Class contructor and methods shouldn't have "arguments" and "caller"
[WebKit-https.git] / Source / JavaScriptCore / runtime / JSGlobalObject.cpp
1 /*
2  * Copyright (C) 2007-2009, 2014-2016 Apple Inc. All rights reserved.
3  * Copyright (C) 2008 Cameron Zwarich (cwzwarich@uwaterloo.ca)
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *
9  * 1.  Redistributions of source code must retain the above copyright
10  *     notice, this list of conditions and the following disclaimer.
11  * 2.  Redistributions in binary form must reproduce the above copyright
12  *     notice, this list of conditions and the following disclaimer in the
13  *     documentation and/or other materials provided with the distribution.
14  * 3.  Neither the name of Apple Inc. ("Apple") nor the names of
15  *     its contributors may be used to endorse or promote products derived
16  *     from this software without specific prior written permission.
17  *
18  * THIS SOFTWARE IS PROVIDED BY APPLE AND ITS CONTRIBUTORS "AS IS" AND ANY
19  * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
20  * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
21  * DISCLAIMED. IN NO EVENT SHALL APPLE OR ITS CONTRIBUTORS BE LIABLE FOR ANY
22  * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
23  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
24  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
25  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
26  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
27  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
28  */
29
30 #include "config.h"
31 #include "JSGlobalObject.h"
32
33 #include "ArrayConstructor.h"
34 #include "ArrayIteratorPrototype.h"
35 #include "ArrayPrototype.h"
36 #include "BooleanConstructor.h"
37 #include "BooleanPrototype.h"
38 #include "BuiltinNames.h"
39 #include "ClonedArguments.h"
40 #include "CodeBlock.h"
41 #include "CodeCache.h"
42 #include "ConsolePrototype.h"
43 #include "DateConstructor.h"
44 #include "DatePrototype.h"
45 #include "Debugger.h"
46 #include "DebuggerScope.h"
47 #include "DirectArguments.h"
48 #include "ECMAScriptSpecInternalFunctions.h"
49 #include "Error.h"
50 #include "ErrorConstructor.h"
51 #include "ErrorPrototype.h"
52 #include "FunctionConstructor.h"
53 #include "FunctionPrototype.h"
54 #include "GeneratorFunctionConstructor.h"
55 #include "GeneratorFunctionPrototype.h"
56 #include "GeneratorPrototype.h"
57 #include "GetterSetter.h"
58 #include "HeapIterationScope.h"
59 #include "InspectorInstrumentationObject.h"
60 #include "Interpreter.h"
61 #include "IteratorPrototype.h"
62 #include "JSAPIWrapperObject.h"
63 #include "JSArrayBuffer.h"
64 #include "JSArrayBufferConstructor.h"
65 #include "JSArrayBufferPrototype.h"
66 #include "JSArrayIterator.h"
67 #include "JSBoundFunction.h"
68 #include "JSBoundSlotBaseFunction.h"
69 #include "JSCInlines.h"
70 #include "JSCallbackConstructor.h"
71 #include "JSCallbackFunction.h"
72 #include "JSCallbackObject.h"
73 #include "JSConsole.h"
74 #include "JSDataView.h"
75 #include "JSDataViewPrototype.h"
76 #include "JSDollarVM.h"
77 #include "JSDollarVMPrototype.h"
78 #include "JSFunction.h"
79 #include "JSGeneratorFunction.h"
80 #include "JSGenericTypedArrayViewConstructorInlines.h"
81 #include "JSGenericTypedArrayViewInlines.h"
82 #include "JSGenericTypedArrayViewPrototypeInlines.h"
83 #include "JSGlobalObjectFunctions.h"
84 #include "JSInternalPromise.h"
85 #include "JSInternalPromiseConstructor.h"
86 #include "JSInternalPromisePrototype.h"
87 #include "JSJob.h"
88 #include "JSLexicalEnvironment.h"
89 #include "JSLock.h"
90 #include "JSMap.h"
91 #include "JSMapIterator.h"
92 #include "JSModuleEnvironment.h"
93 #include "JSModuleNamespaceObject.h"
94 #include "JSModuleRecord.h"
95 #include "JSNativeStdFunction.h"
96 #include "JSONObject.h"
97 #include "JSPromise.h"
98 #include "JSPromiseConstructor.h"
99 #include "JSPromisePrototype.h"
100 #include "JSPropertyNameIterator.h"
101 #include "JSSet.h"
102 #include "JSSetIterator.h"
103 #include "JSStringIterator.h"
104 #include "JSTemplateRegistryKey.h"
105 #include "JSTypedArrayConstructors.h"
106 #include "JSTypedArrayPrototypes.h"
107 #include "JSTypedArrayViewConstructor.h"
108 #include "JSTypedArrayViewPrototype.h"
109 #include "JSTypedArrays.h"
110 #include "JSWASMModule.h"
111 #include "JSWeakMap.h"
112 #include "JSWeakSet.h"
113 #include "JSWithScope.h"
114 #include "LegacyProfiler.h"
115 #include "Lookup.h"
116 #include "MapConstructor.h"
117 #include "MapIteratorPrototype.h"
118 #include "MapPrototype.h"
119 #include "MathObject.h"
120 #include "Microtask.h"
121 #include "ModuleLoaderObject.h"
122 #include "NativeErrorConstructor.h"
123 #include "NativeErrorPrototype.h"
124 #include "NullGetterFunction.h"
125 #include "NullSetterFunction.h"
126 #include "NumberConstructor.h"
127 #include "NumberPrototype.h"
128 #include "ObjCCallbackFunction.h"
129 #include "ObjectConstructor.h"
130 #include "ObjectPrototype.h"
131 #include "ParserError.h"
132 #include "ProxyConstructor.h"
133 #include "ProxyObject.h"
134 #include "ProxyRevoke.h"
135 #include "ReflectObject.h"
136 #include "RegExpConstructor.h"
137 #include "RegExpMatchesArray.h"
138 #include "RegExpObject.h"
139 #include "RegExpPrototype.h"
140 #include "ScopedArguments.h"
141 #include "SetConstructor.h"
142 #include "SetIteratorPrototype.h"
143 #include "SetPrototype.h"
144 #include "StrictEvalActivation.h"
145 #include "StringConstructor.h"
146 #include "StringIteratorPrototype.h"
147 #include "StringPrototype.h"
148 #include "Symbol.h"
149 #include "SymbolConstructor.h"
150 #include "SymbolPrototype.h"
151 #include "VariableWriteFireDetail.h"
152 #include "WeakGCMapInlines.h"
153 #include "WeakMapConstructor.h"
154 #include "WeakMapPrototype.h"
155 #include "WeakSetConstructor.h"
156 #include "WeakSetPrototype.h"
157 #include <wtf/RandomNumber.h>
158
159 #if ENABLE(INTL)
160 #include "IntlObject.h"
161 #include <unicode/ucol.h>
162 #include <unicode/udat.h>
163 #include <unicode/unum.h>
164 #endif // ENABLE(INTL)
165
166 #if ENABLE(REMOTE_INSPECTOR)
167 #include "JSGlobalObjectDebuggable.h"
168 #include "JSGlobalObjectInspectorController.h"
169 #endif
170
171 #if ENABLE(WEB_REPLAY)
172 #include "EmptyInputCursor.h"
173 #include "JSReplayInputs.h"
174 #endif
175
176 #include "JSGlobalObject.lut.h"
177
178 namespace JSC {
179
180 const ClassInfo JSGlobalObject::s_info = { "GlobalObject", &Base::s_info, &globalObjectTable, CREATE_METHOD_TABLE(JSGlobalObject) };
181
182 const GlobalObjectMethodTable JSGlobalObject::s_globalObjectMethodTable = { &allowsAccessFrom, &supportsLegacyProfiling, &supportsRichSourceInfo, &shouldInterruptScript, &javaScriptRuntimeFlags, nullptr, &shouldInterruptScriptBeforeTimeout, nullptr, nullptr, nullptr, nullptr, nullptr, nullptr };
183
184 /* Source for JSGlobalObject.lut.h
185 @begin globalObjectTable
186   parseFloat            globalFuncParseFloat            DontEnum|Function 1
187   isNaN                 globalFuncIsNaN                 DontEnum|Function 1
188   isFinite              globalFuncIsFinite              DontEnum|Function 1
189   escape                globalFuncEscape                DontEnum|Function 1
190   unescape              globalFuncUnescape              DontEnum|Function 1
191   decodeURI             globalFuncDecodeURI             DontEnum|Function 1
192   decodeURIComponent    globalFuncDecodeURIComponent    DontEnum|Function 1
193   encodeURI             globalFuncEncodeURI             DontEnum|Function 1
194   encodeURIComponent    globalFuncEncodeURIComponent    DontEnum|Function 1
195 @end
196 */
197
198 static EncodedJSValue JSC_HOST_CALL getTemplateObject(ExecState* exec)
199 {
200     JSValue thisValue = exec->thisValue();
201     ASSERT(thisValue.inherits(JSTemplateRegistryKey::info()));
202     return JSValue::encode(exec->lexicalGlobalObject()->templateRegistry().getTemplateObject(exec, jsCast<JSTemplateRegistryKey*>(thisValue)->templateRegistryKey()));
203 }
204
205
206 static EncodedJSValue JSC_HOST_CALL enqueueJob(ExecState* exec)
207 {
208     VM& vm = exec->vm();
209     JSGlobalObject* globalObject = exec->lexicalGlobalObject();
210
211     JSValue job = exec->argument(0);
212     JSValue arguments = exec->argument(1);
213     ASSERT(arguments.inherits(JSArray::info()));
214
215     globalObject->queueMicrotask(createJSJob(vm, job, jsCast<JSArray*>(arguments)));
216
217     return JSValue::encode(jsUndefined());
218 }
219
220 JSGlobalObject::JSGlobalObject(VM& vm, Structure* structure, const GlobalObjectMethodTable* globalObjectMethodTable)
221     : Base(vm, structure, 0)
222     , m_vm(vm)
223 #if ENABLE(WEB_REPLAY)
224     , m_inputCursor(EmptyInputCursor::create())
225 #endif
226     , m_masqueradesAsUndefinedWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
227     , m_havingABadTimeWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
228     , m_varInjectionWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
229     , m_weakRandom(Options::forceWeakRandomSeed() ? Options::forcedWeakRandomSeed() : static_cast<unsigned>(randomNumber() * (std::numeric_limits<unsigned>::max() + 1.0)))
230     , m_templateRegistry(vm)
231     , m_evalEnabled(true)
232     , m_runtimeFlags()
233     , m_consoleClient(nullptr)
234     , m_globalObjectMethodTable(globalObjectMethodTable ? globalObjectMethodTable : &s_globalObjectMethodTable)
235 {
236 }
237
238 JSGlobalObject::~JSGlobalObject()
239 {
240 #if ENABLE(REMOTE_INSPECTOR)
241     m_inspectorController->globalObjectDestroyed();
242 #endif
243
244     if (m_debugger)
245         m_debugger->detach(this, Debugger::GlobalObjectIsDestructing);
246
247     if (LegacyProfiler* profiler = vm().enabledProfiler())
248         profiler->stopProfiling(this);
249 }
250
251 void JSGlobalObject::destroy(JSCell* cell)
252 {
253     static_cast<JSGlobalObject*>(cell)->JSGlobalObject::~JSGlobalObject();
254 }
255
256 void JSGlobalObject::setGlobalThis(VM& vm, JSObject* globalThis)
257 {
258     m_globalThis.set(vm, this, globalThis);
259 }
260
261 static JSObject* getGetterById(ExecState* exec, JSObject* base, const Identifier& ident)
262 {
263     JSValue baseValue = JSValue(base);
264     PropertySlot slot(baseValue, PropertySlot::InternalMethodType::VMInquiry);
265     baseValue.getPropertySlot(exec, ident, slot);
266     return slot.getPureResult().toObject(exec);
267 }
268
269 void JSGlobalObject::init(VM& vm)
270 {
271     ASSERT(vm.currentThreadIsHoldingAPILock());
272
273     JSGlobalObject::globalExec()->init(0, 0, CallFrame::noCaller(), 0, 0);
274
275     m_debugger = 0;
276
277 #if ENABLE(REMOTE_INSPECTOR)
278     m_inspectorController = std::make_unique<Inspector::JSGlobalObjectInspectorController>(*this);
279     m_inspectorDebuggable = std::make_unique<JSGlobalObjectDebuggable>(*this);
280     m_inspectorDebuggable->init();
281     m_consoleClient = m_inspectorController->consoleClient();
282 #endif
283
284     ExecState* exec = JSGlobalObject::globalExec();
285
286     m_functionPrototype.set(vm, this, FunctionPrototype::create(vm, FunctionPrototype::createStructure(vm, this, jsNull()))); // The real prototype will be set once ObjectPrototype is created.
