We should have a more concise way of determining when we're varargs calling a functio...
[WebKit-https.git] / Source / JavaScriptCore / runtime / JSGlobalObject.cpp
1 /*
2  * Copyright (C) 2007-2009, 2014-2016 Apple Inc. All rights reserved.
3  * Copyright (C) 2008 Cameron Zwarich (cwzwarich@uwaterloo.ca)
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *
9  * 1.  Redistributions of source code must retain the above copyright
10  *     notice, this list of conditions and the following disclaimer.
11  * 2.  Redistributions in binary form must reproduce the above copyright
12  *     notice, this list of conditions and the following disclaimer in the
13  *     documentation and/or other materials provided with the distribution.
14  * 3.  Neither the name of Apple Inc. ("Apple") nor the names of
15  *     its contributors may be used to endorse or promote products derived
16  *     from this software without specific prior written permission.
17  *
18  * THIS SOFTWARE IS PROVIDED BY APPLE AND ITS CONTRIBUTORS "AS IS" AND ANY
19  * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
20  * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
21  * DISCLAIMED. IN NO EVENT SHALL APPLE OR ITS CONTRIBUTORS BE LIABLE FOR ANY
22  * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
23  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
24  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
25  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
26  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
27  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
28  */
29
30 #include "config.h"
31 #include "JSGlobalObject.h"
32
33 #include "ArrayConstructor.h"
34 #include "ArrayIteratorAdaptiveWatchpoint.h"
35 #include "ArrayIteratorPrototype.h"
36 #include "ArrayPrototype.h"
37 #include "AtomicsObject.h"
38 #include "AsyncFunctionConstructor.h"
39 #include "AsyncFunctionPrototype.h"
40 #include "BooleanConstructor.h"
41 #include "BooleanPrototype.h"
42 #include "BuiltinNames.h"
43 #include "ClonedArguments.h"
44 #include "CodeBlock.h"
45 #include "CodeCache.h"
46 #include "ConsoleObject.h"
47 #include "DateConstructor.h"
48 #include "DatePrototype.h"
49 #include "Debugger.h"
50 #include "DebuggerScope.h"
51 #include "DirectArguments.h"
52 #include "ECMAScriptSpecInternalFunctions.h"
53 #include "Error.h"
54 #include "ErrorConstructor.h"
55 #include "ErrorPrototype.h"
56 #include "FunctionConstructor.h"
57 #include "FunctionPrototype.h"
58 #include "GeneratorFunctionConstructor.h"
59 #include "GeneratorFunctionPrototype.h"
60 #include "GeneratorPrototype.h"
61 #include "GetterSetter.h"
62 #include "HeapIterationScope.h"
63 #include "InspectorInstrumentationObject.h"
64 #include "Interpreter.h"
65 #include "IteratorPrototype.h"
66 #include "JSAPIWrapperObject.h"
67 #include "JSArrayBuffer.h"
68 #include "JSArrayBufferConstructor.h"
69 #include "JSArrayBufferPrototype.h"
70 #include "JSAsyncFunction.h"
71 #include "JSBoundFunction.h"
72 #include "JSCInlines.h"
73 #include "JSCallbackConstructor.h"
74 #include "JSCallbackFunction.h"
75 #include "JSCallbackObject.h"
76 #include "JSCustomGetterSetterFunction.h"
77 #include "JSDataView.h"
78 #include "JSDataViewPrototype.h"
79 #include "JSDollarVM.h"
80 #include "JSDollarVMPrototype.h"
81 #include "JSFixedArray.h"
82 #include "JSFunction.h"
83 #include "JSGeneratorFunction.h"
84 #include "JSGenericTypedArrayViewConstructorInlines.h"
85 #include "JSGenericTypedArrayViewInlines.h"
86 #include "JSGenericTypedArrayViewPrototypeInlines.h"
87 #include "JSGlobalObjectFunctions.h"
88 #include "JSInternalPromise.h"
89 #include "JSInternalPromiseConstructor.h"
90 #include "JSInternalPromisePrototype.h"
91 #include "JSJob.h"
92 #include "JSLexicalEnvironment.h"
93 #include "JSLock.h"
94 #include "JSMap.h"
95 #include "JSMapIterator.h"
96 #include "JSModuleEnvironment.h"
97 #include "JSModuleLoader.h"
98 #include "JSModuleNamespaceObject.h"
99 #include "JSModuleRecord.h"
100 #include "JSNativeStdFunction.h"
101 #include "JSONObject.h"
102 #include "JSPromise.h"
103 #include "JSPromiseConstructor.h"
104 #include "JSPromisePrototype.h"
105 #include "JSPropertyNameIterator.h"
106 #include "JSSet.h"
107 #include "JSSetIterator.h"
108 #include "JSStringIterator.h"
109 #include "JSTemplateRegistryKey.h"
110 #include "JSTypedArrayConstructors.h"
111 #include "JSTypedArrayPrototypes.h"
112 #include "JSTypedArrayViewConstructor.h"
113 #include "JSTypedArrayViewPrototype.h"
114 #include "JSTypedArrays.h"
115 #include "JSWeakMap.h"
116 #include "JSWeakSet.h"
117 #include "JSWebAssembly.h"
118 #include "JSWithScope.h"
119 #include "LazyClassStructureInlines.h"
120 #include "LazyPropertyInlines.h"
121 #include "Lookup.h"
122 #include "MapConstructor.h"
123 #include "MapIteratorPrototype.h"
124 #include "MapPrototype.h"
125 #include "MarkedSpaceInlines.h"
126 #include "MathObject.h"
127 #include "Microtask.h"
128 #include "ModuleLoaderPrototype.h"
129 #include "NativeErrorConstructor.h"
130 #include "NativeErrorPrototype.h"
131 #include "NullGetterFunction.h"
132 #include "NullSetterFunction.h"
133 #include "NumberConstructor.h"
134 #include "NumberPrototype.h"
135 #include "ObjCCallbackFunction.h"
136 #include "ObjectConstructor.h"
137 #include "ObjectPropertyConditionSet.h"
138 #include "ObjectPrototype.h"
139 #include "ParserError.h"
140 #include "ProxyConstructor.h"
141 #include "ProxyObject.h"
142 #include "ProxyRevoke.h"
143 #include "ReflectObject.h"
144 #include "RegExpConstructor.h"
145 #include "RegExpMatchesArray.h"
146 #include "RegExpObject.h"
147 #include "RegExpPrototype.h"
148 #include "ScopedArguments.h"
149 #include "SetConstructor.h"
150 #include "SetIteratorPrototype.h"
151 #include "SetPrototype.h"
152 #include "StrictEvalActivation.h"
153 #include "StringConstructor.h"
154 #include "StringIteratorPrototype.h"
155 #include "StringPrototype.h"
156 #include "Symbol.h"
157 #include "SymbolConstructor.h"
158 #include "SymbolPrototype.h"
159 #include "VariableWriteFireDetail.h"
160 #include "WeakGCMapInlines.h"
161 #include "WeakMapConstructor.h"
162 #include "WeakMapPrototype.h"
163 #include "WeakSetConstructor.h"
164 #include "WeakSetPrototype.h"
165 #include <wtf/RandomNumber.h>
166
167 #if ENABLE(INTL)
168 #include "IntlObject.h"
169 #include <unicode/ucol.h>
170 #include <unicode/udat.h>
171 #include <unicode/unum.h>
172 #endif // ENABLE(INTL)
173
174 #if ENABLE(REMOTE_INSPECTOR)
175 #include "JSGlobalObjectDebuggable.h"
176 #include "JSGlobalObjectInspectorController.h"
177 #endif
178
179 #if ENABLE(WEB_REPLAY)
180 #include "EmptyInputCursor.h"
181 #include "JSReplayInputs.h"
182 #endif
183
184 namespace JSC {
185
186 static JSValue createProxyProperty(VM& vm, JSObject* object)
187 {
188     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
189     return ProxyConstructor::create(vm, ProxyConstructor::createStructure(vm, global, global->functionPrototype()));
190 }
191
192 static JSValue createJSONProperty(VM& vm, JSObject* object)
193 {
194     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
195     return JSONObject::create(vm, JSONObject::createStructure(vm, global, global->objectPrototype()));
196 }
197
198 static JSValue createMathProperty(VM& vm, JSObject* object)
199 {
200     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
201     return MathObject::create(vm, global, MathObject::createStructure(vm, global, global->objectPrototype()));
202 }
203
204 static JSValue createConsoleProperty(VM& vm, JSObject* object)
205 {
206     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
207     return ConsoleObject::create(vm, global, ConsoleObject::createStructure(vm, global, constructEmptyObject(global->globalExec())));
208 }
209
210 static JSValue createAtomicsProperty(VM& vm, JSObject* object)
211 {
212     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
213     return AtomicsObject::create(vm, global, AtomicsObject::createStructure(vm, global, global->objectPrototype()));
214 }
215
216 static EncodedJSValue JSC_HOST_CALL makeBoundFunction(ExecState* exec)
217 {
218     VM& vm = exec->vm();
219     JSGlobalObject* globalObject = exec->lexicalGlobalObject();
220
221     JSObject* target = asObject(exec->uncheckedArgument(0));
222     JSValue boundThis = exec->uncheckedArgument(1);
