalObject* protoGlobalObject = current->globalObject(vm);
1224         if (protoGlobalObject != objectGlobalObject)
1225             addDependency(protoGlobalObject, objectGlobalObject);
1226     } while (true);
1227 }
1228
1229 IterationStatus GlobalObjectDependencyFinder::operator()(HeapCell* cell, HeapCell::Kind kind) const
1230 {
1231     if (isJSCellKind(kind) && static_cast<JSCell*>(cell)->isObject()) {
1232         // FIXME: This const_cast exists because this isn't a C++ lambda.
1233         // https://bugs.webkit.org/show_bug.cgi?id=159644
1234         const_cast<GlobalObjectDependencyFinder*>(this)->visit(jsCast<JSObject*>(static_cast<JSCell*>(cell)));
1235     }
1236     return IterationStatus::Continue;
1237 }
1238
1239 enum class BadTimeFinderMode {
1240     SingleGlobal,
1241     MultipleGlobals
1242 };
1243
1244 template<BadTimeFinderMode mode>
1245 class ObjectsWithBrokenIndexingFinder : public MarkedBlock::VoidFunctor {
1246 public:
1247     ObjectsWithBrokenIndexingFinder(VM&, Vector<JSObject*>&, JSGlobalObject*);
1248     ObjectsWithBrokenIndexingFinder(VM&, Vector<JSObject*>&, HashSet<JSGlobalObject*>&);
1249
1250     bool needsMultiGlobalsScan() const { return m_needsMultiGlobalsScan; }
1251     IterationStatus operator()(HeapCell*, HeapCell::Kind) const;
1252
1253 private:
1254     IterationStatus visit(JSObject*);
1255
1256     VM& m_vm;
1257     Vector<JSObject*>& m_foundObjects;
1258     JSGlobalObject* m_globalObject { nullptr }; // Only used for SingleBadTimeGlobal mode.
1259     HashSet<JSGlobalObject*>* m_globalObjects { nullptr }; // Only used for BadTimeGlobalGraph mode;
1260     bool m_needsMultiGlobalsScan { false };
1261 };
1262
1263 template<>
1264 ObjectsWithBrokenIndexingFinder<BadTimeFinderMode::SingleGlobal>::ObjectsWithBrokenIndexingFinder(
1265     VM& vm, Vector<JSObject*>& foundObjects, JSGlobalObject* globalObject)
1266     : m_vm(vm)
1267     , m_foundObjects(foundObjects)
1268     , m_globalObject(globalObject)
1269 {
1270 }
1271
1272 template<>
1273 ObjectsWithBrokenIndexingFinder<BadTimeFinderMode::MultipleGlobals>::ObjectsWithBrokenIndexingFinder(
1274     VM& vm, Vector<JSObject*>& foundObjects, HashSet<JSGlobalObject*>& globalObjects)
1275     : m_vm(vm)
1276     , m_foundObjects(foundObjects)
1277     , m_globalObjects(&globalObjects)
1278 {
1279 }
1280
1281 inline bool hasBrokenIndexing(IndexingType type)
1282 {
1283     return type && !hasSlowPutArrayStorage(type);
1284 }
1285
1286 inline bool hasBrokenIndexing(JSObject* object)
1287 {
1288     IndexingType type = object->indexingType();
1289     return hasBrokenIndexing(type);
1290 }
1291
1292 template<BadTimeFinderMode mode>
1293 inline IterationStatus ObjectsWithBrokenIndexingFinder<mode>::visit(JSObject* object)
1294 {
1295     VM& vm = m_vm;
1296
1297     // We only want to have a bad time in the affected global object, not in the entire
1298     // VM. But we have to be careful, since there may be objects that claim to belong to
1299     // a different global object that have prototypes from our global object.
1300     auto isInAffectedGlobalObject = [&] (JSObject* object) {
1301         JSGlobalObject* objectGlobalObject { nullptr };
1302         bool objectMayBePrototype { false };
1303
1304         if (mode == BadTimeFinderMode::SingleGlobal) {
1305             objectGlobalObject = object->globalObject(vm);
1306             if (objectGlobalObject == m_globalObject)
1307                 return true;
1308
1309             objectMayBePrototype = object->mayBePrototype();
1310         }
1311
1312         for (JSObject* current = object; ;) {
1313             JSGlobalObject* currentGlobalObject = current->globalObject(vm);
1314             if (mode == BadTimeFinderMode::SingleGlobal) {
1315                 if (objectMayBePrototype && currentGlobalObject != objectGlobalObject)
1316                     m_needsMultiGlobalsScan = true;
1317                 if (currentGlobalObject == m_globalObject)
1318                     return true;
1319             } else {
1320                 if (m_globalObjects->contains(currentGlobalObject))
1321                     return true;
1322             }
1323
1324             JSValue prototypeValue = current->getPrototypeDirect(vm);
1325             if (prototypeValue.isNull())
1326                 return false;
1327             current = asObject(prototypeValue);
1328         }
1329         RELEASE_ASSERT_NOT_REACHED();
1330     };
1331
1332     if (JSFunction* function = jsDynamicCast<JSFunction*>(vm, object)) {
1333         if (FunctionRareData* rareData = function->rareData()) {
1334             // We only use this to cache JSFinalObjects. They do not start off with a broken indexing type.