287     m_calleeStructure.set(vm, this, JSCallee::createStructure(vm, this, jsNull()));
288
289     m_globalLexicalEnvironment.set(vm, this, JSGlobalLexicalEnvironment::create(vm, JSGlobalLexicalEnvironment::createStructure(vm, this), this));
290     // Need to create the callee structure (above) before creating the callee.
291     m_globalCallee.set(vm, this, JSCallee::create(vm, this, globalScope()));
292     exec->setCallee(m_globalCallee.get());
293
294     m_functionStructure.set(vm, this, JSFunction::createStructure(vm, this, m_functionPrototype.get()));
295     m_boundSlotBaseFunctionStructure.set(vm, this, JSBoundSlotBaseFunction::createStructure(vm, this, m_functionPrototype.get()));
296     m_boundFunctionStructure.set(vm, this, JSBoundFunction::createStructure(vm, this, m_functionPrototype.get()));
297     m_getterSetterStructure.set(vm, this, GetterSetter::createStructure(vm, this, jsNull()));
298     m_nativeStdFunctionStructure.set(vm, this, JSNativeStdFunction::createStructure(vm, this, m_functionPrototype.get()));
299     m_namedFunctionStructure.set(vm, this, Structure::addPropertyTransition(vm, m_functionStructure.get(), vm.propertyNames->name, DontDelete | ReadOnly | DontEnum, m_functionNameOffset));
300     m_internalFunctionStructure.set(vm, this, InternalFunction::createStructure(vm, this, m_functionPrototype.get()));
301     JSFunction* callFunction = 0;
302     JSFunction* applyFunction = 0;
303     JSFunction* hasInstanceSymbolFunction = 0;
304     m_functionPrototype->addFunctionProperties(exec, this, &callFunction, &applyFunction, &hasInstanceSymbolFunction);
305     m_callFunction.set(vm, this, callFunction);
306     m_applyFunction.set(vm, this, applyFunction);
307     m_arrayProtoValuesFunction.set(vm, this, JSFunction::create(vm, this, 0, vm.propertyNames->values.string(), arrayProtoFuncValues));
308     m_initializePromiseFunction.set(vm, this, JSFunction::createBuiltinFunction(vm, promiseOperationsInitializePromiseCodeGenerator(vm), this));
309     m_newPromiseCapabilityFunction.set(vm, this, JSFunction::createBuiltinFunction(vm, promiseOperationsNewPromiseCapabilityCodeGenerator(vm), this));
310     m_functionProtoHasInstanceSymbolFunction.set(vm, this, hasInstanceSymbolFunction);
311     m_nullGetterFunction.set(vm, this, NullGetterFunction::create(vm, NullGetterFunction::createStructure(vm, this, m_functionPrototype.get())));
312     m_nullSetterFunction.set(vm, this, NullSetterFunction::create(vm, NullSetterFunction::createStructure(vm, this, m_functionPrototype.get())));
313     m_objectPrototype.set(vm, this, ObjectPrototype::create(vm, this, ObjectPrototype::createStructure(vm, this, jsNull())));
314     GetterSetter* protoAccessor = GetterSetter::create(vm, this);
315     protoAccessor->setGetter(vm, this, JSFunction::create(vm, this, 0, makeString("get ", vm.propertyNames->underscoreProto.string()), globalFuncProtoGetter));
316     protoAccessor->setSetter(vm, this, JSFunction::create(vm, this, 0, makeString("set ", vm.propertyNames->underscoreProto.string()), globalFuncProtoSetter));
317     m_objectPrototype->putDirectNonIndexAccessor(vm, vm.propertyNames->underscoreProto, protoAccessor, Accessor | DontEnum);
318     m_functionPrototype->structure()->setPrototypeWithoutTransition(vm, m_objectPrototype.get());
319
320     JSTypedArrayViewPrototype* typedArrayProto = JSTypedArrayViewPrototype::create(vm, this, JSTypedArrayViewPrototype::createStructure(vm, this, m_objectPrototype.get()));
321
322     m_typedArrays[toIndex(TypeInt8)].prototype.set(vm, this, JSInt8ArrayPrototype::create(vm, this, JSInt8ArrayPrototype::createStructure(vm, this, typedArrayProto)));
323     m_typedArrays[toIndex(TypeInt16)].prototype.set(vm, this, JSInt16ArrayPrototype::create(vm, this, JSInt16ArrayPrototype::createStructure(vm, this, typedArrayProto)));
324     m_typedArrays[toIndex(TypeInt32)].prototype.set(vm, this, JSInt32ArrayPrototype::create(vm, this, JSInt32ArrayPrototype::createStructure(vm, this, typedArrayProto)));
325     m_typedArrays[toIndex(TypeUint8)].prototype.set(vm, this, JSUint8ArrayPrototype::create(vm, this, JSUint8ArrayPrototype::createStructure(vm, this, typedArrayProto)));
326     m_typedArrays[toIndex(TypeUint8Clamped)].prototype.set(vm, this, JSUint8ClampedArrayPrototype::create(vm, this, JSUint8ClampedArrayPrototype::createStructure(vm, this, typedArrayProto)));
327     m_typedArrays[toIndex(TypeUint16)].prototype.set(vm, this, JSUint16ArrayPrototype::create(vm, this, JSUint16ArrayPrototype::createStructure(vm, this, typedArrayProto)));
328     m_typedArrays[toIndex(TypeUint32)].prototype.set(vm, this, JSUint32ArrayPrototype::create(vm, this, JSUint32ArrayPrototype::createStructure(vm, this, typedArrayProto)));
329     m_typedArrays[toIndex(TypeFloat32)].prototype.set(vm, this, JSFloat32ArrayPrototype::create(vm, this, JSFloat32ArrayPrototype::createStructure(vm, this, typedArrayProto)));
330     m_typedArrays[toIndex(TypeFloat64)].prototype.set(vm, this, JSFloat64ArrayPrototype::create(vm, this, JSFloat64ArrayPrototype::createStructure(vm, this, typedArrayProto)));
331     m_typedArrays[toIndex(TypeDataView)].prototype.set(vm, this, JSDataViewPrototype::create(vm, JSDataViewPrototype::createStructure(vm, this, m_objectPrototype.get())));
332     
333     m_typedArrays[toIndex(TypeInt8)].structure.set(vm, this, JSInt8Array::createStructure(vm, this, m_typedArrays[toIndex(TypeInt8)].prototype.get()));
334     m_typedArrays[toIndex(TypeInt16)].structure.set(vm, this, JSInt16Array::createStructure(vm, this, m_typedArrays[toIndex(TypeInt16)].prototype.get()));
335     m_typedArrays[toIndex(TypeInt32)].structure.set(vm, this, JSInt32Array::createStructure(vm, this, m_typedArrays[toIndex(TypeInt32)].prototype.get()));
336     m_typedArrays[toIndex(TypeUint8)].structure.set(vm, this, JSUint8Array::createStructure(vm, this, m_typedArrays[toIndex(TypeUint8)].prototype.get()));
337     m_typedArrays[toIndex(TypeUint8Clamped)].structure.set(vm, this, JSUint8ClampedArray::createStructure(vm, this, m_typedArrays[toIndex(TypeUint8Clamped)].prototype.get()));
338     m_typedArrays[toIndex(TypeUint16)].structure.set(vm, this, JSUint16Array::createStructure(vm, this, m_typedArrays[toIndex(TypeUint16)].prototype.get()));
339     m_typedArrays[toIndex(TypeUint32)].structure.set(vm, this, JSUint32Array::createStructure(vm, this, m_typedArrays[toIndex(TypeUint32)].prototype.get()));
340     m_typedArrays[toIndex(TypeFloat32)].structure.set(vm, this, JSFloat32Array::createStructure(vm, this, m_typedArrays[toIndex(TypeFloat32)].prototype.get()));
341     m_typedArrays[toIndex(TypeFloat64)].structure.set(vm, this, JSFloat64Array::createStructure(vm, this, m_typedArrays[toIndex(TypeFloat64)].prototype.get()));
342     m_typedArrays[toIndex(TypeDataView)].structure.set(vm, this, JSDataView::createStructure(vm, this, m_typedArrays[toIndex(TypeDataView)].prototype.get()));
343     
344     m_lexicalEnvironmentStructure.set(vm, this, JSLexicalEnvironment::createStructure(vm, this));
345     m_moduleEnvironmentStructure.set(vm, this, JSModuleEnvironment::createStructure(vm, this));
346     m_strictEvalActivationStructure.set(vm, this, StrictEvalActivation::createStructure(vm, this, jsNull()));
347     m_debuggerScopeStructure.set(m_vm, this, DebuggerScope::createStructure(m_vm, this));
348     m_withScopeStructure.set(vm, this, JSWithScope::createStructure(vm, this, jsNull()));
349     
350     m_nullPrototypeObjectStructure.set(vm, this, JSFinalObject::createStructure(vm, this, jsNull(), JSFinalObject::defaultInlineCapacity()));
351     
352     m_callbackFunctionStructure.set(vm, this, JSCallbackFunction::createStructure(vm, this, m_functionPrototype.get()));
353     m_directArgumentsStructure.set(vm, this, DirectArguments::createStructure(vm, this, m_objectPrototype.get()));
354     m_scopedArgumentsStructure.set(vm, this, ScopedArguments::createStructure(vm, this, m_objectPrototype.get()));
355     m_clonedArgumentsStructure.set(vm, this, ClonedArguments::createStructure(vm, this, m_objectPrototype.get()));
356     m_callbackConstructorStructure.set(vm, this, JSCallbackConstructor::createStructure(vm, this, m_objectPrototype.get()));
357     m_callbackObjectStructure.set(vm, this, JSCallbackObject<JSDestructibleObject>::createStructure(vm, this, m_objectPrototype.get()));
358
359 #if JSC_OBJC_API_ENABLED
360     m_objcCallbackFunctionStructure.set(vm, this, ObjCCallbackFunction::createStructure(vm, this, m_functionPrototype.get()));
361     m_objcWrapperObjectStructure.set(vm, this, JSCallbackObject<JSAPIWrapperObject>::createStructure(vm, this, m_objectPrototype.get()));
362 #endif
363     
364     m_arrayPrototype.set(vm, this, ArrayPrototype::create(vm, this, ArrayPrototype::createStructure(vm, this, m_objectPrototype.get())));
365     
366     m_originalArrayStructureForIndexingShape[UndecidedShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithUndecided));
367     m_originalArrayStructureForIndexingShape[Int32Shape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithInt32));
368     m_originalArrayStructureForIndexingShape[DoubleShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithDouble));
369     m_originalArrayStructureForIndexingShape[ContiguousShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithContiguous));
370     m_originalArrayStructureForIndexingShape[ArrayStorageShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithArrayStorage));
371     m_originalArrayStructureForIndexingShape[SlowPutArrayStorageShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithSlowPutArrayStorage));
372     for (unsigned i = 0; i < NumberOfIndexingShapes; ++i)
373         m_arrayStructureForIndexingShapeDuringAllocation[i] = m_originalArrayStructureForIndexingShape[i];
374
375     m_regExpPrototype.set(vm, this, RegExpPrototype::create(vm, this, RegExpPrototype::createStructure(vm, this, m_objectPrototype.get())));
376     m_regExpStructure.set(vm, this, RegExpObject::createStructure(vm, this, m_regExpPrototype.get()));
377     m_regExpMatchesArrayStructure.set(vm, this, createRegExpMatchesArrayStructure(vm, this));
378     m_regExpMatchesArraySlowPutStructure.set(vm, this, createRegExpMatchesArraySlowPutStructure(vm, this));