223     JSValue boundArgs = exec->uncheckedArgument(2);
224     JSValue length = exec->uncheckedArgument(3);
225     JSString* name = asString(exec->uncheckedArgument(4));
226
227     return JSValue::encode(JSBoundFunction::create(
228         vm, exec, globalObject, target, boundThis, boundArgs.isCell() ? jsCast<JSArray*>(boundArgs) : nullptr, length.asInt32(), name->value(exec)));
229 }
230
231 static EncodedJSValue JSC_HOST_CALL hasOwnLengthProperty(ExecState* exec)
232 {
233     VM& vm = exec->vm();
234     JSObject* target = asObject(exec->uncheckedArgument(0));
235     return JSValue::encode(jsBoolean(target->hasOwnProperty(exec, vm.propertyNames->length)));
236 }
237
238 } // namespace JSC
239
240 #include "JSGlobalObject.lut.h"
241
242 namespace JSC {
243
244 const ClassInfo JSGlobalObject::s_info = { "GlobalObject", &Base::s_info, &globalObjectTable, CREATE_METHOD_TABLE(JSGlobalObject) };
245
246 const GlobalObjectMethodTable JSGlobalObject::s_globalObjectMethodTable = { &supportsRichSourceInfo, &shouldInterruptScript, &javaScriptRuntimeFlags, nullptr, &shouldInterruptScriptBeforeTimeout, nullptr, nullptr, nullptr, nullptr, nullptr, nullptr };
247
248 /* Source for JSGlobalObject.lut.h
249 @begin globalObjectTable
250   parseFloat            globalFuncParseFloat                         DontEnum|Function 1
251   isNaN                 JSBuiltin                                    DontEnum|Function 1
252   isFinite              JSBuiltin                                    DontEnum|Function 1
253   escape                globalFuncEscape                             DontEnum|Function 1
254   unescape              globalFuncUnescape                           DontEnum|Function 1
255   decodeURI             globalFuncDecodeURI                          DontEnum|Function 1
256   decodeURIComponent    globalFuncDecodeURIComponent                 DontEnum|Function 1
257   encodeURI             globalFuncEncodeURI                          DontEnum|Function 1
258   encodeURIComponent    globalFuncEncodeURIComponent                 DontEnum|Function 1
259   EvalError             JSGlobalObject::m_evalErrorConstructor       DontEnum|CellProperty
260   ReferenceError        JSGlobalObject::m_referenceErrorConstructor  DontEnum|CellProperty
261   SyntaxError           JSGlobalObject::m_syntaxErrorConstructor     DontEnum|CellProperty
262   URIError              JSGlobalObject::m_URIErrorConstructor        DontEnum|CellProperty
263   Proxy                 createProxyProperty                          DontEnum|PropertyCallback
264   JSON                  createJSONProperty                           DontEnum|PropertyCallback
265   Math                  createMathProperty                           DontEnum|PropertyCallback
266   Atomics               createAtomicsProperty                        DontEnum|PropertyCallback
267   console               createConsoleProperty                        DontEnum|PropertyCallback
268   Int8Array             JSGlobalObject::m_typedArrayInt8             DontEnum|ClassStructure
269   Int16Array            JSGlobalObject::m_typedArrayInt16            DontEnum|ClassStructure
270   Int32Array            JSGlobalObject::m_typedArrayInt32            DontEnum|ClassStructure
271   Uint8Array            JSGlobalObject::m_typedArrayUint8            DontEnum|ClassStructure
272   Uint8ClampedArray     JSGlobalObject::m_typedArrayUint8Clamped     DontEnum|ClassStructure
273   Uint16Array           JSGlobalObject::m_typedArrayUint16           DontEnum|ClassStructure
274   Uint32Array           JSGlobalObject::m_typedArrayUint32           DontEnum|ClassStructure
275   Float32Array          JSGlobalObject::m_typedArrayFloat32          DontEnum|ClassStructure
276   Float64Array          JSGlobalObject::m_typedArrayFloat64          DontEnum|ClassStructure
277   DataView              JSGlobalObject::m_typedArrayDataView         DontEnum|ClassStructure
278   Set                   JSGlobalObject::m_setStructure               DontEnum|ClassStructure
279   Date                  JSGlobalObject::m_dateStructure              DontEnum|ClassStructure
280   Boolean               JSGlobalObject::m_booleanObjectStructure     DontEnum|ClassStructure
281   Number                JSGlobalObject::m_numberObjectStructure      DontEnum|ClassStructure
282   WeakMap               JSGlobalObject::m_weakMapStructure           DontEnum|ClassStructure
283   WeakSet               JSGlobalObject::m_weakSetStructure           DontEnum|ClassStructure
284 @end
285 */
286
287 static EncodedJSValue JSC_HOST_CALL getTemplateObject(ExecState* exec)
288 {
289     JSValue thisValue = exec->thisValue();
290     ASSERT(thisValue.inherits(JSTemplateRegistryKey::info()));
291     return JSValue::encode(exec->lexicalGlobalObject()->templateRegistry().getTemplateObject(exec, jsCast<JSTemplateRegistryKey*>(thisValue)->templateRegistryKey()));
292 }
293
294
295 static EncodedJSValue JSC_HOST_CALL enqueueJob(ExecState* exec)
296 {
297     VM& vm = exec->vm();
298     JSGlobalObject* globalObject = exec->lexicalGlobalObject();
299
300     JSValue job = exec->argument(0);
301     JSValue arguments = exec->argument(1);
302     ASSERT(arguments.inherits(JSArray::info()));
303
304     globalObject->queueMicrotask(createJSJob(vm, job, jsCast<JSArray*>(arguments)));
305
306     return JSValue::encode(jsUndefined());
307 }
308
309 JSGlobalObject::JSGlobalObject(VM& vm, Structure* structure, const GlobalObjectMethodTable* globalObjectMethodTable)
310     : Base(vm, structure, 0)
311     , m_vm(vm)
312 #if ENABLE(WEB_REPLAY)
313     , m_inputCursor(EmptyInputCursor::create())
314 #endif
315     , m_masqueradesAsUndefinedWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
316     , m_havingABadTimeWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
317     , m_varInjectionWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
318     , m_weakRandom(Options::forceWeakRandomSeed() ? Options::forcedWeakRandomSeed() : static_cast<unsigned>(randomNumber() * (std::numeric_limits<unsigned>::max() + 1.0)))
319     , m_arrayIteratorProtocolWatchpoint(IsWatched)
320     , m_templateRegistry(vm)
321     , m_evalEnabled(true)
322     , m_runtimeFlags()
323     , m_consoleClient(nullptr)
324     , m_globalObjectMethodTable(globalObjectMethodTable ? globalObjectMethodTable : &s_globalObjectMethodTable)
325 {
326 }
327
328 JSGlobalObject::~JSGlobalObject()
329 {
330 #if ENABLE(REMOTE_INSPECTOR)
331     m_inspectorController->globalObjectDestroyed();
332 #endif
333
334     if (m_debugger)
335         m_debugger->detach(this, Debugger::GlobalObjectIsDestructing);
336 }
337
338 void JSGlobalObject::destroy(JSCell* cell)
339 {
340     static_cast<JSGlobalObject*>(cell)->JSGlobalObject::~JSGlobalObject();
341 }
342
343 void JSGlobalObject::setGlobalThis(VM& vm, JSObject* globalThis)
344 {
345     m_globalThis.set(vm, this, globalThis);
346 }
347
348 static JSObject* getGetterById(ExecState* exec, JSObject* base, const Identifier& ident)
349 {
350     JSValue baseValue = JSValue(base);
351     PropertySlot slot(baseValue, PropertySlot::InternalMethodType::VMInquiry);
352     baseValue.getPropertySlot(exec, ident, slot);
353     return slot.getPureResult().toObject(exec);
354 }
355
356 void JSGlobalObject::init(VM& vm)
357 {
358     ASSERT(vm.currentThreadIsHoldingAPILock());
359
360     Base::setStructure(vm, Structure::toCacheableDictionaryTransition(vm, structure()));
361
362     m_debugger = 0;
363
364 #if ENABLE(REMOTE_INSPECTOR)
365     m_inspectorController = std::make_unique<Inspector::JSGlobalObjectInspectorController>(*this);
366     m_inspectorDebuggable = std::make_unique<JSGlobalObjectDebuggable>(*this);
367     m_inspectorDebuggable->init();
368     m_consoleClient = m_inspectorController->consoleClient();
369 #endif
370
371     m_functionPrototype.set(vm, this, FunctionPrototype::create(vm, FunctionPrototype::createStructure(vm, this, jsNull()))); // The real prototype will be set once ObjectPrototype is created.
372     m_calleeStructure.set(vm, this, JSCallee::createStructure(vm, this, jsNull()));
373
374     m_globalLexicalEnvironment.set(vm, this, JSGlobalLexicalEnvironment::create(vm, JSGlobalLexicalEnvironment::createStructure(vm, this), this));
375     // Need to create the callee structure (above) before creating the callee.