1335             ASSERT(!(rareData->objectAllocationStructure() && hasBrokenIndexing(rareData->objectAllocationStructure()->indexingType())));
1336
1337             if (Structure* structure = rareData->internalFunctionAllocationStructure()) {
1338                 if (hasBrokenIndexing(structure->indexingType())) {
1339                     bool isRelevantGlobalObject =
1340                         (mode == BadTimeFinderMode::SingleGlobal
1341                             ? m_globalObject == structure->globalObject()
1342                             : m_globalObjects->contains(structure->globalObject()))
1343                         || (structure->hasMonoProto() && !structure->storedPrototype().isNull() && isInAffectedGlobalObject(asObject(structure->storedPrototype())));
1344                     if (mode == BadTimeFinderMode::SingleGlobal && m_needsMultiGlobalsScan)
1345                         return IterationStatus::Done; // Bailing early and let the MultipleGlobals path handle everything.
1346                     if (isRelevantGlobalObject)
1347                         rareData->clearInternalFunctionAllocationProfile();
1348                 }
1349             }
1350         }
1351     }
1352
1353     // Run this filter first, since it's cheap, and ought to filter out a lot of objects.
1354     if (!hasBrokenIndexing(object))
1355         return IterationStatus::Continue;
1356
1357     if (isInAffectedGlobalObject(object))
1358         m_foundObjects.append(object);
1359
1360     if (mode == BadTimeFinderMode::SingleGlobal && m_needsMultiGlobalsScan)
1361         return IterationStatus::Done; // Bailing early and let the MultipleGlobals path handle everything.
1362
1363     return IterationStatus::Continue;
1364 }
1365
1366 template<BadTimeFinderMode mode>
1367 IterationStatus ObjectsWithBrokenIndexingFinder<mode>::operator()(HeapCell* cell, HeapCell::Kind kind) const
1368 {
1369     if (isJSCellKind(kind) && static_cast<JSCell*>(cell)->isObject()) {
1370         // FIXME: This const_cast exists because this isn't a C++ lambda.
1371         // https://bugs.webkit.org/show_bug.cgi?id=159644
1372         return const_cast<ObjectsWithBrokenIndexingFinder*>(this)->visit(jsCast<JSObject*>(static_cast<JSCell*>(cell)));
1373     }
1374     return IterationStatus::Continue;
1375 }
1376
1377 } // end private namespace for helpers for JSGlobalObject::haveABadTime()
1378
1379 void JSGlobalObject::fireWatchpointAndMakeAllArrayStructuresSlowPut(VM& vm)
1380 {
1381     if (isHavingABadTime())
1382         return;
1383
1384     // Make sure that all allocations or indexed storage transitions that are inlining
1385     // the assumption that it's safe to transition to a non-SlowPut array storage don't
1386     // do so anymore.
1387     m_havingABadTimeWatchpoint->fireAll(vm, "Having a bad time");
1388     ASSERT(isHavingABadTime()); // The watchpoint is what tells us that we're having a bad time.
1389     
1390     // Make sure that all JSArray allocations that load the appropriate structure from
1391     // this object now load a structure that uses SlowPut.
1392     for (unsigned i = 0; i < NumberOfArrayIndexingModes; ++i)
1393         m_arrayStructureForIndexingShapeDuringAllocation[i].set(vm, this, originalArrayStructureForIndexingType(ArrayWithSlowPutArrayStorage));
1394
1395     // Same for any special array structures.
1396     Structure* slowPutStructure;
1397     slowPutStructure = createRegExpMatchesArraySlowPutStructure(vm, this);
1398     m_regExpMatchesArrayStructure.set(vm, this, slowPutStructure);
1399     slowPutStructure = createRegExpMatchesArrayWithGroupsSlowPutStructure(vm, this);
1400     m_regExpMatchesArrayWithGroupsStructure.set(vm, this, slowPutStructure);
1401     slowPutStructure = ClonedArguments::createSlowPutStructure(vm, this, m_objectPrototype.get());
1402     m_clonedArgumentsStructure.set(vm, this, slowPutStructure);
1403 };
1404
1405 void JSGlobalObject::haveABadTime(VM& vm)
1406 {
1407     ASSERT(&vm == &this->vm());
1408     
1409     if (isHavingABadTime())
1410         return;
1411
1412     vm.structureCache.clear(); // We may be caching array structures in here.