379
380     m_moduleRecordStructure.set(vm, this, JSModuleRecord::createStructure(vm, this, m_objectPrototype.get()));
381     m_moduleNamespaceObjectStructure.set(vm, this, JSModuleNamespaceObject::createStructure(vm, this, jsNull()));
382     {
383         bool isCallable = false;
384         m_proxyObjectStructure.set(vm, this, ProxyObject::createStructure(vm, this, m_objectPrototype.get(), isCallable));
385         isCallable = true;
386         m_callableProxyObjectStructure.set(vm, this, ProxyObject::createStructure(vm, this, m_objectPrototype.get(), isCallable));
387     }
388     m_proxyRevokeStructure.set(vm, this, ProxyRevoke::createStructure(vm, this, m_functionPrototype.get()));
389     
390 #if ENABLE(WEBASSEMBLY)
391     m_wasmModuleStructure.set(vm, this, JSWASMModule::createStructure(vm, this));
392 #endif
393
394     m_parseIntFunction.set(vm, this, JSFunction::create(vm, this, 2, vm.propertyNames->parseInt.string(), globalFuncParseInt, NoIntrinsic));
395     putDirectWithoutTransition(vm, vm.propertyNames->parseInt, m_parseIntFunction.get(), DontEnum);
396
397 #define CREATE_PROTOTYPE_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName) \
398 m_ ## lowerName ## Prototype.set(vm, this, capitalName##Prototype::create(vm, this, capitalName##Prototype::createStructure(vm, this, m_objectPrototype.get()))); \
399 m_ ## properName ## Structure.set(vm, this, instanceType::createStructure(vm, this, m_ ## lowerName ## Prototype.get()));
400     
401     FOR_EACH_SIMPLE_BUILTIN_TYPE(CREATE_PROTOTYPE_FOR_SIMPLE_TYPE)
402     
403 #undef CREATE_PROTOTYPE_FOR_SIMPLE_TYPE
404
405     m_iteratorPrototype.set(vm, this, IteratorPrototype::create(vm, this, IteratorPrototype::createStructure(vm, this, m_objectPrototype.get())));
406
407 #define CREATE_PROTOTYPE_FOR_DERIVED_ITERATOR_TYPE(capitalName, lowerName, properName, instanceType, jsName) \
408 m_ ## lowerName ## Prototype.set(vm, this, capitalName##Prototype::create(vm, this, capitalName##Prototype::createStructure(vm, this, m_iteratorPrototype.get()))); \
409 m_ ## properName ## Structure.set(vm, this, instanceType::createStructure(vm, this, m_ ## lowerName ## Prototype.get()));
410     
411     FOR_EACH_BUILTIN_DERIVED_ITERATOR_TYPE(CREATE_PROTOTYPE_FOR_DERIVED_ITERATOR_TYPE)
412     m_propertyNameIteratorStructure.set(vm, this, JSPropertyNameIterator::createStructure(vm, this, m_iteratorPrototype.get()));
413     m_generatorPrototype.set(vm, this, GeneratorPrototype::create(vm, this, GeneratorPrototype::createStructure(vm, this, m_iteratorPrototype.get())));
414     
415 #undef CREATE_PROTOTYPE_FOR_DERIVED_ITERATOR_TYPE
416
417     // Constructors
418
419     GetterSetter* speciesGetterSetter = GetterSetter::create(vm, this);
420     speciesGetterSetter->setGetter(vm, this, JSFunction::createBuiltinFunction(vm, globalObjectSpeciesGetterCodeGenerator(vm), this, "get [Symbol.species]"));
421
422     ObjectConstructor* objectConstructor = ObjectConstructor::create(vm, this, ObjectConstructor::createStructure(vm, this, m_functionPrototype.get()), m_objectPrototype.get());
423     m_objectConstructor.set(vm, this, objectConstructor);
424
425     JSFunction* definePropertyFunction = m_objectConstructor->addDefineProperty(exec, this);
426     m_definePropertyFunction.set(vm, this, definePropertyFunction);
427
428     JSCell* functionConstructor = FunctionConstructor::create(vm, FunctionConstructor::createStructure(vm, this, m_functionPrototype.get()), m_functionPrototype.get());
429     JSObject* arrayConstructor = ArrayConstructor::create(vm, this, ArrayConstructor::createStructure(vm, this, m_functionPrototype.get()), m_arrayPrototype.get(), speciesGetterSetter);
430     
431     m_regExpConstructor.set(vm, this, RegExpConstructor::create(vm, RegExpConstructor::createStructure(vm, this, m_functionPrototype.get()), m_regExpPrototype.get(), speciesGetterSetter));
432     
433 #define CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName) \
434 capitalName ## Constructor* lowerName ## Constructor = capitalName ## Constructor::create(vm, capitalName ## Constructor::createStructure(vm, this, m_functionPrototype.get()), m_ ## lowerName ## Prototype.get(), speciesGetterSetter); \
435 m_ ## lowerName ## Prototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, lowerName ## Constructor, DontEnum); \
436
437     FOR_EACH_SIMPLE_BUILTIN_TYPE(CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE)
438     
439 #undef CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE
440     
441     m_errorConstructor.set(vm, this, errorConstructor);
442     m_promiseConstructor.set(vm, this, promiseConstructor);
443     m_internalPromiseConstructor.set(vm, this, internalPromiseConstructor);
444     
445     Structure* nativeErrorPrototypeStructure = NativeErrorPrototype::createStructure(vm, this, m_errorPrototype.get());
446     Structure* nativeErrorStructure = NativeErrorConstructor::createStructure(vm, this, m_functionPrototype.get());
447     m_evalErrorConstructor.set(vm, this, NativeErrorConstructor::create(vm, this, nativeErrorStructure, nativeErrorPrototypeStructure, ASCIILiteral("EvalError")));
448     m_rangeErrorConstructor.set(vm, this, NativeErrorConstructor::create(vm, this, nativeErrorStructure, nativeErrorPrototypeStructure, ASCIILiteral("RangeError")));
449     m_referenceErrorConstructor.set(vm, this, NativeErrorConstructor::create(vm, this, nativeErrorStructure, nativeErrorPrototypeStructure, ASCIILiteral("ReferenceError")));
450     m_syntaxErrorConstructor.set(vm, this, NativeErrorConstructor::create(vm, this, nativeErrorStructure, nativeErrorPrototypeStructure, ASCIILiteral("SyntaxError")));
451     m_typeErrorConstructor.set(vm, this, NativeErrorConstructor::create(vm, this, nativeErrorStructure, nativeErrorPrototypeStructure, ASCIILiteral("TypeError")));
452     m_URIErrorConstructor.set(vm, this, NativeErrorConstructor::create(vm, this, nativeErrorStructure, nativeErrorPrototypeStructure, ASCIILiteral("URIError")));
453
454     m_generatorFunctionPrototype.set(vm, this, GeneratorFunctionPrototype::create(vm, GeneratorFunctionPrototype::createStructure(vm, this, m_functionPrototype.get())));
455     GeneratorFunctionConstructor* generatorFunctionConstructor = GeneratorFunctionConstructor::create(vm, GeneratorFunctionConstructor::createStructure(vm, this, functionConstructor), m_generatorFunctionPrototype.get());
456     m_generatorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, generatorFunctionConstructor, DontEnum);
457     m_generatorFunctionStructure.set(vm, this, JSGeneratorFunction::createStructure(vm, this, m_generatorFunctionPrototype.get()));
458
459     m_generatorPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_generatorFunctionPrototype.get(), DontEnum);
460     m_generatorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->prototype, m_generatorPrototype.get(), DontEnum);
461     
462     m_objectPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, objectConstructor, DontEnum);
463     m_functionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, functionConstructor, DontEnum);
464     m_arrayPrototype->setConstructor(vm, arrayConstructor, DontEnum);
465     m_regExpPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_regExpConstructor.get(), DontEnum);
466     
467     putDirectWithoutTransition(vm, vm.propertyNames->Object, objectConstructor, DontEnum);
468     putDirectWithoutTransition(vm, vm.propertyNames->Function, functionConstructor, DontEnum);
469     putDirectWithoutTransition(vm, vm.propertyNames->Array, arrayConstructor, DontEnum);
470     putDirectWithoutTransition(vm, vm.propertyNames->RegExp, m_regExpConstructor.get(), DontEnum);
471     putDirectWithoutTransition(vm, vm.propertyNames->EvalError, m_evalErrorConstructor.get(), DontEnum);
472     putDirectWithoutTransition(vm, vm.propertyNames->RangeError, m_rangeErrorConstructor.get(), DontEnum);
473     putDirectWithoutTransition(vm, vm.propertyNames->ReferenceError, m_referenceErrorConstructor.get(), DontEnum);
474     putDirectWithoutTransition(vm, vm.propertyNames->SyntaxError, m_syntaxErrorConstructor.get(), DontEnum);
475     putDirectWithoutTransition(vm, vm.propertyNames->TypeError, m_typeErrorConstructor.get(), DontEnum);
476     putDirectWithoutTransition(vm, vm.propertyNames->URIError, m_URIErrorConstructor.get(), DontEnum);
477
478     putDirectWithoutTransition(vm, vm.propertyNames->Proxy, ProxyConstructor::create(vm, ProxyConstructor::createStructure(vm, this, m_functionPrototype.get())), DontEnum);
479     
480     
481 #define PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName) \
482 putDirectWithoutTransition(vm, vm.propertyNames-> jsName, lowerName ## Constructor, DontEnum); \
483
484     FOR_EACH_SIMPLE_BUILTIN_TYPE_WITH_CONSTRUCTOR(PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE)
485
486 #undef PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE
487     m_iteratorResultObjectStructure.set(vm, this, createIteratorResultObjectStructure(vm, *this));
488     
489     m_evalFunction.set(vm, this, JSFunction::create(vm, this, 1, vm.propertyNames->eval.string(), globalFuncEval));
490     putDirectWithoutTransition(vm, vm.propertyNames->eval, m_evalFunction.get(), DontEnum);
491     
492 #if ENABLE(INTL)
493     IntlObject* intl = IntlObject::create(vm, this, IntlObject::createStructure(vm, this, m_objectPrototype.get()));
494     putDirectWithoutTransition(vm, vm.propertyNames->Intl, intl, DontEnum);
495 #endif // ENABLE(INTL)
496     putDirectWithoutTransition(vm, vm.propertyNames->JSON, JSONObject::create(vm, JSONObject::createStructure(vm, this, m_objectPrototype.get())), DontEnum);
497     putDirectWithoutTransition(vm, vm.propertyNames->Math, MathObject::create(vm, this, MathObject::createStructure(vm, this, m_objectPrototype.get())), DontEnum);
498     ReflectObject* reflectObject = ReflectObject::create(vm, this, ReflectObject::createStructure(vm, this, m_objectPrototype.get()));
499     putDirectWithoutTransition(vm, vm.propertyNames->Reflect, reflectObject, DontEnum);
500
501     JSTypedArrayViewConstructor* typedArraySuperConstructor = JSTypedArrayViewConstructor::create(vm, this, JSTypedArrayViewConstructor::createStructure(vm, this, m_functionPrototype.get()), typedArrayProto, speciesGetterSetter);