376     JSCallee* globalCallee = JSCallee::create(vm, this, globalScope());
377     m_globalCallee.set(vm, this, globalCallee);
378
379     ExecState::initGlobalExec(JSGlobalObject::globalExec(), globalCallee);
380     ExecState* exec = JSGlobalObject::globalExec();
381
382     m_functionStructure.set(vm, this, JSFunction::createStructure(vm, this, m_functionPrototype.get()));
383     m_customGetterSetterFunctionStructure.initLater(
384         [] (const Initializer<Structure>& init) {
385             init.set(JSCustomGetterSetterFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
386         });
387     m_boundFunctionStructure.initLater(
388         [] (const Initializer<Structure>& init) {
389             init.set(JSBoundFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
390         });
391     m_getterSetterStructure.set(vm, this, GetterSetter::createStructure(vm, this, jsNull()));
392     m_nativeStdFunctionStructure.initLater(
393         [] (const Initializer<Structure>& init) {
394             init.set(JSNativeStdFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
395         });
396     m_namedFunctionStructure.initLater(
397         [] (const Initializer<Structure>& init) {
398             init.set(Structure::addPropertyTransition(init.vm, init.owner->m_functionStructure.get(), init.vm.propertyNames->name, DontDelete | ReadOnly | DontEnum, init.owner->m_functionNameOffset));
399         });
400     JSFunction* callFunction = 0;
401     JSFunction* applyFunction = 0;
402     JSFunction* hasInstanceSymbolFunction = 0;
403     m_functionPrototype->addFunctionProperties(exec, this, &callFunction, &applyFunction, &hasInstanceSymbolFunction);
404     m_callFunction.set(vm, this, callFunction);
405     m_applyFunction.set(vm, this, applyFunction);
406     m_arrayProtoToStringFunction.initLater(
407         [] (const Initializer<JSFunction>& init) {
408             init.set(JSFunction::create(init.vm, init.owner, 0, init.vm.propertyNames->toString.string(), arrayProtoFuncToString, NoIntrinsic));
409         });
410     m_arrayProtoValuesFunction.initLater(
411         [] (const Initializer<JSFunction>& init) {
412             init.set(JSFunction::createBuiltinFunction(init.vm, arrayPrototypeValuesCodeGenerator(init.vm), init.owner));
413         });
414     m_initializePromiseFunction.initLater(
415         [] (const Initializer<JSFunction>& init) {
416             init.set(JSFunction::createBuiltinFunction(init.vm, promiseOperationsInitializePromiseCodeGenerator(init.vm), init.owner));
417         });
418
419     m_iteratorProtocolFunction.initLater(
420         [] (const Initializer<JSFunction>& init) {
421             init.set(JSFunction::createBuiltinFunction(init.vm, iteratorHelpersPerformIterationCodeGenerator(init.vm), init.owner));
422         });
423
424     m_newPromiseCapabilityFunction.set(vm, this, JSFunction::createBuiltinFunction(vm, promiseOperationsNewPromiseCapabilityCodeGenerator(vm), this));
425     m_functionProtoHasInstanceSymbolFunction.set(vm, this, hasInstanceSymbolFunction);
426     m_throwTypeErrorGetterSetter.initLater(
427         [] (const Initializer<GetterSetter>& init) {
428             JSFunction* thrower = init.owner->throwTypeErrorFunction();
429             GetterSetter* getterSetter = GetterSetter::create(init.vm, init.owner);
430             getterSetter->setGetter(init.vm, init.owner, thrower);
431             getterSetter->setSetter(init.vm, init.owner, thrower);
432             init.set(getterSetter);
433         });
434
435     m_nullGetterFunction.set(vm, this, NullGetterFunction::create(vm, NullGetterFunction::createStructure(vm, this, m_functionPrototype.get())));
436     m_nullSetterFunction.set(vm, this, NullSetterFunction::create(vm, NullSetterFunction::createStructure(vm, this, m_functionPrototype.get())));
437     m_objectPrototype.set(vm, this, ObjectPrototype::create(vm, this, ObjectPrototype::createStructure(vm, this, jsNull())));
438     GetterSetter* protoAccessor = GetterSetter::create(vm, this);
439     protoAccessor->setGetter(vm, this, JSFunction::create(vm, this, 0, makeString("get ", vm.propertyNames->underscoreProto.string()), globalFuncProtoGetter));
440     protoAccessor->setSetter(vm, this, JSFunction::create(vm, this, 0, makeString("set ", vm.propertyNames->underscoreProto.string()), globalFuncProtoSetter));
441     m_objectPrototype->putDirectNonIndexAccessor(vm, vm.propertyNames->underscoreProto, protoAccessor, Accessor | DontEnum);
442     m_functionPrototype->structure()->setPrototypeWithoutTransition(vm, m_objectPrototype.get());
443     m_objectStructureForObjectConstructor.set(vm, this, vm.prototypeMap.emptyObjectStructureForPrototype(m_objectPrototype.get(), JSFinalObject::defaultInlineCapacity()));
444     
445     JSFunction* thrower = JSFunction::create(vm, this, 0, String(), globalFuncThrowTypeErrorArgumentsCalleeAndCaller);
446     GetterSetter* getterSetter = GetterSetter::create(vm, this);
447     getterSetter->setGetter(vm, this, thrower);
448     getterSetter->setSetter(vm, this, thrower);
449     m_throwTypeErrorArgumentsCalleeAndCallerGetterSetter.set(vm, this, getterSetter);
450     
451     m_functionPrototype->initRestrictedProperties(exec, this);
452
453     m_speciesGetterSetter.set(vm, this, GetterSetter::create(vm, this));
454     m_speciesGetterSetter->setGetter(vm, this, JSFunction::createBuiltinFunction(vm, globalOperationsSpeciesGetterCodeGenerator(vm), this, "get [Symbol.species]"));
455
456     m_typedArrayProto.initLater(
457         [] (const Initializer<JSTypedArrayViewPrototype>& init) {
458             init.set(JSTypedArrayViewPrototype::create(init.vm, init.owner, JSTypedArrayViewPrototype::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get())));
459             
460             // Make sure that the constructor gets initialized, too.
461             init.owner->m_typedArraySuperConstructor.get(init.owner);
462         });
463     m_typedArraySuperConstructor.initLater(
464         [] (const Initializer<JSTypedArrayViewConstructor>& init) {
465             JSTypedArrayViewPrototype* prototype = init.owner->m_typedArrayProto.get(init.owner);
466             JSTypedArrayViewConstructor* constructor = JSTypedArrayViewConstructor::create(init.vm, init.owner, JSTypedArrayViewConstructor::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()), prototype, init.owner->m_speciesGetterSetter.get());
467             prototype->putDirectWithoutTransition(init.vm, init.vm.propertyNames->constructor, constructor, DontEnum);
468             init.set(constructor);
469         });
470     
471 #define INIT_TYPED_ARRAY_LATER(type) \
472     m_typedArray ## type.initLater( \
473         [] (LazyClassStructure::Initializer& init) { \
474             init.setPrototype(JS ## type ## ArrayPrototype::create(init.vm, init.global, JS ## type ## ArrayPrototype::createStructure(init.vm, init.global, init.global->m_typedArrayProto.get(init.global)))); \
475             init.setStructure(JS ## type ## Array::createStructure(init.vm, init.global, init.prototype)); \
476             init.setConstructor(JS ## type ## ArrayConstructor::create(init.vm, init.global, JS ## type ## ArrayConstructor::createStructure(init.vm, init.global, init.global->m_typedArraySuperConstructor.get(init.global)), init.prototype, ASCIILiteral(#type "Array"), typedArrayConstructorAllocate ## type ## ArrayCodeGenerator(init.vm))); \
477             init.global->putDirectWithoutTransition(init.vm, init.vm.propertyNames->builtinNames().type ## ArrayPrivateName(), init.constructor, DontEnum); \
478         });
479     FOR_EACH_TYPED_ARRAY_TYPE_EXCLUDING_DATA_VIEW(INIT_TYPED_ARRAY_LATER)
480 #undef INIT_TYPED_ARRAY_LATER
481     
482     m_typedArrayDataView.initLater(
483         [] (LazyClassStructure::Initializer& init) {
484             init.setPrototype(JSDataViewPrototype::create(init.vm, JSDataViewPrototype::createStructure(init.vm, init.global, init.global->m_objectPrototype.get())));
485             init.setStructure(JSDataView::createStructure(init.vm, init.global, init.prototype));
486             init.setConstructor(JSDataViewConstructor::create(init.vm, init.global, JSDataViewConstructor::createStructure(init.vm, init.global, init.global->m_functionPrototype.get()), init.prototype, ASCIILiteral("DataView"), nullptr));
487         });
488     
489     m_lexicalEnvironmentStructure.set(vm, this, JSLexicalEnvironment::createStructure(vm, this));
490     m_moduleEnvironmentStructure.initLater(
491         [] (const Initializer<Structure>& init) {
492             init.set(JSModuleEnvironment::createStructure(init.vm, init.owner));
493         });
494     m_strictEvalActivationStructure.set(vm, this, StrictEvalActivation::createStructure(vm, this, jsNull()));
495     m_debuggerScopeStructure.initLater(
496         [] (const Initializer<Structure>& init) {
497             init.set(DebuggerScope::createStructure(init.vm, init.owner));
498         });
499     m_withScopeStructure.initLater(
500         [] (const Initializer<Structure>& init) {
501             init.set(JSWithScope::createStructure(init.vm, init.owner, jsNull()));
502         });
503     
504     m_nullPrototypeObjectStructure.initLater(
505         [] (const Initializer<Structure>& init) {
506             init.set(JSFinalObject::createStructure(init.vm, init.owner, jsNull(), JSFinalObject::defaultInlineCapacity()));
507         });
508     
509     m_callbackFunctionStructure.initLater(
510         [] (const Initializer<Structure>& init) {
511             init.set(JSCallbackFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
512         });
513     m_directArgumentsStructure.set(vm, this, DirectArguments::createStructure(vm, this, m_objectPrototype.get()));
514     m_scopedArgumentsStructure.set(vm, this, ScopedArguments::createStructure(vm, this, m_objectPrototype.get()));
515     m_clonedArgumentsStructure.set(vm, this, ClonedArguments::createStructure(vm, this, m_objectPrototype.get()));
516     m_callbackConstructorStructure.initLater(
517         [] (const Initializer<Structure>& init) {
518             init.set(JSCallbackConstructor::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
519         });
520     m_callbackObjectStructure.initLater(
521         [] (const Initializer<Structure>& init) {
522             init.set(JSCallbackObject<JSDestructibleObject>::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
523         });
524
525 #if JSC_OBJC_API_ENABLED
526     m_objcCallbackFunctionStructure.initLater(