1413
1414     DeferGC deferGC(vm.heap);
1415
1416     // Consider the following objects and prototype chains:
1417     //    O (of global G1) -> A (of global G1)
1418     //    B (of global G2) where G2 has a bad time
1419     //
1420     // If we set B as the prototype of A, G1 will need to have a bad time.
1421     // See comments in Structure::mayInterceptIndexedAccesses() for why.
1422     //
1423     // Now, consider the following objects and prototype chains:
1424     //    O1 (of global G1) -> A1 (of global G1) -> B1 (of global G2)
1425     //    O2 (of global G2) -> A2 (of global G2)
1426     //    B2 (of global G3) where G3 has a bad time.
1427     //
1428     // G1 and G2 does not have a bad time, but G3 already has a bad time.
1429     // If we set B2 as the prototype of A2, then G2 needs to have a bad time.
1430     // Note that by induction, G1 also now needs to have a bad time because of
1431     // O1 -> A1 -> B1.
1432     //
1433     // We describe this as global G1 being affected by global G2, and G2 by G3.
1434     // Similarly, we say that G1 is dependent on G2, and G2 on G3.
1435     // Hence, when G3 has a bad time, we need to ensure that all globals that
1436     // are transitively dependent on it also have a bad time (G2 and G1 in this
1437     // example).
1438     //
1439     // Apart from clearing the VM structure cache above, there are 2 more things
1440     // that we have to do when globals have a bad time:
1441     // 1. For each affected global:
1442     //    a. Fire its HaveABadTime watchpoint.
1443     //    b. Convert all of its array structures to SlowPutArrayStorage.
1444     // 2. Make sure that all affected objects  switch to the slow kind of
1445     //    indexed storage. An object is considered to be affected if it has
1446     //    indexed storage and has a prototype object which may have indexed
1447     //    accessors. If the prototype object belongs to a global having a bad
1448     //    time, then the prototype object is considered to possibly have indexed
1449     //    accessors. See comments in Structure::mayInterceptIndexedAccesses()
1450     //    for details.
1451     //
1452     // Note: step 1 must be completed before step 2 because step 2 relies on
1453     // the HaveABadTime watchpoint having already been fired on all affected
1454     // globals.
1455     //
1456     // In the common case, only this global will start having a bad time here,
1457     // and no other globals are affected by it. So, we first proceed on this assumption
1458     // with a simpler ObjectsWithBrokenIndexingFinder scan to find heap objects
1459     // affected by this global that need to be converted to SlowPutArrayStorage.
1460     // We'll also have the finder check for the presence of other global objects
1461     // depending on this one.
1462     //
1463     // If we do discover other globals depending on this one, we'll abort this
1464     // first ObjectsWithBrokenIndexingFinder scan because it will be insufficient
1465     // to find all affected objects that need to be converted to SlowPutArrayStorage.
1466     // It also does not make dependent globals have a bad time. Instead, we'll
1467     // take a more comprehensive approach of first creating a dependency graph
1468     // between globals, and then using that graph to determine all affected
1469     // globals and objects. With that, we can make all affected globals have a
1470     // bad time, and convert all affected objects to SlowPutArrayStorage.
1471
1472     fireWatchpointAndMakeAllArrayStructuresSlowPut(vm); // Step 1 above.
1473     
1474     Vector<JSObject*> foundObjects;
1475     ObjectsWithBrokenIndexingFinder<BadTimeFinderMode::SingleGlobal> finder(vm, foundObjects, this);
1476     {
1477         HeapIterationScope iterationScope(vm.heap);
1478         vm.heap.objectSpace().forEachLiveCell(iterationScope, finder); // Attempt step 2 above.
1479     }
1480
1481     if (finder.needsMultiGlobalsScan()) {
1482         foundObjects.clear();
1483
1484         // Find all globals that will also have a bad time as a side effect of
1485         // this global having a bad time.
1486         GlobalObjectDependencyFinder dependencies(vm);
1487         {
1488             HeapIterationScope iterationScope(vm.heap);
1489             vm.heap.objectSpace().forEachLiveCell(iterationScope, dependencies);
1490         }
1491
1492         HashSet<JSGlobalObject*> globalsHavingABadTime;
1493         Deque<JSGlobalObject*> globals;
1494
1495         globals.append(this);
1496         while (!globals.isEmpty()) {
1497             JSGlobalObject* global = globals.takeFirst();
1498             global->fireWatchpointAndMakeAllArrayStructuresSlowPut(vm); // Step 1 above.