502     typedArrayProto->putDirectWithoutTransition(vm, vm.propertyNames->constructor, typedArraySuperConstructor, DontEnum);
503
504     m_typedArrays[toIndex(TypeInt8)].constructor.set(vm , this, JSInt8ArrayConstructor::create(vm, this, JSInt8ArrayConstructor::createStructure(vm, this, typedArraySuperConstructor), m_typedArrays[toIndex(TypeInt8)].prototype.get(), ASCIILiteral("Int8Array"), typedArrayConstructorAllocateInt8ArrayCodeGenerator(vm)));
505     m_typedArrays[toIndex(TypeInt16)].constructor.set(vm, this, JSInt16ArrayConstructor::create(vm, this, JSInt16ArrayConstructor::createStructure(vm, this, typedArraySuperConstructor), m_typedArrays[toIndex(TypeInt16)].prototype.get(), ASCIILiteral("Int16Array"), typedArrayConstructorAllocateInt16ArrayCodeGenerator(vm)));
506     m_typedArrays[toIndex(TypeInt32)].constructor.set(vm, this, JSInt32ArrayConstructor::create(vm, this, JSInt32ArrayConstructor::createStructure(vm, this, typedArraySuperConstructor), m_typedArrays[toIndex(TypeInt32)].prototype.get(), ASCIILiteral("Int32Array"), typedArrayConstructorAllocateInt32ArrayCodeGenerator(vm)));
507     m_typedArrays[toIndex(TypeUint8)].constructor.set(vm, this, JSUint8ArrayConstructor::create(vm, this, JSUint8ArrayConstructor::createStructure(vm, this, typedArraySuperConstructor), m_typedArrays[toIndex(TypeUint8)].prototype.get(), ASCIILiteral("Uint8Array"), typedArrayConstructorAllocateUint8ArrayCodeGenerator(vm)));
508     m_typedArrays[toIndex(TypeUint8Clamped)].constructor.set(vm, this, JSUint8ClampedArrayConstructor::create(vm, this, JSUint8ClampedArrayConstructor::createStructure(vm, this, typedArraySuperConstructor), m_typedArrays[toIndex(TypeUint8Clamped)].prototype.get(), ASCIILiteral("Uint8ClampedArray"), typedArrayConstructorAllocateUint8ClampedArrayCodeGenerator(vm)));
509     m_typedArrays[toIndex(TypeUint16)].constructor.set(vm, this, JSUint16ArrayConstructor::create(vm, this, JSUint16ArrayConstructor::createStructure(vm, this, typedArraySuperConstructor), m_typedArrays[toIndex(TypeUint16)].prototype.get(), ASCIILiteral("Uint16Array"), typedArrayConstructorAllocateUint16ArrayCodeGenerator(vm)));
510     m_typedArrays[toIndex(TypeUint32)].constructor.set(vm, this, JSUint32ArrayConstructor::create(vm, this, JSUint32ArrayConstructor::createStructure(vm, this, typedArraySuperConstructor), m_typedArrays[toIndex(TypeUint32)].prototype.get(), ASCIILiteral("Uint32Array"), typedArrayConstructorAllocateUint32ArrayCodeGenerator(vm)));
511     m_typedArrays[toIndex(TypeFloat32)].constructor.set(vm, this, JSFloat32ArrayConstructor::create(vm, this, JSFloat32ArrayConstructor::createStructure(vm, this, typedArraySuperConstructor), m_typedArrays[toIndex(TypeFloat32)].prototype.get(), ASCIILiteral("Float32Array"), typedArrayConstructorAllocateFloat32ArrayCodeGenerator(vm)));
512     m_typedArrays[toIndex(TypeFloat64)].constructor.set(vm, this, JSFloat64ArrayConstructor::create(vm, this, JSFloat64ArrayConstructor::createStructure(vm, this, typedArraySuperConstructor), m_typedArrays[toIndex(TypeFloat64)].prototype.get(), ASCIILiteral("Float64Array"), typedArrayConstructorAllocateFloat64ArrayCodeGenerator(vm)));
513     m_typedArrays[toIndex(TypeDataView)].constructor.set(vm, this, JSDataViewConstructor::create(vm, this, JSDataViewConstructor::createStructure(vm, this, m_functionPrototype.get()), m_typedArrays[toIndex(TypeDataView)].prototype.get(), ASCIILiteral("DataView"), nullptr));
514     
515     for (unsigned typedArrayIndex = NUMBER_OF_TYPED_ARRAY_TYPES; typedArrayIndex--;) {
516         m_typedArrays[typedArrayIndex].prototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_typedArrays[typedArrayIndex].constructor.get(), DontEnum);
517         putDirectWithoutTransition(vm, Identifier::fromString(exec, m_typedArrays[typedArrayIndex].constructor.get()->name(exec)), m_typedArrays[typedArrayIndex].constructor.get(), DontEnum);
518     }
519
520     putDirectWithoutTransition(vm, vm.propertyNames->Int8ArrayPrivateName, m_typedArrays[toIndex(TypeInt8)].constructor.get(), DontEnum);
521     putDirectWithoutTransition(vm, vm.propertyNames->Int16ArrayPrivateName, m_typedArrays[toIndex(TypeInt16)].constructor.get(), DontEnum);
522     putDirectWithoutTransition(vm, vm.propertyNames->Int32ArrayPrivateName, m_typedArrays[toIndex(TypeInt32)].constructor.get(), DontEnum);
523     putDirectWithoutTransition(vm, vm.propertyNames->Uint8ArrayPrivateName, m_typedArrays[toIndex(TypeUint8)].constructor.get(), DontEnum);
524     putDirectWithoutTransition(vm, vm.propertyNames->Uint8ClampedArrayPrivateName, m_typedArrays[toIndex(TypeUint8Clamped)].constructor.get(), DontEnum);
525     putDirectWithoutTransition(vm, vm.propertyNames->Uint16ArrayPrivateName, m_typedArrays[toIndex(TypeUint16)].constructor.get(), DontEnum);
526     putDirectWithoutTransition(vm, vm.propertyNames->Uint32ArrayPrivateName, m_typedArrays[toIndex(TypeUint32)].constructor.get(), DontEnum);
527     putDirectWithoutTransition(vm, vm.propertyNames->Float32ArrayPrivateName, m_typedArrays[toIndex(TypeFloat32)].constructor.get(), DontEnum);
528     putDirectWithoutTransition(vm, vm.propertyNames->Float64ArrayPrivateName, m_typedArrays[toIndex(TypeFloat64)].constructor.get(), DontEnum);
529
530     m_moduleLoader.set(vm, this, ModuleLoaderObject::create(vm, this, ModuleLoaderObject::createStructure(vm, this, m_objectPrototype.get())));
531     if (Options::exposeInternalModuleLoader())
532         putDirectWithoutTransition(vm, vm.propertyNames->Loader, m_moduleLoader.get(), DontEnum);
533
534     JSFunction* builtinLog = JSFunction::create(vm, this, 1, vm.propertyNames->emptyIdentifier.string(), globalFuncBuiltinLog);
535
536     JSFunction* privateFuncAbs = JSFunction::create(vm, this, 0, String(), mathProtoFuncAbs, AbsIntrinsic);
537     JSFunction* privateFuncFloor = JSFunction::create(vm, this, 0, String(), mathProtoFuncFloor, FloorIntrinsic);
538     JSFunction* privateFuncIsFinite = JSFunction::create(vm, this, 0, String(), globalFuncIsFinite);
539     JSFunction* privateFuncIsNaN = JSFunction::create(vm, this, 0, String(), globalFuncIsNaN);
540     JSFunction* privateFuncTrunc = JSFunction::create(vm, this, 0, String(), mathProtoFuncTrunc, TruncIntrinsic);
541
542     JSFunction* privateFuncGetTemplateObject = JSFunction::create(vm, this, 0, String(), getTemplateObject);
543     JSFunction* privateFuncToLength = JSFunction::createBuiltinFunction(vm, globalObjectToLengthCodeGenerator(vm), this);
544     JSFunction* privateFuncToInteger = JSFunction::createBuiltinFunction(vm, globalObjectToIntegerCodeGenerator(vm), this);
545     JSFunction* privateFuncTypedArrayLength = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncLength);
546     JSFunction* privateFuncTypedArrayGetOriginalConstructor = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncGetOriginalConstructor);
547     JSFunction* privateFuncTypedArraySort = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncSort);
548     JSFunction* privateFuncIsBoundFunction = JSFunction::create(vm, this, 0, String(), isBoundFunction);
549     JSFunction* privateFuncHasInstanceBoundFunction = JSFunction::create(vm, this, 0, String(), hasInstanceBoundFunction);
550     JSFunction* privateFuncInstanceOf = JSFunction::create(vm, this, 0, String(), objectPrivateFuncInstanceOf);
551     JSFunction* privateFuncThisTimeValue = JSFunction::create(vm, this, 0, String(), dateProtoFuncGetTime);
552     JSFunction* privateFuncThisNumberValue = JSFunction::create(vm, this, 0, String(), numberProtoFuncValueOf);
553     JSFunction* privateFuncIsArrayConstructor = JSFunction::create(vm, this, 0, String(), arrayConstructorPrivateFuncIsArrayConstructor);
554
555     JSObject* regExpProtoFlagsGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->flags);
556     JSObject* regExpProtoGlobalGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->global);
557     m_regExpProtoGlobalGetter.set(vm, this, regExpProtoGlobalGetterObject);
558     JSObject* regExpProtoIgnoreCaseGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->ignoreCase);
559     JSObject* regExpProtoMultilineGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->multiline);
560     JSObject* regExpProtoSourceGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->source);
561     JSObject* regExpProtoStickyGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->sticky);
562     JSObject* regExpProtoUnicodeGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->unicode);
563     m_regExpProtoUnicodeGetter.set(vm, this, regExpProtoUnicodeGetterObject);
564     JSObject* builtinRegExpExec = asObject(m_regExpPrototype->getDirect(vm, vm.propertyNames->exec).asCell());
565     m_regExpProtoExec.set(vm, this, builtinRegExpExec);
566     JSObject* regExpSymbolReplace = asObject(m_regExpPrototype->getDirect(vm, vm.propertyNames->replaceSymbol).asCell());
567     m_regExpProtoSymbolReplace.set(vm, this, regExpSymbolReplace);
568
569     GlobalPropertyInfo staticGlobals[] = {
570         GlobalPropertyInfo(vm.propertyNames->NaN, jsNaN(), DontEnum | DontDelete | ReadOnly),
571         GlobalPropertyInfo(vm.propertyNames->Infinity, jsNumber(std::numeric_limits<double>::infinity()), DontEnum | DontDelete | ReadOnly),
572         GlobalPropertyInfo(vm.propertyNames->undefinedKeyword, jsUndefined(), DontEnum | DontDelete | ReadOnly),
573         GlobalPropertyInfo(vm.propertyNames->ObjectPrivateName, objectConstructor, DontEnum | DontDelete | ReadOnly),
574         GlobalPropertyInfo(vm.propertyNames->ownEnumerablePropertyKeysPrivateName, JSFunction::create(vm, this, 0, String(), ownEnumerablePropertyKeys), DontEnum | DontDelete | ReadOnly),
575         GlobalPropertyInfo(vm.propertyNames->getTemplateObjectPrivateName, privateFuncGetTemplateObject, DontEnum | DontDelete | ReadOnly),
576         GlobalPropertyInfo(vm.propertyNames->enqueueJobPrivateName, JSFunction::create(vm, this, 0, String(), enqueueJob), DontEnum | DontDelete | ReadOnly),
577         GlobalPropertyInfo(vm.propertyNames->ErrorPrivateName, m_errorConstructor.get(), DontEnum | DontDelete | ReadOnly),
578         GlobalPropertyInfo(vm.propertyNames->RangeErrorPrivateName, m_rangeErrorConstructor.get(), DontEnum | DontDelete | ReadOnly),