527         [] (const Initializer<Structure>& init) {
528             init.set(ObjCCallbackFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
529         });
530     m_objcWrapperObjectStructure.initLater(
531         [] (const Initializer<Structure>& init) {
532             init.set(JSCallbackObject<JSAPIWrapperObject>::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
533         });
534 #endif
535     
536     m_arrayPrototype.set(vm, this, ArrayPrototype::create(vm, this, ArrayPrototype::createStructure(vm, this, m_objectPrototype.get())));
537     
538     m_originalArrayStructureForIndexingShape[UndecidedShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithUndecided));
539     m_originalArrayStructureForIndexingShape[Int32Shape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithInt32));
540     m_originalArrayStructureForIndexingShape[DoubleShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithDouble));
541     m_originalArrayStructureForIndexingShape[ContiguousShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithContiguous));
542     m_originalArrayStructureForIndexingShape[ArrayStorageShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithArrayStorage));
543     m_originalArrayStructureForIndexingShape[SlowPutArrayStorageShape >> IndexingShapeShift].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithSlowPutArrayStorage));
544     for (unsigned i = 0; i < NumberOfIndexingShapes; ++i)
545         m_arrayStructureForIndexingShapeDuringAllocation[i] = m_originalArrayStructureForIndexingShape[i];
546
547     m_regExpPrototype.set(vm, this, RegExpPrototype::create(vm, this, RegExpPrototype::createStructure(vm, this, m_objectPrototype.get())));
548     m_regExpStructure.set(vm, this, RegExpObject::createStructure(vm, this, m_regExpPrototype.get()));
549     m_regExpMatchesArrayStructure.set(vm, this, createRegExpMatchesArrayStructure(vm, this));
550
551     m_moduleRecordStructure.set(vm, this, JSModuleRecord::createStructure(vm, this, m_objectPrototype.get()));
552     m_moduleNamespaceObjectStructure.set(vm, this, JSModuleNamespaceObject::createStructure(vm, this, jsNull()));
553     {
554         bool isCallable = false;
555         m_proxyObjectStructure.set(vm, this, ProxyObject::createStructure(vm, this, jsNull(), isCallable));
556         isCallable = true;
557         m_callableProxyObjectStructure.set(vm, this, ProxyObject::createStructure(vm, this, jsNull(), isCallable));
558     }
559     m_proxyRevokeStructure.set(vm, this, ProxyRevoke::createStructure(vm, this, m_functionPrototype.get()));
560
561     m_parseIntFunction.set(vm, this, JSFunction::create(vm, this, 2, vm.propertyNames->parseInt.string(), globalFuncParseInt, NoIntrinsic));
562     putDirectWithoutTransition(vm, vm.propertyNames->parseInt, m_parseIntFunction.get(), DontEnum);
563     
564     m_arrayBufferPrototype.set(vm, this, JSArrayBufferPrototype::create(vm, this, JSArrayBufferPrototype::createStructure(vm, this, m_objectPrototype.get()), ArrayBufferSharingMode::Default));
565     m_arrayBufferStructure.set(vm, this, JSArrayBuffer::createStructure(vm, this, m_arrayBufferPrototype.get()));
566     if (m_runtimeFlags.isSharedArrayBufferEnabled()) {
567         m_sharedArrayBufferPrototype.set(vm, this, JSArrayBufferPrototype::create(vm, this, JSArrayBufferPrototype::createStructure(vm, this, m_objectPrototype.get()), ArrayBufferSharingMode::Shared));
568         m_sharedArrayBufferStructure.set(vm, this, JSArrayBuffer::createStructure(vm, this, m_sharedArrayBufferPrototype.get()));
569     }
570
571 #define CREATE_PROTOTYPE_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
572 m_ ## lowerName ## Prototype.set(vm, this, capitalName##Prototype::create(vm, this, capitalName##Prototype::createStructure(vm, this, m_ ## prototypeBase ## Prototype.get()))); \
573 m_ ## properName ## Structure.set(vm, this, instanceType::createStructure(vm, this, m_ ## lowerName ## Prototype.get()));
574     
575     FOR_EACH_SIMPLE_BUILTIN_TYPE(CREATE_PROTOTYPE_FOR_SIMPLE_TYPE)
576     
577 #undef CREATE_PROTOTYPE_FOR_SIMPLE_TYPE
578
579 #define CREATE_PROTOTYPE_FOR_LAZY_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
580     m_ ## properName ## Structure.initLater(\
581         [] (LazyClassStructure::Initializer& init) { \
582             init.setPrototype(capitalName##Prototype::create(init.vm, init.global, capitalName##Prototype::createStructure(init.vm, init.global, init.global->m_ ## prototypeBase ## Prototype.get()))); \
583             init.setStructure(instanceType::createStructure(init.vm, init.global, init.prototype)); \
584             init.setConstructor(capitalName ## Constructor::create(init.vm, capitalName ## Constructor::createStructure(init.vm, init.global, init.global->m_functionPrototype.get()), jsCast<capitalName ## Prototype*>(init.prototype), init.global->m_speciesGetterSetter.get())); \
585         });
586     
587     FOR_EACH_LAZY_BUILTIN_TYPE(CREATE_PROTOTYPE_FOR_LAZY_TYPE)
588     
589 #undef CREATE_PROTOTYPE_FOR_LAZY_TYPE
590     
591     m_iteratorPrototype.set(vm, this, IteratorPrototype::create(vm, this, IteratorPrototype::createStructure(vm, this, m_objectPrototype.get())));
592
593 #define CREATE_PROTOTYPE_FOR_DERIVED_ITERATOR_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
594     m_ ## lowerName ## Structure.initLater( \
595         [] (const Initializer<Structure>& init) { \
596             JSObject* prototype = capitalName ## Prototype::create(init.vm, init.owner, capitalName ## Prototype::createStructure(init.vm, init.owner, init.owner->m_iteratorPrototype.get())); \
597             init.set(instanceType::createStructure(init.vm, init.owner, prototype)); \
598         });
599     FOR_EACH_BUILTIN_DERIVED_ITERATOR_TYPE(CREATE_PROTOTYPE_FOR_DERIVED_ITERATOR_TYPE)
600 #undef CREATE_PROTOTYPE_FOR_DERIVED_ITERATOR_TYPE
601
602     m_propertyNameIteratorStructure.set(vm, this, JSPropertyNameIterator::createStructure(vm, this, m_iteratorPrototype.get()));
603     m_generatorPrototype.set(vm, this, GeneratorPrototype::create(vm, this, GeneratorPrototype::createStructure(vm, this, m_iteratorPrototype.get())));
604     m_moduleLoaderPrototype.set(vm, this, ModuleLoaderPrototype::create(vm, this, ModuleLoaderPrototype::createStructure(vm, this, m_objectPrototype.get())));
605     
606     // Constructors
607
608     ObjectConstructor* objectConstructor = ObjectConstructor::create(vm, this, ObjectConstructor::createStructure(vm, this, m_functionPrototype.get()), m_objectPrototype.get());
609     m_objectConstructor.set(vm, this, objectConstructor);
610
611     JSFunction* throwTypeErrorFunction = JSFunction::create(vm, this, 0, String(), globalFuncThrowTypeError);
612     m_throwTypeErrorFunction.set(vm, this, throwTypeErrorFunction);
613
614     JSCell* functionConstructor = FunctionConstructor::create(vm, FunctionConstructor::createStructure(vm, this, m_functionPrototype.get()), m_functionPrototype.get());
615     m_functionConstructor.set(vm, this, (FunctionConstructor*)functionConstructor);
616
617     ArrayConstructor* arrayConstructor = ArrayConstructor::create(vm, this, ArrayConstructor::createStructure(vm, this, m_functionPrototype.get()), m_arrayPrototype.get(), m_speciesGetterSetter.get());
618     m_arrayConstructor.set(vm, this, arrayConstructor);
619     
620     m_regExpConstructor.set(vm, this, RegExpConstructor::create(vm, RegExpConstructor::createStructure(vm, this, m_functionPrototype.get()), m_regExpPrototype.get(), m_speciesGetterSetter.get()));
621     
622     JSArrayBufferConstructor* arrayBufferConstructor = JSArrayBufferConstructor::create(vm, JSArrayBufferConstructor::createStructure(vm, this, m_functionPrototype.get()), m_arrayBufferPrototype.get(), m_speciesGetterSetter.get(), ArrayBufferSharingMode::Default);
623     m_arrayBufferPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, arrayBufferConstructor, DontEnum);
624     JSArrayBufferConstructor* sharedArrayBufferConstructor = nullptr;
625     if (m_runtimeFlags.isSharedArrayBufferEnabled()) {
626         sharedArrayBufferConstructor = JSArrayBufferConstructor::create(vm, JSArrayBufferConstructor::createStructure(vm, this, m_functionPrototype.get()), m_sharedArrayBufferPrototype.get(), m_speciesGetterSetter.get(), ArrayBufferSharingMode::Shared);
627         m_sharedArrayBufferPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, sharedArrayBufferConstructor, DontEnum);
628     }
629     
630 #define CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
631 capitalName ## Constructor* lowerName ## Constructor = capitalName ## Constructor::create(vm, capitalName ## Constructor::createStructure(vm, this, m_functionPrototype.get()), m_ ## lowerName ## Prototype.get(), m_speciesGetterSetter.get()); \
632 m_ ## lowerName ## Prototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, lowerName ## Constructor, DontEnum); \
633
634     FOR_EACH_SIMPLE_BUILTIN_TYPE(CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE)
635     
636 #undef CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE
637
638     m_errorConstructor.set(vm, this, errorConstructor);
639     m_promiseConstructor.set(vm, this, promiseConstructor);
640     m_internalPromiseConstructor.set(vm, this, internalPromiseConstructor);
641     
642     m_nativeErrorPrototypeStructure.set(vm, this, NativeErrorPrototype::createStructure(vm, this, m_errorPrototype.get()));
643     m_nativeErrorStructure.set(vm, this, NativeErrorConstructor::createStructure(vm, this, m_functionPrototype.get()));
644     m_evalErrorConstructor.initLater(
645         [] (const Initializer<NativeErrorConstructor>& init) {
646             init.set(NativeErrorConstructor::create(init.vm, init.owner, init.owner->m_nativeErrorStructure.get(), init.owner->m_nativeErrorPrototypeStructure.get(), ASCIILiteral("EvalError")));
647         });
648     m_rangeErrorConstructor.set(vm, this, NativeErrorConstructor::create(vm, this, m_nativeErrorStructure.get(), m_nativeErrorPrototypeStructure.get(), ASCIILiteral("RangeError")));
649     m_referenceErrorConstructor.initLater(
650         [] (const Initializer<NativeErrorConstructor>& init) {
651             init.set(NativeErrorConstructor::create(init.vm, init.owner, init.owner->m_nativeErrorStructure.get(), init.owner->m_nativeErrorPrototypeStructure.get(), ASCIILiteral("ReferenceError")));
652         });
653     m_syntaxErrorConstructor.initLater(
654         [] (const Initializer<NativeErrorConstructor>& init) {