1499             auto result = globalsHavingABadTime.add(global);
1500             if (result.isNewEntry) {
1501                 if (HashSet<JSGlobalObject*>* dependents = dependencies.dependentsFor(global)) {
1502                     for (JSGlobalObject* dependentGlobal : *dependents)
1503                         globals.append(dependentGlobal);
1504                 }
1505             }
1506         }
1507
1508         ObjectsWithBrokenIndexingFinder<BadTimeFinderMode::MultipleGlobals> finder(vm, foundObjects, globalsHavingABadTime);
1509         {
1510             HeapIterationScope iterationScope(vm.heap);
1511             vm.heap.objectSpace().forEachLiveCell(iterationScope, finder); // Step 2 above.
1512         }
1513     }
1514
1515     while (!foundObjects.isEmpty()) {
1516         JSObject* object = asObject(foundObjects.last());
1517         foundObjects.removeLast();
1518         ASSERT(hasBrokenIndexing(object));
1519         object->switchToSlowPutArrayStorage(vm);
1520     }
1521 }
1522
1523 // Set prototype, and also insert the object prototype at the end of the chain.
1524 void JSGlobalObject::resetPrototype(VM& vm, JSValue prototype)
1525 {
1526     setPrototypeDirect(vm, prototype);
1527
1528     JSObject* oldLastInPrototypeChain = lastInPrototypeChain(vm, this);
1529     JSObject* objectPrototype = m_objectPrototype.get();
1530     if (oldLastInPrototypeChain != objectPrototype)
1531         oldLastInPrototypeChain->setPrototypeDirect(vm, objectPrototype);
1532
1533     // Whenever we change the prototype of the global object, we need to create a new JSProxy with the correct prototype.
1534     setGlobalThis(vm, JSProxy::create(vm, JSProxy::createStructure(vm, this, prototype, PureForwardingProxyType), this));
1535 }
1536
1537 void JSGlobalObject::visitChildren(JSCell* cell, SlotVisitor& visitor)
1538
1539     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(cell);
1540     ASSERT_GC_OBJECT_INHERITS(thisObject, info());
1541     Base::visitChildren(thisObject, visitor);
1542
1543     visitor.append(thisObject->m_globalThis);
1544
1545     visitor.append(thisObject->m_globalLexicalEnvironment);
1546     visitor.append(thisObject->m_globalScopeExtension);
1547     visitor.append(thisObject->m_globalCallee);
1548     visitor.append(thisObject->m_stackOverflowFrameCallee);
1549     visitor.append(thisObject->m_regExpConstructor);
1550     visitor.append(thisObject->m_errorConstructor);
1551     visitor.append(thisObject->m_nativeErrorPrototypeStructure);
1552     visitor.append(thisObject->m_nativeErrorStructure);
1553     thisObject->m_evalErrorConstructor.visit(visitor);
1554     visitor.append(thisObject->m_rangeErrorConstructor);
1555     thisObject->m_referenceErrorConstructor.visit(visitor);
1556     thisObject->m_syntaxErrorConstructor.visit(visitor);
1557     visitor.append(thisObject->m_typeErrorConstructor);
1558     thisObject->m_URIErrorConstructor.visit(visitor);
1559     visitor.append(thisObject->m_objectConstructor);
1560     visitor.append(thisObject->m_promiseConstructor);
1561
1562     visitor.append(thisObject->m_nullGetterFunction);
1563     visitor.append(thisObject->m_nullSetterFunction);
1564
1565     visitor.append(thisObject->m_parseIntFunction);
1566     visitor.append(thisObject->m_parseFloatFunction);
1567     visitor.append(thisObject->m_evalFunction);
1568     visitor.append(thisObject->m_callFunction);
1569     visitor.append(thisObject->m_applyFunction);
1570     visitor.append(thisObject->m_throwTypeErrorFunction);
1571     thisObject->m_arrayProtoToStringFunction.visit(visitor);
1572     thisObject->m_arrayProtoValuesFunction.visit(visitor);
1573     thisObject->m_initializePromiseFunction.visit(visitor);
1574     thisObject->m_iteratorProtocolFunction.visit(visitor);
1575     thisObject->m_promiseResolveFunction.visit(visitor);
1576     visitor.append(thisObject->m_objectProtoValueOfFunction);