579         GlobalPropertyInfo(vm.propertyNames->TypeErrorPrivateName, m_typeErrorConstructor.get(), DontEnum | DontDelete | ReadOnly),
580         GlobalPropertyInfo(vm.propertyNames->typedArrayLengthPrivateName, privateFuncTypedArrayLength, DontEnum | DontDelete | ReadOnly),
581         GlobalPropertyInfo(vm.propertyNames->typedArrayGetOriginalConstructorPrivateName, privateFuncTypedArrayGetOriginalConstructor, DontEnum | DontDelete | ReadOnly),
582         GlobalPropertyInfo(vm.propertyNames->typedArraySortPrivateName, privateFuncTypedArraySort, DontEnum | DontDelete | ReadOnly),
583         GlobalPropertyInfo(vm.propertyNames->isBoundFunctionPrivateName, privateFuncIsBoundFunction, DontEnum | DontDelete | ReadOnly),
584         GlobalPropertyInfo(vm.propertyNames->hasInstanceBoundFunctionPrivateName, privateFuncHasInstanceBoundFunction, DontEnum | DontDelete | ReadOnly),
585         GlobalPropertyInfo(vm.propertyNames->instanceOfPrivateName, privateFuncInstanceOf, DontEnum | DontDelete | ReadOnly),
586         GlobalPropertyInfo(vm.propertyNames->BuiltinLogPrivateName, builtinLog, DontEnum | DontDelete | ReadOnly),
587         GlobalPropertyInfo(vm.propertyNames->ArrayPrivateName, arrayConstructor, DontEnum | DontDelete | ReadOnly),
588         GlobalPropertyInfo(vm.propertyNames->NumberPrivateName, numberConstructor, DontEnum | DontDelete | ReadOnly),
589         GlobalPropertyInfo(vm.propertyNames->RegExpPrivateName, m_regExpConstructor.get(), DontEnum | DontDelete | ReadOnly),
590         GlobalPropertyInfo(vm.propertyNames->StringPrivateName, stringConstructor, DontEnum | DontDelete | ReadOnly),
591         GlobalPropertyInfo(vm.propertyNames->absPrivateName, privateFuncAbs, DontEnum | DontDelete | ReadOnly),
592         GlobalPropertyInfo(vm.propertyNames->floorPrivateName, privateFuncFloor, DontEnum | DontDelete | ReadOnly),
593         GlobalPropertyInfo(vm.propertyNames->truncPrivateName, privateFuncTrunc, DontEnum | DontDelete | ReadOnly),
594         GlobalPropertyInfo(vm.propertyNames->isFinitePrivateName, privateFuncIsFinite, DontEnum | DontDelete | ReadOnly),
595         GlobalPropertyInfo(vm.propertyNames->isNaNPrivateName, privateFuncIsNaN, DontEnum | DontDelete | ReadOnly),
596         GlobalPropertyInfo(vm.propertyNames->PromisePrivateName, promiseConstructor, DontEnum | DontDelete | ReadOnly),
597         GlobalPropertyInfo(vm.propertyNames->ReflectPrivateName, reflectObject, DontEnum | DontDelete | ReadOnly),
598         GlobalPropertyInfo(vm.propertyNames->InternalPromisePrivateName, internalPromiseConstructor, DontEnum | DontDelete | ReadOnly),
599
600         GlobalPropertyInfo(vm.propertyNames->repeatCharacterPrivateName, JSFunction::create(vm, this, 2, String(), stringProtoFuncRepeatCharacter), DontEnum | DontDelete | ReadOnly),
601         GlobalPropertyInfo(vm.propertyNames->builtinNames().repeatSlowPathPrivateName(), JSFunction::createBuiltinFunction(vm, stringPrototypeRepeatSlowPathCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
602         GlobalPropertyInfo(vm.propertyNames->builtinNames().repeatCharactersSlowPathPrivateName(), JSFunction::createBuiltinFunction(vm, stringPrototypeRepeatCharactersSlowPathCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
603
604         GlobalPropertyInfo(vm.propertyNames->isSetPrivateName, JSFunction::create(vm, this, 1, String(), privateFuncIsSet), DontEnum | DontDelete | ReadOnly),
605         GlobalPropertyInfo(vm.propertyNames->SetIteratorPrivateName, JSFunction::create(vm, this, 1, String(), privateFuncSetIterator), DontEnum | DontDelete | ReadOnly),
606         GlobalPropertyInfo(vm.propertyNames->setIteratorNextPrivateName, JSFunction::create(vm, this, 0, String(), privateFuncSetIteratorNext), DontEnum | DontDelete | ReadOnly),
607         GlobalPropertyInfo(vm.propertyNames->isMapPrivateName, JSFunction::create(vm, this, 1, String(), privateFuncIsMap), DontEnum | DontDelete | ReadOnly),
608         GlobalPropertyInfo(vm.propertyNames->isArrayPrivateName, arrayConstructor->getDirect(vm, vm.propertyNames->isArray), DontEnum | DontDelete | ReadOnly),
609         GlobalPropertyInfo(vm.propertyNames->isArrayConstructorPrivateName, privateFuncIsArrayConstructor, DontEnum | DontDelete | ReadOnly),
610         GlobalPropertyInfo(vm.propertyNames->MapIteratorPrivateName, JSFunction::create(vm, this, 1, String(), privateFuncMapIterator), DontEnum | DontDelete | ReadOnly),
611         GlobalPropertyInfo(vm.propertyNames->mapIteratorNextPrivateName, JSFunction::create(vm, this, 0, String(), privateFuncMapIteratorNext), DontEnum | DontDelete | ReadOnly),
612
613         GlobalPropertyInfo(vm.propertyNames->builtinNames().toLengthPrivateName(), privateFuncToLength, DontEnum | DontDelete | ReadOnly),
614         GlobalPropertyInfo(vm.propertyNames->builtinNames().toIntegerPrivateName(), privateFuncToInteger, DontEnum | DontDelete | ReadOnly),
615         GlobalPropertyInfo(vm.propertyNames->builtinNames().isDictionaryPrivateName(), JSFunction::createBuiltinFunction(vm, globalObjectIsDictionaryCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
616         GlobalPropertyInfo(vm.propertyNames->builtinNames().isPromisePrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsIsPromiseCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
617         GlobalPropertyInfo(vm.propertyNames->builtinNames().newPromiseReactionPrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsNewPromiseReactionCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
618         GlobalPropertyInfo(vm.propertyNames->builtinNames().newPromiseCapabilityPrivateName(), m_newPromiseCapabilityFunction.get(), DontEnum | DontDelete | ReadOnly),
619         GlobalPropertyInfo(vm.propertyNames->builtinNames().triggerPromiseReactionsPrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsTriggerPromiseReactionsCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
620         GlobalPropertyInfo(vm.propertyNames->builtinNames().rejectPromisePrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsRejectPromiseCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
621         GlobalPropertyInfo(vm.propertyNames->builtinNames().fulfillPromisePrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsFulfillPromiseCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
622         GlobalPropertyInfo(vm.propertyNames->builtinNames().createResolvingFunctionsPrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsCreateResolvingFunctionsCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
623         GlobalPropertyInfo(vm.propertyNames->builtinNames().promiseReactionJobPrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsPromiseReactionJobCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
624         GlobalPropertyInfo(vm.propertyNames->builtinNames().promiseResolveThenableJobPrivateName(), JSFunction::createBuiltinFunction(vm, promiseOperationsPromiseResolveThenableJobCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
625         GlobalPropertyInfo(vm.propertyNames->builtinNames().InspectorInstrumentationPrivateName(), InspectorInstrumentationObject::create(vm, this, InspectorInstrumentationObject::createStructure(vm, this, m_objectPrototype.get())), DontEnum | DontDelete | ReadOnly),
626         GlobalPropertyInfo(vm.propertyNames->MapPrivateName, mapConstructor, DontEnum | DontDelete | ReadOnly),
627         GlobalPropertyInfo(vm.propertyNames->builtinNames().generatorResumePrivateName(), JSFunction::createBuiltinFunction(vm, generatorPrototypeGeneratorResumeCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
628         GlobalPropertyInfo(vm.propertyNames->builtinNames().thisTimeValuePrivateName(), privateFuncThisTimeValue, DontEnum | DontDelete | ReadOnly),
629         GlobalPropertyInfo(vm.propertyNames->builtinNames().thisNumberValuePrivateName(), privateFuncThisNumberValue, DontEnum | DontDelete | ReadOnly),
630 #if ENABLE(INTL)
631         GlobalPropertyInfo(vm.propertyNames->builtinNames().CollatorPrivateName(), intl->getDirect(vm, vm.propertyNames->Collator), DontEnum | DontDelete | ReadOnly),
632         GlobalPropertyInfo(vm.propertyNames->builtinNames().DateTimeFormatPrivateName(), intl->getDirect(vm, vm.propertyNames->DateTimeFormat), DontEnum | DontDelete | ReadOnly),
633         GlobalPropertyInfo(vm.propertyNames->builtinNames().NumberFormatPrivateName(), intl->getDirect(vm, vm.propertyNames->NumberFormat), DontEnum | DontDelete | ReadOnly),
634 #endif // ENABLE(INTL)
635
636         GlobalPropertyInfo(vm.propertyNames->isConstructorPrivateName, JSFunction::create(vm, this, 1, String(), esSpecIsConstructor, NoIntrinsic), DontEnum | DontDelete | ReadOnly),
637         GlobalPropertyInfo(vm.propertyNames->isRegExpObjectPrivateName, JSFunction::create(vm, this, 1, String(), esSpecIsRegExpObject, IsRegExpObjectIntrinsic), DontEnum | DontDelete | ReadOnly),
638         GlobalPropertyInfo(vm.propertyNames->builtinNames().speciesConstructorPrivateName(), JSFunction::createBuiltinFunction(vm, globalObjectSpeciesConstructorCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
639
640         GlobalPropertyInfo(vm.propertyNames->regExpProtoFlagsGetterPrivateName, regExpProtoFlagsGetterObject, DontEnum | DontDelete | ReadOnly),
641         GlobalPropertyInfo(vm.propertyNames->regExpProtoGlobalGetterPrivateName, regExpProtoGlobalGetterObject, DontEnum | DontDelete | ReadOnly),
642         GlobalPropertyInfo(vm.propertyNames->regExpProtoIgnoreCaseGetterPrivateName, regExpProtoIgnoreCaseGetterObject, DontEnum | DontDelete | ReadOnly),
643         GlobalPropertyInfo(vm.propertyNames->regExpProtoMultilineGetterPrivateName, regExpProtoMultilineGetterObject, DontEnum | DontDelete | ReadOnly),
644         GlobalPropertyInfo(vm.propertyNames->regExpProtoSourceGetterPrivateName, regExpProtoSourceGetterObject, DontEnum | DontDelete | ReadOnly),
645         GlobalPropertyInfo(vm.propertyNames->regExpProtoStickyGetterPrivateName, regExpProtoStickyGetterObject, DontEnum | DontDelete | ReadOnly),
646         GlobalPropertyInfo(vm.propertyNames->regExpProtoUnicodeGetterPrivateName, regExpProtoUnicodeGetterObject, DontEnum | DontDelete | ReadOnly),
647
648         // RegExp.prototype helpers.