655             init.set(NativeErrorConstructor::create(init.vm, init.owner, init.owner->m_nativeErrorStructure.get(), init.owner->m_nativeErrorPrototypeStructure.get(), ASCIILiteral("SyntaxError")));
656         });
657     m_typeErrorConstructor.set(vm, this, NativeErrorConstructor::create(vm, this, m_nativeErrorStructure.get(), m_nativeErrorPrototypeStructure.get(), ASCIILiteral("TypeError")));
658     m_URIErrorConstructor.initLater(
659         [] (const Initializer<NativeErrorConstructor>& init) {
660             init.set(NativeErrorConstructor::create(init.vm, init.owner, init.owner->m_nativeErrorStructure.get(), init.owner->m_nativeErrorPrototypeStructure.get(), ASCIILiteral("URIError")));
661         });
662
663     m_generatorFunctionPrototype.set(vm, this, GeneratorFunctionPrototype::create(vm, GeneratorFunctionPrototype::createStructure(vm, this, m_functionPrototype.get())));
664     GeneratorFunctionConstructor* generatorFunctionConstructor = GeneratorFunctionConstructor::create(vm, GeneratorFunctionConstructor::createStructure(vm, this, functionConstructor), m_generatorFunctionPrototype.get());
665     m_generatorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, generatorFunctionConstructor, DontEnum | ReadOnly);
666     m_generatorFunctionStructure.set(vm, this, JSGeneratorFunction::createStructure(vm, this, m_generatorFunctionPrototype.get()));
667
668     m_generatorPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_generatorFunctionPrototype.get(), DontEnum | ReadOnly);
669     m_generatorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->prototype, m_generatorPrototype.get(), DontEnum | ReadOnly);
670
671     m_asyncFunctionStructure.initLater(
672         [](LazyClassStructure::Initializer& init) {
673             AsyncFunctionPrototype* asyncFunctionPrototype = AsyncFunctionPrototype::create(init.vm, AsyncFunctionPrototype::createStructure(init.vm, init.global, init.global->m_functionPrototype.get()));
674             init.setPrototype(asyncFunctionPrototype);
675             init.setStructure(JSAsyncFunction::createStructure(init.vm, init.global, init.prototype));
676             init.setConstructor(PropertyName(nullptr), AsyncFunctionConstructor::create(init.vm, AsyncFunctionConstructor::createStructure(init.vm, init.global, init.global->m_functionConstructor.get()), asyncFunctionPrototype));
677
678             init.global->putDirectWithoutTransition(init.vm, init.vm.propertyNames->builtinNames().asyncFunctionResumePrivateName(), JSFunction::createBuiltinFunction(init.vm, asyncFunctionPrototypeAsyncFunctionResumeCodeGenerator(init.vm), init.global), DontEnum | DontDelete | ReadOnly);
679         });
680
681     m_objectPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, objectConstructor, DontEnum);
682     m_functionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, functionConstructor, DontEnum);
683     m_arrayPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, arrayConstructor, DontEnum);
684     m_regExpPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_regExpConstructor.get(), DontEnum);
685     
686     putDirectWithoutTransition(vm, vm.propertyNames->Object, objectConstructor, DontEnum);
687     putDirectWithoutTransition(vm, vm.propertyNames->Function, functionConstructor, DontEnum);
688     putDirectWithoutTransition(vm, vm.propertyNames->Array, arrayConstructor, DontEnum);
689     putDirectWithoutTransition(vm, vm.propertyNames->RegExp, m_regExpConstructor.get(), DontEnum);
690     putDirectWithoutTransition(vm, vm.propertyNames->RangeError, m_rangeErrorConstructor.get(), DontEnum);
691     putDirectWithoutTransition(vm, vm.propertyNames->TypeError, m_typeErrorConstructor.get(), DontEnum);
692
693     putDirectWithoutTransition(vm, vm.propertyNames->builtinNames().ObjectPrivateName(), objectConstructor, DontEnum | DontDelete | ReadOnly);
694     putDirectWithoutTransition(vm, vm.propertyNames->builtinNames().ArrayPrivateName(), arrayConstructor, DontEnum | DontDelete | ReadOnly);
695
696     putDirectWithoutTransition(vm, vm.propertyNames->ArrayBuffer, arrayBufferConstructor, DontEnum);
697     if (m_runtimeFlags.isSharedArrayBufferEnabled())
698         putDirectWithoutTransition(vm, vm.propertyNames->SharedArrayBuffer, sharedArrayBufferConstructor, DontEnum);
699
700 #define PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
701 putDirectWithoutTransition(vm, vm.propertyNames-> jsName, lowerName ## Constructor, DontEnum); \
702
703     FOR_EACH_SIMPLE_BUILTIN_TYPE_WITH_CONSTRUCTOR(PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE)
704
705 #undef PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE
706     m_iteratorResultObjectStructure.set(vm, this, createIteratorResultObjectStructure(vm, *this));
707     
708     m_evalFunction.set(vm, this, JSFunction::create(vm, this, 1, vm.propertyNames->eval.string(), globalFuncEval));
709     putDirectWithoutTransition(vm, vm.propertyNames->eval, m_evalFunction.get(), DontEnum);
710     
711 #if ENABLE(INTL)
712     IntlObject* intl = IntlObject::create(vm, this, IntlObject::createStructure(vm, this, m_objectPrototype.get()));
713     putDirectWithoutTransition(vm, vm.propertyNames->Intl, intl, DontEnum);
714 #endif // ENABLE(INTL)
715     ReflectObject* reflectObject = ReflectObject::create(vm, this, ReflectObject::createStructure(vm, this, m_objectPrototype.get()));
716     putDirectWithoutTransition(vm, vm.propertyNames->Reflect, reflectObject, DontEnum);
717
718     m_moduleLoaderStructure.set(vm, this, JSModuleLoader::createStructure(vm, this, m_moduleLoaderPrototype.get()));
719     m_moduleLoader.set(vm, this, JSModuleLoader::create(globalExec(), vm, this, m_moduleLoaderStructure.get()));
720     if (Options::exposeInternalModuleLoader())
721         putDirectWithoutTransition(vm, vm.propertyNames->Loader, m_moduleLoader.get(), DontEnum);
722
723     JSFunction* builtinLog = JSFunction::create(vm, this, 1, vm.propertyNames->emptyIdentifier.string(), globalFuncBuiltinLog);
724
725     JSFunction* privateFuncAbs = JSFunction::create(vm, this, 0, String(), mathProtoFuncAbs, AbsIntrinsic);
726     JSFunction* privateFuncFloor = JSFunction::create(vm, this, 0, String(), mathProtoFuncFloor, FloorIntrinsic);
727     JSFunction* privateFuncTrunc = JSFunction::create(vm, this, 0, String(), mathProtoFuncTrunc, TruncIntrinsic);
728
729     JSFunction* privateFuncGetTemplateObject = JSFunction::create(vm, this, 0, String(), getTemplateObject);
730     JSFunction* privateFuncTypedArrayLength = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncLength);
731     JSFunction* privateFuncTypedArrayGetOriginalConstructor = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncGetOriginalConstructor);
732     JSFunction* privateFuncTypedArraySort = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncSort);
733     JSFunction* privateFuncIsTypedArrayView = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncIsTypedArrayView, IsTypedArrayViewIntrinsic);
734     JSFunction* privateFuncTypedArraySubarrayCreate = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncSubarrayCreate);
735     JSFunction* privateFuncIsBoundFunction = JSFunction::create(vm, this, 0, String(), isBoundFunction);
736     JSFunction* privateFuncHasInstanceBoundFunction = JSFunction::create(vm, this, 0, String(), hasInstanceBoundFunction);
737     JSFunction* privateFuncInstanceOf = JSFunction::create(vm, this, 0, String(), objectPrivateFuncInstanceOf);
738     JSFunction* privateFuncThisTimeValue = JSFunction::create(vm, this, 0, String(), dateProtoFuncGetTime);
739     JSFunction* privateFuncThisNumberValue = JSFunction::create(vm, this, 0, String(), numberProtoFuncValueOf);
740     JSFunction* privateFuncIsArrayConstructor = JSFunction::create(vm, this, 0, String(), arrayConstructorPrivateFuncIsArrayConstructor);
741     JSFunction* privateFuncIsArraySlow = JSFunction::create(vm, this, 0, String(), arrayConstructorPrivateFuncIsArraySlow);
742     JSFunction* privateFuncConcatMemcpy = JSFunction::create(vm, this, 0, String(), arrayProtoPrivateFuncConcatMemcpy);
743     JSFunction* privateFuncAppendMemcpy = JSFunction::create(vm, this, 0, String(), arrayProtoPrivateFuncAppendMemcpy);
744     JSFunction* privateFuncConcatSlowPath = JSFunction::createBuiltinFunction(vm, arrayPrototypeConcatSlowPathCodeGenerator(vm), this);
745
746     JSObject* regExpProtoFlagsGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->flags);
747     JSObject* regExpProtoGlobalGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->global);
748     m_regExpProtoGlobalGetter.set(vm, this, regExpProtoGlobalGetterObject);
749     JSObject* regExpProtoIgnoreCaseGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->ignoreCase);
750     JSObject* regExpProtoMultilineGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->multiline);
751     JSObject* regExpProtoSourceGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->source);
752     JSObject* regExpProtoStickyGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->sticky);
753     JSObject* regExpProtoUnicodeGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->unicode);
754     m_regExpProtoUnicodeGetter.set(vm, this, regExpProtoUnicodeGetterObject);
755     JSObject* builtinRegExpExec = asObject(m_regExpPrototype->getDirect(vm, vm.propertyNames->exec).asCell());
756     m_regExpProtoExec.set(vm, this, builtinRegExpExec);
757     JSObject* regExpSymbolReplace = asObject(m_regExpPrototype->getDirect(vm, vm.propertyNames->replaceSymbol).asCell());
758     m_regExpProtoSymbolReplace.set(vm, this, regExpSymbolReplace);
759
760 #define CREATE_PRIVATE_GLOBAL_FUNCTION(name, code) JSFunction* name ## PrivateFunction = JSFunction::createBuiltinFunction(vm, code ## CodeGenerator(vm), this);
761     JSC_FOREACH_BUILTIN_FUNCTION_PRIVATE_GLOBAL_NAME(CREATE_PRIVATE_GLOBAL_FUNCTION)
762 #undef CREATE_PRIVATE_GLOBAL_FUNCTION
763
764     JSObject* arrayIteratorPrototype = ArrayIteratorPrototype::create(vm, this, ArrayIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
765     createArrayIteratorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, arrayIteratorPrototype);
766
767     GlobalPropertyInfo staticGlobals[] = {
768 #define INIT_PRIVATE_GLOBAL(name, code) GlobalPropertyInfo(vm.propertyNames->builtinNames().name ## PrivateName(), name ## PrivateFunction, DontEnum | DontDelete | ReadOnly),
769         JSC_FOREACH_BUILTIN_FUNCTION_PRIVATE_GLOBAL_NAME(INIT_PRIVATE_GLOBAL)
770 #undef INIT_PRIVATE_GLOBAL
771         GlobalPropertyInfo(vm.propertyNames->NaN, jsNaN(), DontEnum | DontDelete | ReadOnly),