1577     visitor.append(thisObject->m_numberProtoToStringFunction);
1578     visitor.append(thisObject->m_newPromiseCapabilityFunction);
1579     visitor.append(thisObject->m_functionProtoHasInstanceSymbolFunction);
1580     thisObject->m_throwTypeErrorGetterSetter.visit(visitor);
1581     visitor.append(thisObject->m_throwTypeErrorArgumentsCalleeAndCallerGetterSetter);
1582     thisObject->m_moduleLoader.visit(visitor);
1583
1584     visitor.append(thisObject->m_objectPrototype);
1585     visitor.append(thisObject->m_functionPrototype);
1586     visitor.append(thisObject->m_arrayPrototype);
1587     visitor.append(thisObject->m_errorPrototype);
1588     visitor.append(thisObject->m_iteratorPrototype);
1589     visitor.append(thisObject->m_generatorFunctionPrototype);
1590     visitor.append(thisObject->m_generatorPrototype);
1591     visitor.append(thisObject->m_asyncFunctionPrototype);
1592     visitor.append(thisObject->m_asyncGeneratorPrototype);
1593     visitor.append(thisObject->m_asyncIteratorPrototype);
1594     visitor.append(thisObject->m_asyncGeneratorFunctionPrototype);
1595
1596     thisObject->m_debuggerScopeStructure.visit(visitor);
1597     thisObject->m_withScopeStructure.visit(visitor);
1598     visitor.append(thisObject->m_strictEvalActivationStructure);
1599     visitor.append(thisObject->m_lexicalEnvironmentStructure);
1600     thisObject->m_moduleEnvironmentStructure.visit(visitor);
1601     visitor.append(thisObject->m_directArgumentsStructure);
1602     visitor.append(thisObject->m_scopedArgumentsStructure);
1603     visitor.append(thisObject->m_clonedArgumentsStructure);
1604     visitor.append(thisObject->m_objectStructureForObjectConstructor);
1605     for (unsigned i = 0; i < NumberOfArrayIndexingModes; ++i)
1606         visitor.append(thisObject->m_originalArrayStructureForIndexingShape[i]);
1607     for (unsigned i = 0; i < NumberOfArrayIndexingModes; ++i)
1608         visitor.append(thisObject->m_arrayStructureForIndexingShapeDuringAllocation[i]);
1609     thisObject->m_callbackConstructorStructure.visit(visitor);
1610     thisObject->m_callbackFunctionStructure.visit(visitor);
1611     thisObject->m_callbackObjectStructure.visit(visitor);
1612 #if JSC_OBJC_API_ENABLED
1613     thisObject->m_objcCallbackFunctionStructure.visit(visitor);
1614     thisObject->m_objcWrapperObjectStructure.visit(visitor);
1615 #endif
1616 #ifdef JSC_GLIB_API_ENABLED
1617     thisObject->m_glibCallbackFunctionStructure.visit(visitor);
1618     thisObject->m_glibWrapperObjectStructure.visit(visitor);
1619 #endif
1620     visitor.append(thisObject->m_nullPrototypeObjectStructure);
1621     visitor.append(thisObject->m_errorStructure);
1622     visitor.append(thisObject->m_calleeStructure);
1623
1624     visitor.append(thisObject->m_hostFunctionStructure);
1625     auto visitFunctionStructures = [&] (FunctionStructures& structures) {
1626         visitor.append(structures.arrowFunctionStructure);
1627         visitor.append(structures.sloppyFunctionStructure);
1628         visitor.append(structures.strictFunctionStructure);
1629     };
1630     visitFunctionStructures(thisObject->m_builtinFunctions);
1631     visitFunctionStructures(thisObject->m_ordinaryFunctions);
1632
1633     thisObject->m_customGetterSetterFunctionStructure.visit(visitor);
1634     thisObject->m_boundFunctionStructure.visit(visitor);
1635     visitor.append(thisObject->m_getterSetterStructure);
1636     thisObject->m_nativeStdFunctionStructure.visit(visitor);
1637     visitor.append(thisObject->m_bigIntObjectStructure);
1638     visitor.append(thisObject->m_symbolObjectStructure);
1639     visitor.append(thisObject->m_regExpStructure);
1640     visitor.append(thisObject->m_generatorFunctionStructure);
1641     visitor.append(thisObject->m_asyncFunctionStructure);
1642     visitor.append(thisObject->m_asyncGeneratorFunctionStructure);
1643     visitor.append(thisObject->m_iteratorResultObjectStructure);