649         GlobalPropertyInfo(vm.propertyNames->regExpBuiltinExecPrivateName, builtinRegExpExec, DontEnum | DontDelete | ReadOnly),
650         GlobalPropertyInfo(vm.propertyNames->regExpCreatePrivateName, JSFunction::create(vm, this, 2, String(), esSpecRegExpCreate, NoIntrinsic), DontEnum | DontDelete | ReadOnly),
651         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasObservableSideEffectsForRegExpMatchPrivateName(), JSFunction::createBuiltinFunction(vm, regExpPrototypeHasObservableSideEffectsForRegExpMatchCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
652         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasObservableSideEffectsForRegExpSplitPrivateName(), JSFunction::createBuiltinFunction(vm, regExpPrototypeHasObservableSideEffectsForRegExpSplitCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
653         GlobalPropertyInfo(vm.propertyNames->builtinNames().advanceStringIndexPrivateName(), JSFunction::createBuiltinFunction(vm, regExpPrototypeAdvanceStringIndexCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
654         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpExecPrivateName(), JSFunction::createBuiltinFunction(vm, regExpPrototypeRegExpExecCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
655         GlobalPropertyInfo(vm.propertyNames->regExpMatchFastPrivateName, JSFunction::create(vm, this, 1, String(), regExpProtoFuncMatchFast), DontEnum | DontDelete | ReadOnly),
656         GlobalPropertyInfo(vm.propertyNames->regExpSearchFastPrivateName, JSFunction::create(vm, this, 1, String(), regExpProtoFuncSearchFast), DontEnum | DontDelete | ReadOnly),
657         GlobalPropertyInfo(vm.propertyNames->regExpSplitFastPrivateName, JSFunction::create(vm, this, 2, String(), regExpProtoFuncSplitFast), DontEnum | DontDelete | ReadOnly),
658         GlobalPropertyInfo(vm.propertyNames->regExpPrototypeSymbolReplacePrivateName, m_regExpPrototype->getDirect(vm, vm.propertyNames->replaceSymbol), DontEnum | DontDelete | ReadOnly),
659         GlobalPropertyInfo(vm.propertyNames->regExpTestFastPrivateName, JSFunction::create(vm, this, 1, String(), regExpProtoFuncTestFast, RegExpTestFastIntrinsic), DontEnum | DontDelete | ReadOnly),
660
661         // String.prototype helpers.
662         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasObservableSideEffectsForStringReplacePrivateName(), JSFunction::createBuiltinFunction(vm, stringPrototypeHasObservableSideEffectsForStringReplaceCodeGenerator(vm), this), DontEnum | DontDelete | ReadOnly),
663         GlobalPropertyInfo(vm.propertyNames->stringIncludesInternalPrivateName, JSFunction::create(vm, this, 1, String(), builtinStringIncludesInternal), DontEnum | DontDelete | ReadOnly),
664         GlobalPropertyInfo(vm.propertyNames->stringSplitFastPrivateName, JSFunction::create(vm, this, 2, String(), stringProtoFuncSplitFast), DontEnum | DontDelete | ReadOnly),
665         GlobalPropertyInfo(vm.propertyNames->stringSubstrInternalPrivateName, JSFunction::create(vm, this, 2, String(), builtinStringSubstrInternal), DontEnum | DontDelete | ReadOnly),
666     };
667     addStaticGlobals(staticGlobals, WTF_ARRAY_LENGTH(staticGlobals));
668     
669     m_specialPointers[Special::CallFunction] = m_callFunction.get();
670     m_specialPointers[Special::ApplyFunction] = m_applyFunction.get();
671     m_specialPointers[Special::ObjectConstructor] = objectConstructor;
672     m_specialPointers[Special::ArrayConstructor] = arrayConstructor;
673
674     m_linkTimeConstants[static_cast<unsigned>(LinkTimeConstant::DefinePropertyFunction)] = m_definePropertyFunction.get();
675
676     ConsolePrototype* consolePrototype = ConsolePrototype::create(vm, this, ConsolePrototype::createStructure(vm, this, m_objectPrototype.get()));
677     m_consoleStructure.set(vm, this, JSConsole::createStructure(vm, this, consolePrototype));
678     JSConsole* consoleObject = JSConsole::create(vm, m_consoleStructure.get());
679     putDirectWithoutTransition(vm, Identifier::fromString(exec, "console"), consoleObject, DontEnum);
680
681     if (UNLIKELY(Options::useDollarVM())) {
682         JSDollarVMPrototype* dollarVMPrototype = JSDollarVMPrototype::create(vm, this, JSDollarVMPrototype::createStructure(vm, this, m_objectPrototype.get()));
683         m_dollarVMStructure.set(vm, this, JSDollarVM::createStructure(vm, this, dollarVMPrototype));
684         JSDollarVM* dollarVM = JSDollarVM::create(vm, m_dollarVMStructure.get());
685
686         GlobalPropertyInfo extraStaticGlobals[] = {
687             GlobalPropertyInfo(vm.propertyNames->builtinNames().dollarVMPrivateName(), dollarVM, DontEnum | DontDelete | ReadOnly),
688         };
689         addStaticGlobals(extraStaticGlobals, WTF_ARRAY_LENGTH(extraStaticGlobals));
690
691         putDirectWithoutTransition(vm, Identifier::fromString(exec, "$vm"), dollarVM, DontEnum);
692     }
693
694     resetPrototype(vm, getPrototypeDirect());
695 }
696
697 bool JSGlobalObject::hasLegacyProfiler() const
698 {
699     return globalObjectMethodTable()->supportsLegacyProfiling(this);
700 }
701
702 bool JSGlobalObject::put(JSCell* cell, ExecState* exec, PropertyName propertyName, JSValue value, PutPropertySlot& slot)
703 {
704     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(cell);
705     ASSERT(!Heap::heap(value) || Heap::heap(value) == Heap::heap(thisObject));
706
707     if (UNLIKELY(isThisValueAltered(slot, thisObject)))
708         return ordinarySetSlow(exec, thisObject, propertyName, value, slot.thisValue(), slot.isStrictMode());
709
710     bool shouldThrowReadOnlyError = slot.isStrictMode();
711     bool ignoreReadOnlyErrors = false;
712     bool putResult = false;
713     if (symbolTablePutTouchWatchpointSet(thisObject, exec, propertyName, value, shouldThrowReadOnlyError, ignoreReadOnlyErrors, putResult))
714         return putResult;
715     return Base::put(thisObject, exec, propertyName, value, slot);
716 }
717
718 bool JSGlobalObject::defineOwnProperty(JSObject* object, ExecState* exec, PropertyName propertyName, const PropertyDescriptor& descriptor, bool shouldThrow)
719 {
720     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(object);
721     PropertySlot slot(thisObject, PropertySlot::InternalMethodType::VMInquiry);
722     // silently ignore attempts to add accessors aliasing vars.
723     if (descriptor.isAccessorDescriptor() && symbolTableGet(thisObject, propertyName, slot))
724         return false;
725     return Base::defineOwnProperty(thisObject, exec, propertyName, descriptor, shouldThrow);
726 }
727
728 void JSGlobalObject::addGlobalVar(const Identifier& ident)
729 {
730     ConcurrentJITLocker locker(symbolTable()->m_lock);
731     SymbolTableEntry entry = symbolTable()->get(locker, ident.impl());
732     if (!entry.isNull())
733         return;
734     
735     ScopeOffset offset = symbolTable()->takeNextScopeOffset(locker);
736     SymbolTableEntry newEntry(VarOffset(offset), 0);
737     newEntry.prepareToWatch();
738     symbolTable()->add(locker, ident.impl(), WTFMove(newEntry));
739     
740     ScopeOffset offsetForAssert = addVariables(1, jsUndefined());
741     RELEASE_ASSERT(offsetForAssert == offset);
742 }
743
744 void JSGlobalObject::addFunction(ExecState* exec, const Identifier& propertyName)
745 {
746     VM& vm = exec->vm();
747     removeDirect(vm, propertyName); // Newly declared functions overwrite existing properties.
748     addGlobalVar(propertyName);
749 }
750
751 static inline JSObject* lastInPrototypeChain(JSObject* object)
752 {
753     JSObject* o = object;
754     while (o->getPrototypeDirect().isObject())
755         o = asObject(o->getPrototypeDirect());
756     return o;
757 }
758
759 // Private namespace for helpers for JSGlobalObject::haveABadTime()
760 namespace {
761
762 class ObjectsWithBrokenIndexingFinder : public MarkedBlock::VoidFunctor {
763 public:
764     ObjectsWithBrokenIndexingFinder(MarkedArgumentBuffer&, JSGlobalObject*);
765     IterationStatus operator()(JSCell*);
766
767 private:
768     void visit(JSCell*);
769
770     MarkedArgumentBuffer& m_foundObjects;
771     JSGlobalObject* m_globalObject;
772 };
773
774 ObjectsWithBrokenIndexingFinder::ObjectsWithBrokenIndexingFinder(
775     MarkedArgumentBuffer& foundObjects, JSGlobalObject* globalObject)
776     : m_foundObjects(foundObjects)
777     , m_globalObject(globalObject)
778 {
779 }
780
781 inline bool hasBrokenIndexing(JSObject* object)
782 {
783     // This will change if we have more indexing types.
784     IndexingType type = object->indexingType();
785     // This could be made obviously more efficient, but isn't made so right now, because
786     // we expect this to be an unlikely slow path anyway.