772         GlobalPropertyInfo(vm.propertyNames->Infinity, jsNumber(std::numeric_limits<double>::infinity()), DontEnum | DontDelete | ReadOnly),
773         GlobalPropertyInfo(vm.propertyNames->undefinedKeyword, jsUndefined(), DontEnum | DontDelete | ReadOnly),
774         GlobalPropertyInfo(vm.propertyNames->builtinNames().ownEnumerablePropertyKeysPrivateName(), JSFunction::create(vm, this, 0, String(), ownEnumerablePropertyKeys), DontEnum | DontDelete | ReadOnly),
775         GlobalPropertyInfo(vm.propertyNames->builtinNames().getTemplateObjectPrivateName(), privateFuncGetTemplateObject, DontEnum | DontDelete | ReadOnly),
776         GlobalPropertyInfo(vm.propertyNames->builtinNames().enqueueJobPrivateName(), JSFunction::create(vm, this, 0, String(), enqueueJob), DontEnum | DontDelete | ReadOnly),
777         GlobalPropertyInfo(vm.propertyNames->builtinNames().ErrorPrivateName(), m_errorConstructor.get(), DontEnum | DontDelete | ReadOnly),
778         GlobalPropertyInfo(vm.propertyNames->builtinNames().RangeErrorPrivateName(), m_rangeErrorConstructor.get(), DontEnum | DontDelete | ReadOnly),
779         GlobalPropertyInfo(vm.propertyNames->builtinNames().TypeErrorPrivateName(), m_typeErrorConstructor.get(), DontEnum | DontDelete | ReadOnly),
780         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArrayLengthPrivateName(), privateFuncTypedArrayLength, DontEnum | DontDelete | ReadOnly),
781         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArrayGetOriginalConstructorPrivateName(), privateFuncTypedArrayGetOriginalConstructor, DontEnum | DontDelete | ReadOnly),
782         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArraySortPrivateName(), privateFuncTypedArraySort, DontEnum | DontDelete | ReadOnly),
783         GlobalPropertyInfo(vm.propertyNames->builtinNames().isTypedArrayViewPrivateName(), privateFuncIsTypedArrayView, DontEnum | DontDelete | ReadOnly),
784         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArraySubarrayCreatePrivateName(), privateFuncTypedArraySubarrayCreate, DontEnum | DontDelete | ReadOnly),
785         GlobalPropertyInfo(vm.propertyNames->builtinNames().isBoundFunctionPrivateName(), privateFuncIsBoundFunction, DontEnum | DontDelete | ReadOnly),
786         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasInstanceBoundFunctionPrivateName(), privateFuncHasInstanceBoundFunction, DontEnum | DontDelete | ReadOnly),
787         GlobalPropertyInfo(vm.propertyNames->builtinNames().instanceOfPrivateName(), privateFuncInstanceOf, DontEnum | DontDelete | ReadOnly),
788         GlobalPropertyInfo(vm.propertyNames->builtinNames().BuiltinLogPrivateName(), builtinLog, DontEnum | DontDelete | ReadOnly),
789         GlobalPropertyInfo(vm.propertyNames->builtinNames().NumberPrivateName(), numberConstructor, DontEnum | DontDelete | ReadOnly),
790         GlobalPropertyInfo(vm.propertyNames->builtinNames().RegExpPrivateName(), m_regExpConstructor.get(), DontEnum | DontDelete | ReadOnly),
791         GlobalPropertyInfo(vm.propertyNames->builtinNames().StringPrivateName(), stringConstructor, DontEnum | DontDelete | ReadOnly),
792         GlobalPropertyInfo(vm.propertyNames->builtinNames().absPrivateName(), privateFuncAbs, DontEnum | DontDelete | ReadOnly),
793         GlobalPropertyInfo(vm.propertyNames->builtinNames().floorPrivateName(), privateFuncFloor, DontEnum | DontDelete | ReadOnly),
794         GlobalPropertyInfo(vm.propertyNames->builtinNames().truncPrivateName(), privateFuncTrunc, DontEnum | DontDelete | ReadOnly),
795         GlobalPropertyInfo(vm.propertyNames->builtinNames().PromisePrivateName(), promiseConstructor, DontEnum | DontDelete | ReadOnly),
796         GlobalPropertyInfo(vm.propertyNames->builtinNames().ReflectPrivateName(), reflectObject, DontEnum | DontDelete | ReadOnly),
797         GlobalPropertyInfo(vm.propertyNames->builtinNames().InternalPromisePrivateName(), internalPromiseConstructor, DontEnum | DontDelete | ReadOnly),
798
799         GlobalPropertyInfo(vm.propertyNames->builtinNames().repeatCharacterPrivateName(), JSFunction::create(vm, this, 2, String(), stringProtoFuncRepeatCharacter), DontEnum | DontDelete | ReadOnly),
800         GlobalPropertyInfo(vm.propertyNames->builtinNames().SetIteratorPrivateName(), JSFunction::create(vm, this, 1, String(), privateFuncSetIterator), DontEnum | DontDelete | ReadOnly),
801         GlobalPropertyInfo(vm.propertyNames->builtinNames().setIteratorNextPrivateName(), JSFunction::create(vm, this, 0, String(), privateFuncSetIteratorNext), DontEnum | DontDelete | ReadOnly),
802         GlobalPropertyInfo(vm.propertyNames->builtinNames().isArrayPrivateName(), arrayConstructor->getDirect(vm, vm.propertyNames->isArray), DontEnum | DontDelete | ReadOnly),
803         GlobalPropertyInfo(vm.propertyNames->builtinNames().isArraySlowPrivateName(), privateFuncIsArraySlow, DontEnum | DontDelete | ReadOnly),
804         GlobalPropertyInfo(vm.propertyNames->builtinNames().isArrayConstructorPrivateName(), privateFuncIsArrayConstructor, DontEnum | DontDelete | ReadOnly),
805         GlobalPropertyInfo(vm.propertyNames->builtinNames().concatMemcpyPrivateName(), privateFuncConcatMemcpy, DontEnum | DontDelete | ReadOnly),
806         GlobalPropertyInfo(vm.propertyNames->builtinNames().appendMemcpyPrivateName(), privateFuncAppendMemcpy, DontEnum | DontDelete | ReadOnly),
807         GlobalPropertyInfo(vm.propertyNames->builtinNames().concatSlowPathPrivateName(), privateFuncConcatSlowPath, DontEnum | DontDelete | ReadOnly),
808         GlobalPropertyInfo(vm.propertyNames->builtinNames().MapIteratorPrivateName(), JSFunction::create(vm, this, 1, String(), privateFuncMapIterator), DontEnum | DontDelete | ReadOnly),
809         GlobalPropertyInfo(vm.propertyNames->builtinNames().mapIteratorNextPrivateName(), JSFunction::create(vm, this, 0, String(), privateFuncMapIteratorNext), DontEnum | DontDelete | ReadOnly),
810
811         GlobalPropertyInfo(vm.propertyNames->builtinNames().InspectorInstrumentationPrivateName(), InspectorInstrumentationObject::create(vm, this, InspectorInstrumentationObject::createStructure(vm, this, m_objectPrototype.get())), DontEnum | DontDelete | ReadOnly),
812         GlobalPropertyInfo(vm.propertyNames->builtinNames().MapPrivateName(), mapConstructor, DontEnum | DontDelete | ReadOnly),
813         GlobalPropertyInfo(vm.propertyNames->builtinNames().thisTimeValuePrivateName(), privateFuncThisTimeValue, DontEnum | DontDelete | ReadOnly),
814         GlobalPropertyInfo(vm.propertyNames->builtinNames().thisNumberValuePrivateName(), privateFuncThisNumberValue, DontEnum | DontDelete | ReadOnly),
815 #if ENABLE(INTL)
816         GlobalPropertyInfo(vm.propertyNames->builtinNames().CollatorPrivateName(), intl->getDirect(vm, vm.propertyNames->Collator), DontEnum | DontDelete | ReadOnly),
817         GlobalPropertyInfo(vm.propertyNames->builtinNames().DateTimeFormatPrivateName(), intl->getDirect(vm, vm.propertyNames->DateTimeFormat), DontEnum | DontDelete | ReadOnly),
818         GlobalPropertyInfo(vm.propertyNames->builtinNames().NumberFormatPrivateName(), intl->getDirect(vm, vm.propertyNames->NumberFormat), DontEnum | DontDelete | ReadOnly),
819 #endif // ENABLE(INTL)
820
821         GlobalPropertyInfo(vm.propertyNames->builtinNames().isConstructorPrivateName(), JSFunction::create(vm, this, 1, String(), esSpecIsConstructor, NoIntrinsic), DontEnum | DontDelete | ReadOnly),
822
823         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoFlagsGetterPrivateName(), regExpProtoFlagsGetterObject, DontEnum | DontDelete | ReadOnly),
824         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoGlobalGetterPrivateName(), regExpProtoGlobalGetterObject, DontEnum | DontDelete | ReadOnly),
825         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoIgnoreCaseGetterPrivateName(), regExpProtoIgnoreCaseGetterObject, DontEnum | DontDelete | ReadOnly),
826         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoMultilineGetterPrivateName(), regExpProtoMultilineGetterObject, DontEnum | DontDelete | ReadOnly),
827         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoSourceGetterPrivateName(), regExpProtoSourceGetterObject, DontEnum | DontDelete | ReadOnly),
828         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoStickyGetterPrivateName(), regExpProtoStickyGetterObject, DontEnum | DontDelete | ReadOnly),
829         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoUnicodeGetterPrivateName(), regExpProtoUnicodeGetterObject, DontEnum | DontDelete | ReadOnly),
830
831         // RegExp.prototype helpers.
832         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpBuiltinExecPrivateName(), builtinRegExpExec, DontEnum | DontDelete | ReadOnly),
833         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpCreatePrivateName(), JSFunction::create(vm, this, 2, String(), esSpecRegExpCreate, NoIntrinsic), DontEnum | DontDelete | ReadOnly),
834         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpMatchFastPrivateName(), JSFunction::create(vm, this, 1, String(), regExpProtoFuncMatchFast), DontEnum | DontDelete | ReadOnly),
835         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpSearchFastPrivateName(), JSFunction::create(vm, this, 1, String(), regExpProtoFuncSearchFast), DontEnum | DontDelete | ReadOnly),
836         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpSplitFastPrivateName(), JSFunction::create(vm, this, 2, String(), regExpProtoFuncSplitFast), DontEnum | DontDelete | ReadOnly),
837         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpPrototypeSymbolReplacePrivateName(), m_regExpPrototype->getDirect(vm, vm.propertyNames->replaceSymbol), DontEnum | DontDelete | ReadOnly),
838         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpTestFastPrivateName(), JSFunction::create(vm, this, 1, String(), regExpProtoFuncTestFast, RegExpTestFastIntrinsic), DontEnum | DontDelete | ReadOnly),
839
840         // String.prototype helpers.
841         GlobalPropertyInfo(vm.propertyNames->builtinNames().stringIncludesInternalPrivateName(), JSFunction::create(vm, this, 1, String(), builtinStringIncludesInternal), DontEnum | DontDelete | ReadOnly),
842         GlobalPropertyInfo(vm.propertyNames->builtinNames().stringSplitFastPrivateName(), JSFunction::create(vm, this, 2, String(), stringProtoFuncSplitFast), DontEnum | DontDelete | ReadOnly),
843         GlobalPropertyInfo(vm.propertyNames->builtinNames().stringSubstrInternalPrivateName(), JSFunction::create(vm, this, 2, String(), builtinStringSubstrInternal), DontEnum | DontDelete | ReadOnly),
844
845         // Function prototype helpers.