1644     visitor.append(thisObject->m_regExpMatchesArrayStructure);
1645     visitor.append(thisObject->m_regExpMatchesArrayWithGroupsStructure);
1646     visitor.append(thisObject->m_moduleRecordStructure);
1647     visitor.append(thisObject->m_moduleNamespaceObjectStructure);
1648     visitor.append(thisObject->m_proxyObjectStructure);
1649     visitor.append(thisObject->m_callableProxyObjectStructure);
1650     visitor.append(thisObject->m_proxyRevokeStructure);
1651     
1652     visitor.append(thisObject->m_arrayBufferPrototype);
1653     visitor.append(thisObject->m_arrayBufferStructure);
1654 #if ENABLE(SHARED_ARRAY_BUFFER)
1655     visitor.append(thisObject->m_sharedArrayBufferPrototype);
1656     visitor.append(thisObject->m_sharedArrayBufferStructure);
1657 #endif
1658
1659 #define VISIT_SIMPLE_TYPE(CapitalName, lowerName, properName, instanceType, jsName, prototypeBase) do { \
1660         visitor.append(thisObject->m_ ## lowerName ## Prototype); \
1661         visitor.append(thisObject->m_ ## properName ## Structure); \
1662     } while (0);
1663
1664     FOR_EACH_SIMPLE_BUILTIN_TYPE(VISIT_SIMPLE_TYPE)
1665     if (UNLIKELY(Options::useBigInt()))
1666         FOR_BIG_INT_BUILTIN_TYPE_WITH_CONSTRUCTOR(VISIT_SIMPLE_TYPE)
1667     FOR_EACH_BUILTIN_DERIVED_ITERATOR_TYPE(VISIT_SIMPLE_TYPE)
1668     
1669 #if ENABLE(WEBASSEMBLY)
1670     visitor.append(thisObject->m_webAssemblyStructure);
1671     visitor.append(thisObject->m_webAssemblyModuleRecordStructure);
1672     visitor.append(thisObject->m_webAssemblyFunctionStructure);
1673     visitor.append(thisObject->m_webAssemblyWrapperFunctionStructure);
1674     visitor.append(thisObject->m_webAssemblyToJSCalleeStructure);
1675     FOR_EACH_WEBASSEMBLY_CONSTRUCTOR_TYPE(VISIT_SIMPLE_TYPE)
1676 #endif // ENABLE(WEBASSEMBLY)
1677
1678 #undef VISIT_SIMPLE_TYPE
1679
1680 #define VISIT_LAZY_TYPE(CapitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
1681     thisObject->m_ ## properName ## Structure.visit(visitor);
1682     
1683     FOR_EACH_LAZY_BUILTIN_TYPE(VISIT_LAZY_TYPE)
1684
1685 #undef VISIT_LAZY_TYPE
1686
1687     for (unsigned i = NumberOfTypedArrayTypes; i--;)
1688         thisObject->lazyTypedArrayStructure(indexToTypedArrayType(i)).visit(visitor);
1689     
1690     visitor.append(thisObject->m_speciesGetterSetter);
1691     thisObject->m_typedArrayProto.visit(visitor);
1692     thisObject->m_typedArraySuperConstructor.visit(visitor);
1693 }
1694
1695 ExecState* JSGlobalObject::globalExec()
1696 {
1697     return CallFrame::create(m_globalCallFrame);
1698 }
1699
1700 void JSGlobalObject::exposeDollarVM(VM& vm)
1701 {
1702     if (hasOwnProperty(globalExec(), vm.propertyNames->builtinNames().dollarVMPrivateName()))
1703         return;
1704
1705     JSDollarVM* dollarVM = JSDollarVM::create(vm, JSDollarVM::createStructure(vm, this, m_objectPrototype.get()));
1706
1707     GlobalPropertyInfo extraStaticGlobals[] = {
1708         GlobalPropertyInfo(vm.propertyNames->builtinNames().dollarVMPrivateName(), dollarVM, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1709     };
1710     addStaticGlobals(extraStaticGlobals, WTF_ARRAY_LENGTH(extraStaticGlobals));
1711
1712     putDirect(vm, Identifier::fromString(globalExec(), "$vm"), dollarVM, static_cast<unsigned>(PropertyAttribute::DontEnum));
1713 }
1714
1715 void JSGlobalObject::addStaticGlobals(GlobalPropertyInfo* globals, int count)
1716 {
1717     ScopeOffset startOffset = addVariables(count, jsUndefined());
1718
1719     for (int i = 0; i < count; ++i) {
1720         GlobalPropertyInfo& global = globals[i];
1721         // This `configurable = false` is necessary condition for static globals,
1722         // otherwise lexical bindings can change the result of GlobalVar queries too.
1723         // We won't be able to declare a global lexical variable with the sanem name to
1724         // the static globals because configurable = false.