787     return hasUndecided(type) || hasInt32(type) || hasDouble(type) || hasContiguous(type) || hasArrayStorage(type);
788 }
789
790 inline void ObjectsWithBrokenIndexingFinder::visit(JSCell* cell)
791 {
792     if (!cell->isObject())
793         return;
794     
795     JSObject* object = asObject(cell);
796
797     // Run this filter first, since it's cheap, and ought to filter out a lot of objects.
798     if (!hasBrokenIndexing(object))
799         return;
800     
801     // We only want to have a bad time in the affected global object, not in the entire
802     // VM. But we have to be careful, since there may be objects that claim to belong to
803     // a different global object that have prototypes from our global object.
804     bool foundGlobalObject = false;
805     for (JSObject* current = object; ;) {
806         if (current->globalObject() == m_globalObject) {
807             foundGlobalObject = true;
808             break;
809         }
810         
811         JSValue prototypeValue = current->getPrototypeDirect();
812         if (prototypeValue.isNull())
813             break;
814         current = asObject(prototypeValue);
815     }
816     if (!foundGlobalObject)
817         return;
818     
819     m_foundObjects.append(object);
820 }
821
822 IterationStatus ObjectsWithBrokenIndexingFinder::operator()(JSCell* cell)
823 {
824     visit(cell);
825     return IterationStatus::Continue;
826 }
827
828 } // end private namespace for helpers for JSGlobalObject::haveABadTime()
829
830 void JSGlobalObject::haveABadTime(VM& vm)
831 {
832     ASSERT(&vm == &this->vm());
833     
834     if (isHavingABadTime())
835         return;
836     
837     // Make sure that all allocations or indexed storage transitions that are inlining
838     // the assumption that it's safe to transition to a non-SlowPut array storage don't
839     // do so anymore.
840     m_havingABadTimeWatchpoint->fireAll("Having a bad time");
841     ASSERT(isHavingABadTime()); // The watchpoint is what tells us that we're having a bad time.
842     
843     // Make sure that all JSArray allocations that load the appropriate structure from
844     // this object now load a structure that uses SlowPut.
845     for (unsigned i = 0; i < NumberOfIndexingShapes; ++i)
846         m_arrayStructureForIndexingShapeDuringAllocation[i].set(vm, this, originalArrayStructureForIndexingType(ArrayWithSlowPutArrayStorage));
847
848     // Same for any special array structures.
849     m_regExpMatchesArrayStructure.set(vm, this, m_regExpMatchesArraySlowPutStructure.get());
850     
851     // Make sure that all objects that have indexed storage switch to the slow kind of
852     // indexed storage.
853     MarkedArgumentBuffer foundObjects; // Use MarkedArgumentBuffer because switchToSlowPutArrayStorage() may GC.
854     ObjectsWithBrokenIndexingFinder finder(foundObjects, this);
855     {
856         HeapIterationScope iterationScope(vm.heap);
857         vm.heap.objectSpace().forEachLiveCell(iterationScope, finder);
858     }
859     while (!foundObjects.isEmpty()) {
860         JSObject* object = asObject(foundObjects.last());
861         foundObjects.removeLast();
862         ASSERT(hasBrokenIndexing(object));
863         object->switchToSlowPutArrayStorage(vm);
864     }
865 }
866
867 bool JSGlobalObject::objectPrototypeIsSane()
868 {
869     return !hasIndexedProperties(m_objectPrototype->indexingType())
870         && m_objectPrototype->getPrototypeDirect().isNull();
871 }
872
873 bool JSGlobalObject::arrayPrototypeChainIsSane()
874 {
875     return !hasIndexedProperties(m_arrayPrototype->indexingType())
876         && m_arrayPrototype->getPrototypeDirect() == m_objectPrototype.get()
877         && objectPrototypeIsSane();
878 }
879
880 bool JSGlobalObject::stringPrototypeChainIsSane()
881 {
882     return !hasIndexedProperties(m_stringPrototype->indexingType())
883         && m_stringPrototype->getPrototypeDirect() == m_objectPrototype.get()
884         && objectPrototypeIsSane();
885 }
886
887 void JSGlobalObject::createThrowTypeError(VM& vm)
888 {
889     JSFunction* thrower = JSFunction::create(vm, this, 0, String(), globalFuncThrowTypeError);
890     GetterSetter* getterSetter = GetterSetter::create(vm, this);
891     getterSetter->setGetter(vm, this, thrower);
892     getterSetter->setSetter(vm, this, thrower);
893     m_throwTypeErrorGetterSetter.set(vm, this, getterSetter);
894 }
895
896 void JSGlobalObject::createThrowTypeErrorArgumentsAndCaller(VM& vm)
897 {
898     JSFunction* thrower = JSFunction::create(vm, this, 0, String(), globalFuncThrowTypeErrorArgumentsAndCaller);
899     GetterSetter* getterSetter = GetterSetter::create(vm, this);
900     getterSetter->setGetter(vm, this, thrower);
901     getterSetter->setSetter(vm, this, thrower);
902     m_throwTypeErrorArgumentsAndCallerGetterSetter.set(vm, this, getterSetter);
903 }
904
905 // Set prototype, and also insert the object prototype at the end of the chain.
906 void JSGlobalObject::resetPrototype(VM& vm, JSValue prototype)
907 {
908     setPrototypeDirect(vm, prototype);
909
910     JSObject* oldLastInPrototypeChain = lastInPrototypeChain(this);
911     JSObject* objectPrototype = m_objectPrototype.get();
912     if (oldLastInPrototypeChain != objectPrototype)
913         oldLastInPrototypeChain->setPrototypeDirect(vm, objectPrototype);
914
915     // Whenever we change the prototype of the global object, we need to create a new JSProxy with the correct prototype.
916     setGlobalThis(vm, JSProxy::create(vm, JSProxy::createStructure(vm, this, prototype, PureForwardingProxyType), this));
917 }
918
919 void JSGlobalObject::visitChildren(JSCell* cell, SlotVisitor& visitor)
920
921     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(cell);
922     ASSERT_GC_OBJECT_INHERITS(thisObject, info());
923     Base::visitChildren(thisObject, visitor);
924
925     visitor.append(&thisObject->m_globalThis);
926
927     visitor.append(&thisObject->m_globalLexicalEnvironment);
928     visitor.append(&thisObject->m_globalCallee);
929     visitor.append(&thisObject->m_regExpConstructor);
930     visitor.append(&thisObject->m_errorConstructor);
931     visitor.append(&thisObject->m_evalErrorConstructor);
932     visitor.append(&thisObject->m_rangeErrorConstructor);
933     visitor.append(&thisObject->m_referenceErrorConstructor);
934     visitor.append(&thisObject->m_syntaxErrorConstructor);
935     visitor.append(&thisObject->m_typeErrorConstructor);
936     visitor.append(&thisObject->m_URIErrorConstructor);
937     visitor.append(&thisObject->m_objectConstructor);
938     visitor.append(&thisObject->m_promiseConstructor);
939     visitor.append(&thisObject->m_internalPromiseConstructor);
940
941     visitor.append(&thisObject->m_nullGetterFunction);
942     visitor.append(&thisObject->m_nullSetterFunction);
943
944     visitor.append(&thisObject->m_parseIntFunction);
945     visitor.append(&thisObject->m_evalFunction);
946     visitor.append(&thisObject->m_callFunction);
947     visitor.append(&thisObject->m_applyFunction);
948     visitor.append(&thisObject->m_definePropertyFunction);
949     visitor.append(&thisObject->m_arrayProtoValuesFunction);
950     visitor.append(&thisObject->m_initializePromiseFunction);
951     visitor.append(&thisObject->m_newPromiseCapabilityFunction);
952     visitor.append(&thisObject->m_functionProtoHasInstanceSymbolFunction);
953     visitor.append(&thisObject->m_throwTypeErrorGetterSetter);
954     visitor.append(&thisObject->m_throwTypeErrorArgumentsAndCallerGetterSetter);
955     visitor.append(&thisObject->m_moduleLoader);
956
957     visitor.append(&thisObject->m_objectPrototype);
958     visitor.append(&thisObject->m_functionPrototype);
959     visitor.append(&thisObject->m_arrayPrototype);
960     visitor.append(&thisObject->m_errorPrototype);
961     visitor.append(&thisObject->m_iteratorPrototype);
962     visitor.append(&thisObject->m_generatorFunctionPrototype);
963     visitor.append(&thisObject->m_generatorPrototype);
964
965     visitor.append(&thisObject->m_debuggerScopeStructure);
966     visitor.append(&thisObject->m_withScopeStructure);
967     visitor.append(&thisObject->m_strictEvalActivationStructure);
968     visitor.append(&thisObject->m_lexicalEnvironmentStructure);
969     visitor.append(&thisObject->m_moduleEnvironmentStructure);
970     visitor.append(&thisObject->m_directArgumentsStructure);
971     visitor.append(&thisObject->m_scopedArgumentsStructure);
972     visitor.append(&thisObject->m_clonedArgumentsStructure);
973     for (unsigned i = 0; i < NumberOfIndexingShapes; ++i)
974         visitor.append(&thisObject->m_originalArrayStructureForIndexingShape[i]);
975     for (unsigned i = 0; i < NumberOfIndexingShapes; ++i)
976         visitor.append(&thisObject->m_arrayStructureForIndexingShapeDuringAllocation[i]);
977     visitor.append(&thisObject->m_booleanObjectStructure);
978     visitor.append(&thisObject->m_callbackConstructorStructure);
979     visitor.append(&thisObject->m_callbackFunctionStructure);
980     visitor.append(&thisObject->m_callbackObjectStructure);
981     visitor.append(&thisObject->m_propertyNameIteratorStructure);
982 #if JSC_OBJC_API_ENABLED
983     visitor.append(&thisObject->m_objcCallbackFunctionStructure);
984     visitor.append(&thisObject->m_objcWrapperObjectStructure);
985 #endif
986     visitor.append(&thisObject->m_nullPrototypeObjectStructure);
987     visitor.append(&thisObject->m_errorStructure);
988     visitor.append(&thisObject->m_calleeStructure);
989     visitor.append(&thisObject->m_functionStructure);
990     visitor.append(&thisObject->m_boundSlotBaseFunctionStructure);
991     visitor.append(&thisObject->m_boundFunctionStructure);
992     visitor.append(&thisObject->m_getterSetterStructure);
993     visitor.append(&thisObject->m_nativeStdFunctionStructure);
994     visitor.append(&thisObject->m_namedFunctionStructure);
995     visitor.append(&thisObject->m_symbolObjectStructure);
996     visitor.append(&thisObject->m_regExpStructure);
997     visitor.append(&thisObject->m_generatorFunctionStructure);
998     visitor.append(&thisObject->m_iteratorResultObjectStructure);
999     visitor.append(&thisObject->m_regExpMatchesArrayStructure);
1000     visitor.append(&thisObject->m_regExpMatchesArraySlowPutStructure);