846         GlobalPropertyInfo(vm.propertyNames->builtinNames().makeBoundFunctionPrivateName(), JSFunction::create(vm, this, 5, String(), makeBoundFunction), DontEnum | DontDelete | ReadOnly),
847         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasOwnLengthPropertyPrivateName(), JSFunction::create(vm, this, 1, String(), hasOwnLengthProperty), DontEnum | DontDelete | ReadOnly),
848     };
849     addStaticGlobals(staticGlobals, WTF_ARRAY_LENGTH(staticGlobals));
850     
851     m_specialPointers[Special::CallFunction] = m_callFunction.get();
852     m_specialPointers[Special::ApplyFunction] = m_applyFunction.get();
853     m_specialPointers[Special::ObjectConstructor] = objectConstructor;
854     m_specialPointers[Special::ArrayConstructor] = arrayConstructor;
855
856     m_linkTimeConstants[static_cast<unsigned>(LinkTimeConstant::ThrowTypeErrorFunction)] = m_throwTypeErrorFunction.get();
857
858     if (UNLIKELY(Options::useDollarVM())) {
859         JSDollarVMPrototype* dollarVMPrototype = JSDollarVMPrototype::create(vm, this, JSDollarVMPrototype::createStructure(vm, this, m_objectPrototype.get()));
860         m_dollarVMStructure.set(vm, this, JSDollarVM::createStructure(vm, this, dollarVMPrototype));
861         JSDollarVM* dollarVM = JSDollarVM::create(vm, m_dollarVMStructure.get());
862
863         GlobalPropertyInfo extraStaticGlobals[] = {
864             GlobalPropertyInfo(vm.propertyNames->builtinNames().dollarVMPrivateName(), dollarVM, DontEnum | DontDelete | ReadOnly),
865         };
866         addStaticGlobals(extraStaticGlobals, WTF_ARRAY_LENGTH(extraStaticGlobals));
867
868         putDirectWithoutTransition(vm, Identifier::fromString(exec, "$vm"), dollarVM, DontEnum);
869     }
870
871 #if ENABLE(WEBASSEMBLY)
872     if (Options::useWebAssembly()) {
873         auto* webAssemblyPrototype = WebAssemblyPrototype::create(vm, this, WebAssemblyPrototype::createStructure(vm, this, m_objectPrototype.get()));
874         m_webAssemblyStructure.set(vm, this, JSWebAssembly::createStructure(vm, this, webAssemblyPrototype));
875         auto* webAssembly = JSWebAssembly::create(vm, this, m_webAssemblyStructure.get());
876         putDirectWithoutTransition(vm, Identifier::fromString(exec, "WebAssembly"), webAssembly, DontEnum);
877
878 #define CREATE_WEBASSEMBLY_CONSTRUCTOR(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) do { \
879         typedef capitalName ## Prototype Prototype; \
880         typedef capitalName ## Constructor Constructor; \
881         typedef JS ## capitalName JSObj; \
882         auto* base = m_ ## prototypeBase ## Prototype.get(); \
883         auto* prototype = Prototype::create(vm, this, Prototype::createStructure(vm, this, base)); \
884         auto* structure = JSObj::createStructure(vm, this, prototype); \
885         auto* constructor = Constructor::create(vm, Constructor::createStructure(vm, this, this->functionPrototype()), prototype); \
886         prototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, constructor, DontEnum); \
887         m_ ## lowerName ## Prototype.set(vm, this, prototype); \
888         m_ ## properName ## Structure.set(vm, this, structure); \
889         webAssembly->putDirectWithoutTransition(vm, Identifier::fromString(this->globalExec(), #jsName), constructor, DontEnum); \
890     } while (0);
891
892         FOR_EACH_WEBASSEMBLY_CONSTRUCTOR_TYPE(CREATE_WEBASSEMBLY_CONSTRUCTOR)
893
894 #undef CREATE_WEBASSEMBLY_CONSTRUCTOR
895     }
896 #endif // ENABLE(WEBASSEMBLY)
897
898     {
899         ExecState* exec = globalExec();
900         auto scope = DECLARE_THROW_SCOPE(vm);
901
902         auto setupAdaptiveWatchpoint = [&] (JSObject* base, const Identifier& ident) -> ObjectPropertyCondition {
903             // Performing these gets should not throw.
904             PropertySlot slot(base, PropertySlot::InternalMethodType::Get);
905             bool result = base->getOwnPropertySlot(base, exec, ident, slot);
906             ASSERT_UNUSED(result, result);
907             ASSERT_UNUSED(scope, !scope.exception());
908             RELEASE_ASSERT(slot.isCacheableValue());
909             JSValue functionValue = slot.getValue(exec, ident);
910             ASSERT_UNUSED(scope, !scope.exception());
911             ASSERT(jsDynamicCast<JSFunction*>(functionValue));
912
913             ObjectPropertyCondition condition = generateConditionForSelfEquivalence(m_vm, nullptr, base, ident.impl());
914             RELEASE_ASSERT(condition.requiredValue() == functionValue);
915
916             bool isWatchable = condition.isWatchable(PropertyCondition::EnsureWatchability);
917             RELEASE_ASSERT(isWatchable); // We allow this to install the necessary watchpoints.
918
919             return condition;
920         };
921
922         {
923             ObjectPropertyCondition condition = setupAdaptiveWatchpoint(arrayIteratorPrototype, m_vm.propertyNames->next);
924             m_arrayIteratorPrototypeNext = std::make_unique<ArrayIteratorAdaptiveWatchpoint>(condition, this);
925             m_arrayIteratorPrototypeNext->install();
926         }
927
928         {
929             ArrayPrototype* arrayPrototype = this->arrayPrototype();
930             ObjectPropertyCondition condition = setupAdaptiveWatchpoint(arrayPrototype, m_vm.propertyNames->iteratorSymbol);
931             m_arrayPrototypeSymbolIteratorWatchpoint = std::make_unique<ArrayIteratorAdaptiveWatchpoint>(condition, this);
932             m_arrayPrototypeSymbolIteratorWatchpoint->install();
933         }
934     }
935
936     resetPrototype(vm, getPrototypeDirect());
937 }
938
939 bool JSGlobalObject::put(JSCell* cell, ExecState* exec, PropertyName propertyName, JSValue value, PutPropertySlot& slot)
940 {
941     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(cell);
942     ASSERT(!Heap::heap(value) || Heap::heap(value) == Heap::heap(thisObject));
943
944     if (UNLIKELY(isThisValueAltered(slot, thisObject)))
945         return ordinarySetSlow(exec, thisObject, propertyName, value, slot.thisValue(), slot.isStrictMode());
946
947     bool shouldThrowReadOnlyError = slot.isStrictMode();
948     bool ignoreReadOnlyErrors = false;
949     bool putResult = false;
950     if (symbolTablePutTouchWatchpointSet(thisObject, exec, propertyName, value, shouldThrowReadOnlyError, ignoreReadOnlyErrors, putResult))
951         return putResult;
952     return Base::put(thisObject, exec, propertyName, value, slot);
953 }
954
955 bool JSGlobalObject::defineOwnProperty(JSObject* object, ExecState* exec, PropertyName propertyName, const PropertyDescriptor& descriptor, bool shouldThrow)
956 {
957     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(object);
958     PropertySlot slot(thisObject, PropertySlot::InternalMethodType::VMInquiry);
959     // silently ignore attempts to add accessors aliasing vars.
960     if (descriptor.isAccessorDescriptor() && symbolTableGet(thisObject, propertyName, slot))
961         return false;
962     return Base::defineOwnProperty(thisObject, exec, propertyName, descriptor, shouldThrow);
963 }
964
965 void JSGlobalObject::addGlobalVar(const Identifier& ident)
966 {
967     ConcurrentJITLocker locker(symbolTable()->m_lock);
968     SymbolTableEntry entry = symbolTable()->get(locker, ident.impl());
969     if (!entry.isNull())
970         return;
971     
972     ScopeOffset offset = symbolTable()->takeNextScopeOffset(locker);
973     SymbolTableEntry newEntry(VarOffset(offset), 0);
974     newEntry.prepareToWatch();
975     symbolTable()->add(locker, ident.impl(), WTFMove(newEntry));
976     
977     ScopeOffset offsetForAssert = addVariables(1, jsUndefined());
978     RELEASE_ASSERT(offsetForAssert == offset);
979 }
980
981 void JSGlobalObject::addFunction(ExecState* exec, const Identifier& propertyName)
982 {
983     VM& vm = exec->vm();
984     VM::DeletePropertyModeScope scope(vm, VM::DeletePropertyMode::IgnoreConfigurable);
985     methodTable(vm)->deleteProperty(this, exec, propertyName);
986     addGlobalVar(propertyName);
987 }
988
989 void JSGlobalObject::setGlobalScopeExtension(JSScope* scope)
990 {
991     m_globalScopeExtension.set(vm(), this, scope);
992 }
993
994 void JSGlobalObject::clearGlobalScopeExtension()
995 {
996     m_globalScopeExtension.clear();
997 }
998
999 static inline JSObject* lastInPrototypeChain(JSObject* object)
1000 {
1001     JSObject* o = object;
1002     while (o->getPrototypeDirect().isObject())
1003         o = asObject(o->getPrototypeDirect());
1004     return o;
1005 }
1006
1007 // Private namespace for helpers for JSGlobalObject::haveABadTime()
1008 namespace {
1009
1010 class ObjectsWithBrokenIndexingFinder : public MarkedBlock::VoidFunctor {
1011 public:
1012     ObjectsWithBrokenIndexingFinder(MarkedArgumentBuffer&, JSGlobalObject*);
1013     IterationStatus operator()(HeapCell*, HeapCell::Kind) const;
1014
1015 private:
1016     void visit(JSCell*);
1017
1018     MarkedArgumentBuffer& m_foundObjects;
1019     JSGlobalObject* m_globalObject;
1020 };
1021
1022 ObjectsWithBrokenIndexingFinder::ObjectsWithBrokenIndexingFinder(
1023     MarkedArgumentBuffer& foundObjects, JSGlobalObject* globalObject)
1024     : m_foundObjects(foundObjects)
1025     , m_globalObject(globalObject)
1026 {
1027 }
1028
1029 inline bool hasBrokenIndexing(JSObject* object)
1030 {
1031     // This will change if we have more indexing types.