1725         ASSERT(global.attributes & PropertyAttribute::DontDelete);
1726         
1727         WatchpointSet* watchpointSet = nullptr;
1728         WriteBarrierBase<Unknown>* variable = nullptr;
1729         {
1730             ConcurrentJSLocker locker(symbolTable()->m_lock);
1731             ScopeOffset offset = symbolTable()->takeNextScopeOffset(locker);
1732             RELEASE_ASSERT(offset == startOffset + i);
1733             SymbolTableEntry newEntry(VarOffset(offset), global.attributes);
1734             newEntry.prepareToWatch();
1735             watchpointSet = newEntry.watchpointSet();
1736             symbolTable()->add(locker, global.identifier.impl(), WTFMove(newEntry));
1737             variable = &variableAt(offset);
1738         }
1739         symbolTablePutTouchWatchpointSet(vm(), this, global.identifier, global.value, variable, watchpointSet);
1740     }
1741 }
1742
1743 bool JSGlobalObject::getOwnPropertySlot(JSObject* object, ExecState* exec, PropertyName propertyName, PropertySlot& slot)
1744 {
1745     if (Base::getOwnPropertySlot(object, exec, propertyName, slot))
1746         return true;
1747     return symbolTableGet(jsCast<JSGlobalObject*>(object), propertyName, slot);
1748 }
1749
1750 void JSGlobalObject::clearRareData(JSCell* cell)
1751 {
1752     jsCast<JSGlobalObject*>(cell)->m_rareData = nullptr;
1753 }
1754
1755 void slowValidateCell(JSGlobalObject* globalObject)
1756 {
1757     RELEASE_ASSERT(globalObject->isGlobalObject());
1758     ASSERT_GC_OBJECT_INHERITS(globalObject, JSGlobalObject::info());
1759 }
1760
1761 void JSGlobalObject::setRemoteDebuggingEnabled(bool enabled)
1762 {
1763 #if ENABLE(REMOTE_INSPECTOR)
1764     m_inspectorDebuggable->setRemoteDebuggingAllowed(enabled);
1765 #else
1766     UNUSED_PARAM(enabled);
1767 #endif
1768 }
1769
1770 bool JSGlobalObject::remoteDebuggingEnabled() const
1771 {
1772 #if ENABLE(REMOTE_INSPECTOR)
1773     return m_inspectorDebuggable->remoteDebuggingAllowed();
1774 #else
1775     return false;
1776 #endif
1777 }
1778
1779 void JSGlobalObject::setName(const String& name)
1780 {
1781     m_name = name;
1782
1783 #if ENABLE(REMOTE_INSPECTOR)
1784     m_inspectorDebuggable->update();
1785 #endif
1786 }
1787
1788 # if ENABLE(INTL)
1789 static void addMissingScriptLocales(HashSet<String>& availableLocales)
1790 {
1791     if (availableLocales.contains("pa-Arab-PK"))
1792         availableLocales.add("pa-PK"_s);
1793     if (availableLocales.contains("zh-Hans-CN"))
1794         availableLocales.add("zh-CN"_s);
1795     if (availableLocales.contains("zh-Hant-HK"))
1796         availableLocales.add("zh-HK"_s);
1797     if (availableLocales.contains("zh-Hans-SG"))
1798         availableLocales.add("zh-SG"_s);
1799     if (availableLocales.contains("zh-Hant-TW"))
1800         availableLocales.add("zh-TW"_s);
1801 }
1802
1803 const HashSet<String>& JSGlobalObject::intlCollatorAvailableLocales()
1804 {
1805     if (m_intlCollatorAvailableLocales.isEmpty()) {
1806         int32_t count = ucol_countAvailable();
1807         for (int32_t i = 0; i < count; ++i) {
1808             String locale = convertICULocaleToBCP47LanguageTag(ucol_getAvailable(i));
1809             if (!locale.isEmpty())
1810                 m_intlCollatorAvailableLocales.add(locale);
1811         }
1812         addMissingScriptLocales(m_intlCollatorAvailableLocales);
1813     }
1814     return m_intlCollatorAvailableLocales;
1815 }
1816
1817 const HashSet<String>& JSGlobalObject::intlDateTimeFormatAvailableLocales()
1818 {
1819     if (m_intlDateTimeFormatAvailableLocales.isEmpty()) {
1820         int32_t count = udat_countAvailable();
1821         for (int32_t i = 0; i < count; ++i) {
1822             String locale = convertICULocaleToBCP47LanguageTag(udat_getAvailable(i));
1823             if (!locale.isEmpty())
1824                 m_intlDateTimeFormatAvailableLocales.add(locale);
1825         }
1826         addMissingScriptLocales(m_intlDateTimeFormatAvailableLocales);
1827     }
1828     return m_intlDateTimeFormatAvailableLocales;
1829 }
1830
1831 const HashSet<String>& JSGlobalObject::intlNumberFormatAvailableLocales()
1832 {