1001     visitor.append(&thisObject->m_moduleRecordStructure);
1002     visitor.append(&thisObject->m_moduleNamespaceObjectStructure);
1003     visitor.append(&thisObject->m_consoleStructure);
1004     visitor.append(&thisObject->m_dollarVMStructure);
1005     visitor.append(&thisObject->m_internalFunctionStructure);
1006     visitor.append(&thisObject->m_proxyObjectStructure);
1007     visitor.append(&thisObject->m_callableProxyObjectStructure);
1008     visitor.append(&thisObject->m_proxyRevokeStructure);
1009 #if ENABLE(WEBASSEMBLY)
1010     visitor.append(&thisObject->m_wasmModuleStructure);
1011 #endif
1012
1013 #define VISIT_SIMPLE_TYPE(CapitalName, lowerName, properName, instanceType, jsName) \
1014     visitor.append(&thisObject->m_ ## lowerName ## Prototype); \
1015     visitor.append(&thisObject->m_ ## properName ## Structure); \
1016
1017     FOR_EACH_SIMPLE_BUILTIN_TYPE(VISIT_SIMPLE_TYPE)
1018     FOR_EACH_BUILTIN_DERIVED_ITERATOR_TYPE(VISIT_SIMPLE_TYPE)
1019
1020 #undef VISIT_SIMPLE_TYPE
1021
1022     for (unsigned i = NUMBER_OF_TYPED_ARRAY_TYPES; i--;) {
1023         visitor.append(&thisObject->m_typedArrays[i].prototype);
1024         visitor.append(&thisObject->m_typedArrays[i].constructor);
1025         visitor.append(&thisObject->m_typedArrays[i].structure);
1026     }
1027 }
1028
1029 JSValue JSGlobalObject::toThis(JSCell*, ExecState* exec, ECMAMode ecmaMode)
1030 {
1031     if (ecmaMode == StrictMode)
1032         return jsUndefined();
1033     return exec->globalThisValue();
1034 }
1035
1036 ExecState* JSGlobalObject::globalExec()
1037 {
1038     return CallFrame::create(m_globalCallFrame);
1039 }
1040
1041 void JSGlobalObject::addStaticGlobals(GlobalPropertyInfo* globals, int count)
1042 {
1043     ScopeOffset startOffset = addVariables(count, jsUndefined());
1044
1045     for (int i = 0; i < count; ++i) {
1046         GlobalPropertyInfo& global = globals[i];
1047         ASSERT(global.attributes & DontDelete);
1048         
1049         WatchpointSet* watchpointSet = nullptr;
1050         WriteBarrierBase<Unknown>* variable = nullptr;
1051         {
1052             ConcurrentJITLocker locker(symbolTable()->m_lock);
1053             ScopeOffset offset = symbolTable()->takeNextScopeOffset(locker);
1054             RELEASE_ASSERT(offset = startOffset + i);
1055             SymbolTableEntry newEntry(VarOffset(offset), global.attributes);
1056             newEntry.prepareToWatch();
1057             watchpointSet = newEntry.watchpointSet();
1058             symbolTable()->add(locker, global.identifier.impl(), WTFMove(newEntry));
1059             variable = &variableAt(offset);
1060         }
1061         symbolTablePutTouchWatchpointSet(vm(), this, global.identifier, global.value, variable, watchpointSet);
1062     }
1063 }
1064
1065 bool JSGlobalObject::getOwnPropertySlot(JSObject* object, ExecState* exec, PropertyName propertyName, PropertySlot& slot)
1066 {
1067     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(object);
1068     if (getStaticFunctionSlot<Base>(exec, globalObjectTable, thisObject, propertyName, slot))
1069         return true;
1070     return symbolTableGet(thisObject, propertyName, slot);
1071 }
1072
1073 void JSGlobalObject::clearRareData(JSCell* cell)
1074 {
1075     jsCast<JSGlobalObject*>(cell)->m_rareData = nullptr;
1076 }
1077
1078 void slowValidateCell(JSGlobalObject* globalObject)
1079 {
1080     RELEASE_ASSERT(globalObject->isGlobalObject());
1081     ASSERT_GC_OBJECT_INHERITS(globalObject, JSGlobalObject::info());
1082 }
1083
1084 UnlinkedProgramCodeBlock* JSGlobalObject::createProgramCodeBlock(CallFrame* callFrame, ProgramExecutable* executable, JSObject** exception)
1085 {
1086     ParserError error;
1087     JSParserStrictMode strictMode = executable->isStrictMode() ? JSParserStrictMode::Strict : JSParserStrictMode::NotStrict;
1088     DebuggerMode debuggerMode = hasInteractiveDebugger() ? DebuggerOn : DebuggerOff;
1089     ProfilerMode profilerMode = hasLegacyProfiler() ? ProfilerOn : ProfilerOff;
1090     UnlinkedProgramCodeBlock* unlinkedCodeBlock = vm().codeCache()->getProgramCodeBlock(
1091         vm(), executable, executable->source(), JSParserBuiltinMode::NotBuiltin, strictMode, 
1092         debuggerMode, profilerMode, error);
1093
1094     if (hasDebugger())
1095         debugger()->sourceParsed(callFrame, executable->source().provider(), error.line(), error.message());
1096
1097     if (error.isValid()) {
1098         *exception = error.toErrorObject(this, executable->source());
1099         return nullptr;
1100     }
1101     
1102     return unlinkedCodeBlock;
1103 }
1104
1105 UnlinkedEvalCodeBlock* JSGlobalObject::createEvalCodeBlock(CallFrame* callFrame, EvalExecutable* executable, ThisTDZMode thisTDZMode, const VariableEnvironment* variablesUnderTDZ)
1106 {
1107     ParserError error;
1108     JSParserStrictMode strictMode = executable->isStrictMode() ? JSParserStrictMode::Strict : JSParserStrictMode::NotStrict;
1109     DebuggerMode debuggerMode = hasInteractiveDebugger() ? DebuggerOn : DebuggerOff;
1110     EvalContextType evalContextType = executable->executableInfo().evalContextType();
1111     
1112     ProfilerMode profilerMode = hasLegacyProfiler() ? ProfilerOn : ProfilerOff;
1113     UnlinkedEvalCodeBlock* unlinkedCodeBlock = vm().codeCache()->getEvalCodeBlock(
1114         vm(), executable, executable->source(), JSParserBuiltinMode::NotBuiltin, strictMode, thisTDZMode, debuggerMode, profilerMode, error, evalContextType, variablesUnderTDZ);
1115
1116     if (hasDebugger())
1117         debugger()->sourceParsed(callFrame, executable->source().provider(), error.line(), error.message());
1118
1119     if (error.isValid()) {
1120         throwVMError(callFrame, error.toErrorObject(this, executable->source()));
1121         return nullptr;
1122     }
1123
1124     return unlinkedCodeBlock;
1125 }
1126
1127 UnlinkedModuleProgramCodeBlock* JSGlobalObject::createModuleProgramCodeBlock(CallFrame* callFrame, ModuleProgramExecutable* executable)
1128 {
1129     ParserError error;
1130     DebuggerMode debuggerMode = hasInteractiveDebugger() ? DebuggerOn : DebuggerOff;
1131     ProfilerMode profilerMode = hasLegacyProfiler() ? ProfilerOn : ProfilerOff;
1132     UnlinkedModuleProgramCodeBlock* unlinkedCodeBlock = vm().codeCache()->getModuleProgramCodeBlock(
1133         vm(), executable, executable->source(), JSParserBuiltinMode::NotBuiltin, debuggerMode, profilerMode, error);
1134
1135     if (hasDebugger())
1136         debugger()->sourceParsed(callFrame, executable->source().provider(), error.line(), error.message());
1137
1138     if (error.isValid()) {
1139         throwVMError(callFrame, error.toErrorObject(this, executable->source()));
1140         return nullptr;
1141     }
1142
1143     return unlinkedCodeBlock;
1144 }
1145
1146 void JSGlobalObject::setRemoteDebuggingEnabled(bool enabled)
1147 {
1148 #if ENABLE(REMOTE_INSPECTOR)
1149     m_inspectorDebuggable->setRemoteDebuggingAllowed(enabled);
1150 #else
1151     UNUSED_PARAM(enabled);
1152 #endif
1153 }
1154
1155 bool JSGlobalObject::remoteDebuggingEnabled() const
1156 {
1157 #if ENABLE(REMOTE_INSPECTOR)
1158     return m_inspectorDebuggable->remoteDebuggingAllowed();
1159 #else
1160     return false;
1161 #endif
1162 }
1163
1164 #if ENABLE(WEB_REPLAY)
1165 void JSGlobalObject::setInputCursor(PassRefPtr<InputCursor> prpCursor)
1166 {
1167     m_inputCursor = prpCursor;
1168     ASSERT(m_inputCursor);
1169
1170     InputCursor& cursor = inputCursor();
1171     // Save or set the random seed. This performed here rather than the constructor
1172     // to avoid threading the input cursor through all the abstraction layers.
1173     if (cursor.isCapturing())
1174         cursor.appendInput<SetRandomSeed>(m_weakRandom.seed());
1175     else if (cursor.isReplaying()) {
1176         if (SetRandomSeed* input = cursor.fetchInput<SetRandomSeed>())
1177             m_weakRandom.setSeed(static_cast<unsigned>(input->randomSeed()));
1178     }
1179 }
1180 #endif
1181
1182 void JSGlobalObject::setName(const String& name)
1183 {
1184     m_name = name;
1185
1186 #if ENABLE(REMOTE_INSPECTOR)
1187     m_inspectorDebuggable->update();
1188 #endif
1189 }
1190
1191 # if ENABLE(INTL)
1192 const HashSet<String>& JSGlobalObject::intlCollatorAvailableLocales()
1193 {
1194     if (m_intlCollatorAvailableLocales.isEmpty()) {
1195         int32_t count = ucol_countAvailable();
1196         for (int32_t i = 0; i < count; ++i) {
1197             String locale(ucol_getAvailable(i));
1198             convertICULocaleToBCP47LanguageTag(locale);
1199             m_intlCollatorAvailableLocales.add(locale);
1200         }
1201     }
1202     return m_intlCollatorAvailableLocales;
1203 }
1204
1205 const HashSet<String>& JSGlobalObject::intlDateTimeFormatAvailableLocales()
1206 {
1207     if (m_intlDateTimeFormatAvailableLocales.isEmpty()) {
1208         int32_t count = udat_countAvailable();
1209         for (int32_t i = 0; i < count; ++i) {
1210             String locale(udat_getAvailable(i));
1211             convertICULocaleToBCP47LanguageTag(locale);
1212             m_intlDateTimeFormatAvailableLocales.add(locale);
1213         }
1214     }
1215     return m_intlDateTimeFormatAvailableLocales;
1216 }
1217
1218 const HashSet<String>& JSGlobalObject::intlNumberFormatAvailableLocales()
1219 {
1220     if (m_intlNumberFormatAvailableLocales.isEmpty()) {
1221         int32_t count = unum_countAvailable();
1222         for (int32_t i = 0; i < count; ++i) {
1223             String locale(unum_getAvailable(i));
1224             convertICULocaleToBCP47LanguageTag(locale);
1225             m_intlNumberFormatAvailableLocales.add(locale);
1226         }
1227     }
1228     return m_intlNumberFormatAvailableLocales;
1229 }
1230 #endif // ENABLE(INTL)
1231
1232 void JSGlobalObject::queueMicrotask(PassRefPtr<Microtask> task)
1233 {
1234     if (globalObjectMethodTable()->queueTaskToEventLoop) {
1235         globalObjectMethodTable()->queueTaskToEventLoop(this, task);
1236         return;
1237     }
1238
1239     vm().queueMicrotask(this, task);
1240 }
1241
1242 bool JSGlobalObject::hasDebugger() const
1243
1244     return m_debugger;
1245 }
1246
1247 bool JSGlobalObject::hasInteractiveDebugger() const 
1248
1249     return m_debugger && m_debugger->isInteractivelyDebugging();
1250 }
1251
1252 } // namespace JSC