1833     if (m_intlNumberFormatAvailableLocales.isEmpty()) {
1834         int32_t count = unum_countAvailable();
1835         for (int32_t i = 0; i < count; ++i) {
1836             String locale = convertICULocaleToBCP47LanguageTag(unum_getAvailable(i));
1837             if (!locale.isEmpty())
1838                 m_intlNumberFormatAvailableLocales.add(locale);
1839         }
1840         addMissingScriptLocales(m_intlNumberFormatAvailableLocales);
1841     }
1842     return m_intlNumberFormatAvailableLocales;
1843 }
1844
1845 const HashSet<String>& JSGlobalObject::intlPluralRulesAvailableLocales()
1846 {
1847     if (m_intlPluralRulesAvailableLocales.isEmpty()) {
1848         int32_t count = uloc_countAvailable();
1849         for (int32_t i = 0; i < count; ++i) {
1850             String locale = convertICULocaleToBCP47LanguageTag(uloc_getAvailable(i));
1851             if (!locale.isEmpty())
1852                 m_intlPluralRulesAvailableLocales.add(locale);
1853         }
1854         addMissingScriptLocales(m_intlPluralRulesAvailableLocales);
1855     }
1856     return m_intlPluralRulesAvailableLocales;
1857 }
1858 #endif // ENABLE(INTL)
1859
1860 void JSGlobalObject::notifyLexicalBindingShadowing(VM& vm, const IdentifierSet& set)
1861 {
1862     auto scope = DECLARE_THROW_SCOPE(vm);
1863 #if ENABLE(DFG_JIT)
1864     for (const auto& key : set)
1865         ensureReferencedPropertyWatchpointSet(key.get()).fireAll(vm, "Lexical binding shadows the existing global properties");
1866 #endif
1867     vm.heap.codeBlockSet().iterate([&] (CodeBlock* codeBlock) {
1868         if (codeBlock->globalObject() != this)
1869             return;
1870         codeBlock->notifyLexicalBindingShadowing(vm, set);
1871         scope.assertNoException();
1872     });
1873     scope.release();
1874 }
1875
1876 void JSGlobalObject::queueMicrotask(Ref<Microtask>&& task)
1877 {
1878     if (globalObjectMethodTable()->queueTaskToEventLoop) {
1879         globalObjectMethodTable()->queueTaskToEventLoop(*this, WTFMove(task));
1880         return;
1881     }
1882
1883     vm().queueMicrotask(*this, WTFMove(task));
1884 }
1885
1886 bool JSGlobalObject::hasDebugger() const
1887
1888     return m_debugger;
1889 }
1890
1891 bool JSGlobalObject::hasInteractiveDebugger() const 
1892
1893     return m_debugger && m_debugger->isInteractivelyDebugging();
1894 }
1895
1896 #if ENABLE(DFG_JIT)
1897 WatchpointSet* JSGlobalObject::getReferencedPropertyWatchpointSet(UniquedStringImpl* uid)
1898 {
1899     return m_referencedGlobalPropertyWatchpointSets.get(uid);
1900 }
1901
1902 WatchpointSet& JSGlobalObject::ensureReferencedPropertyWatchpointSet(UniquedStringImpl* uid)
1903 {
1904     return m_referencedGlobalPropertyWatchpointSets.ensure(uid, [] {
1905         return WatchpointSet::create(IsWatched);
1906     }).iterator->value.get();
1907 }
1908 #endif
1909
1910 JSGlobalObject* JSGlobalObject::create(VM& vm, Structure* structure)
1911 {
1912     JSGlobalObject* globalObject = new (NotNull, allocateCell<JSGlobalObject>(vm.heap)) JSGlobalObject(vm, structure);
1913     globalObject->finishCreation(vm);
1914     return globalObject;
1915 }
1916
1917 void JSGlobalObject::finishCreation(VM& vm)
1918 {
1919     Base::finishCreation(vm);
1920     structure(vm)->setGlobalObject(vm, this);
1921     m_runtimeFlags = m_globalObjectMethodTable->javaScriptRuntimeFlags(this);
1922     init(vm);
1923     setGlobalThis(vm, JSProxy::create(vm, JSProxy::createStructure(vm, this, getPrototypeDirect(vm), PureForwardingProxyType), this));
1924     ASSERT(type() == GlobalObjectType);
1925 }
1926
1927 void JSGlobalObject::finishCreation(VM& vm, JSObject* thisValue)
1928 {
1929     Base::finishCreation(vm);
1930     structure(vm)->setGlobalObject(vm, this);
1931     m_runtimeFlags = m_globalObjectMethodTable->javaScriptRuntimeFlags(this);
1932     init(vm);
1933     setGlobalThis(vm, thisValue);
1934     ASSERT(type() == GlobalObjectType);
1935 }
1936
1937 #ifdef JSC_GLIB_API_ENABLED
1938 void JSGlobalObject::setWrapperMap(std::unique_ptr<WrapperMap>&& map)
1939 {
1940     m_wrapperMap = WTFMove(map);
1941 }
1942 #endif
1943
1944 } // namespace JSC