1032     IndexingType type = object->indexingType();
1033     // This could be made obviously more efficient, but isn't made so right now, because
1034     // we expect this to be an unlikely slow path anyway.
1035     return hasUndecided(type) || hasInt32(type) || hasDouble(type) || hasContiguous(type) || hasArrayStorage(type);
1036 }
1037
1038 inline void ObjectsWithBrokenIndexingFinder::visit(JSCell* cell)
1039 {
1040     if (!cell->isObject())
1041         return;
1042     
1043     JSObject* object = asObject(cell);
1044
1045     // Run this filter first, since it's cheap, and ought to filter out a lot of objects.
1046     if (!hasBrokenIndexing(object))
1047         return;
1048     
1049     // We only want to have a bad time in the affected global object, not in the entire
1050     // VM. But we have to be careful, since there may be objects that claim to belong to
1051     // a different global object that have prototypes from our global object.
1052     bool foundGlobalObject = false;
1053     for (JSObject* current = object; ;) {
1054         if (current->globalObject() == m_globalObject) {
1055             foundGlobalObject = true;
1056             break;
1057         }
1058         
1059         JSValue prototypeValue = current->getPrototypeDirect();
1060         if (prototypeValue.isNull())
1061             break;
1062         current = asObject(prototypeValue);
1063     }
1064     if (!foundGlobalObject)
1065         return;
1066     
1067     m_foundObjects.append(object);
1068 }
1069
1070 IterationStatus ObjectsWithBrokenIndexingFinder::operator()(HeapCell* cell, HeapCell::Kind kind) const
1071 {
1072     if (kind == HeapCell::JSCell) {
1073         // FIXME: This const_cast exists because this isn't a C++ lambda.
1074         // https://bugs.webkit.org/show_bug.cgi?id=159644
1075         const_cast<ObjectsWithBrokenIndexingFinder*>(this)->visit(static_cast<JSCell*>(cell));
1076     }
1077     return IterationStatus::Continue;
1078 }
1079
1080 } // end private namespace for helpers for JSGlobalObject::haveABadTime()
1081
1082 void JSGlobalObject::haveABadTime(VM& vm)
1083 {
1084     ASSERT(&vm == &this->vm());
1085     
1086     if (isHavingABadTime())
1087         return;
1088     
1089     // Make sure that all allocations or indexed storage transitions that are inlining
1090     // the assumption that it's safe to transition to a non-SlowPut array storage don't
1091     // do so anymore.
1092     m_havingABadTimeWatchpoint->fireAll(vm, "Having a bad time");
1093     ASSERT(isHavingABadTime()); // The watchpoint is what tells us that we're having a bad time.
1094     
1095     // Make sure that all JSArray allocations that load the appropriate structure from
1096     // this object now load a structure that uses SlowPut.
1097     for (unsigned i = 0; i < NumberOfIndexingShapes; ++i)
1098         m_arrayStructureForIndexingShapeDuringAllocation[i].set(vm, this, originalArrayStructureForIndexingType(ArrayWithSlowPutArrayStorage));
1099
1100     // Same for any special array structures.
1101     Structure* slowPutStructure;
1102     slowPutStructure = createRegExpMatchesArraySlowPutStructure(vm, this);
1103     m_regExpMatchesArrayStructure.set(vm, this, slowPutStructure);
1104     slowPutStructure = ClonedArguments::createSlowPutStructure(vm, this, m_objectPrototype.get());
1105     m_clonedArgumentsStructure.set(vm, this, slowPutStructure);
1106
1107     // Make sure that all objects that have indexed storage switch to the slow kind of
1108     // indexed storage.
1109     MarkedArgumentBuffer foundObjects; // Use MarkedArgumentBuffer because switchToSlowPutArrayStorage() may GC.
1110     ObjectsWithBrokenIndexingFinder finder(foundObjects, this);
1111     {
1112         HeapIterationScope iterationScope(vm.heap);
1113         vm.heap.objectSpace().forEachLiveCell(iterationScope, finder);
1114     }
1115     while (!foundObjects.isEmpty()) {
1116         JSObject* object = asObject(foundObjects.last());
1117         foundObjects.removeLast();
1118         ASSERT(hasBrokenIndexing(object));
1119         object->switchToSlowPutArrayStorage(vm);
1120     }
1121 }
1122
1123 // Set prototype, and also insert the object prototype at the end of the chain.
1124 void JSGlobalObject::resetPrototype(VM& vm, JSValue prototype)
1125 {
1126     setPrototypeDirect(vm, prototype);
1127
1128     JSObject* oldLastInPrototypeChain = lastInPrototypeChain(this);
1129     JSObject* objectPrototype = m_objectPrototype.get();
1130     if (oldLastInPrototypeChain != objectPrototype)
1131         oldLastInPrototypeChain->setPrototypeDirect(vm, objectPrototype);
1132
1133     // Whenever we change the prototype of the global object, we need to create a new JSProxy with the correct prototype.
1134     setGlobalThis(vm, JSProxy::create(vm, JSProxy::createStructure(vm, this, prototype, PureForwardingProxyType), this));
1135 }
1136
1137 void JSGlobalObject::visitChildren(JSCell* cell, SlotVisitor& visitor)
1138
1139     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(cell);
1140     ASSERT_GC_OBJECT_INHERITS(thisObject, info());
1141     Base::visitChildren(thisObject, visitor);
1142
1143     visitor.append(&thisObject->m_globalThis);
1144
1145     visitor.append(&thisObject->m_globalLexicalEnvironment);
1146     visitor.append(&thisObject->m_globalScopeExtension);
1147     visitor.append(&thisObject->m_globalCallee);
1148     visitor.append(&thisObject->m_regExpConstructor);
1149     visitor.append(&thisObject->m_errorConstructor);
1150     visitor.append(&thisObject->m_nativeErrorPrototypeStructure);
1151     visitor.append(&thisObject->m_nativeErrorStructure);
1152     thisObject->m_evalErrorConstructor.visit(visitor);
1153     visitor.append(&thisObject->m_rangeErrorConstructor);
1154     thisObject->m_referenceErrorConstructor.visit(visitor);
1155     thisObject->m_syntaxErrorConstructor.visit(visitor);
1156     visitor.append(&thisObject->m_typeErrorConstructor);
1157     thisObject->m_URIErrorConstructor.visit(visitor);
1158     visitor.append(&thisObject->m_objectConstructor);
1159     visitor.append(&thisObject->m_promiseConstructor);
1160
1161     visitor.append(&thisObject->m_nullGetterFunction);
1162     visitor.append(&thisObject->m_nullSetterFunction);
1163
1164     visitor.append(&thisObject->m_parseIntFunction);
1165     visitor.append(&thisObject->m_evalFunction);
1166     visitor.append(&thisObject->m_callFunction);
1167     visitor.append(&thisObject->m_applyFunction);
1168     visitor.append(&thisObject->m_throwTypeErrorFunction);
1169     thisObject->m_arrayProtoToStringFunction.visit(visitor);
1170     thisObject->m_arrayProtoValuesFunction.visit(visitor);
1171     thisObject->m_initializePromiseFunction.visit(visitor);
1172     thisObject->m_iteratorProtocolFunction.visit(visitor);
1173     visitor.append(&thisObject->m_newPromiseCapabilityFunction);
1174     visitor.append(&thisObject->m_functionProtoHasInstanceSymbolFunction);
1175     thisObject->m_throwTypeErrorGetterSetter.visit(visitor);
1176     visitor.append(&thisObject->m_throwTypeErrorArgumentsCalleeAndCallerGetterSetter);
1177     visitor.append(&thisObject->m_moduleLoader);
1178     visitor.append(&thisObject->m_functionConstructor);
1179
1180     visitor.append(&thisObject->m_objectPrototype);
1181     visitor.append(&thisObject->m_functionPrototype);
1182     visitor.append(&thisObject->m_arrayPrototype);
1183     visitor.append(&thisObject->m_errorPrototype);
1184     visitor.append(&thisObject->m_iteratorPrototype);
1185     visitor.append(&thisObject->m_generatorFunctionPrototype);
1186     visitor.append(&thisObject->m_generatorPrototype);
1187     thisObject->m_asyncFunctionStructure.visit(visitor);
1188     visitor.append(&thisObject->m_moduleLoaderPrototype);
1189
1190     thisObject->m_debuggerScopeStructure.visit(visitor);
1191     thisObject->m_withScopeStructure.visit(visitor);
1192     visitor.append(&thisObject->m_strictEvalActivationStructure);
1193     visitor.append(&thisObject->m_lexicalEnvironmentStructure);
1194     thisObject->m_moduleEnvironmentStructure.visit(visitor);
1195     visitor.append(&thisObject->m_directArgumentsStructure);
1196     visitor.append(&thisObject->m_scopedArgumentsStructure);
1197     visitor.append(&thisObject->m_clonedArgumentsStructure);
1198     visitor.append(&thisObject->m_objectStructureForObjectConstructor);
1199     for (unsigned i = 0; i < NumberOfIndexingShapes; ++i)
1200         visitor.append(&thisObject->m_originalArrayStructureForIndexingShape[i]);
1201     for (unsigned i = 0; i < NumberOfIndexingShapes; ++i)
1202         visitor.append(&thisObject->m_arrayStructureForIndexingShapeDuringAllocation[i]);
1203     thisObject->m_callbackConstructorStructure.visit(visitor);
1204     thisObject->m_callbackFunctionStructure.visit(visitor);
1205     thisObject->m_callbackObjectStructure.visit(visitor);
1206     visitor.append(&thisObject->m_propertyNameIteratorStructure);
1207 #if JSC_OBJC_API_ENABLED
1208     thisObject->m_objcCallbackFunctionStructure.visit(visitor);
1209     thisObject->m_objcWrapperObjectStructure.visit(visitor);
1210 #endif
1211     thisObject->m_nullPrototypeObjectStructure.visit(visitor);
1212     visitor.append(&thisObject->m_errorStructure);
1213     visitor.append(&thisObject->m_calleeStructure);
1214     visitor.append(&thisObject->m_functionStructure);
1215     thisObject->m_customGetterSetterFunctionStructure.visit(visitor);
1216     thisObject->m_boundFunctionStructure.visit(visitor);
1217     visitor.append(&thisObject->m_getterSetterStructure);
1218     thisObject->m_nativeStdFunctionStructure.visit(visitor);
1219     thisObject->m_namedFunctionStructure.visit(visitor);
1220     visitor.append(&thisObject->m_symbolObjectStructure);
1221     visitor.append(&thisObject->m_regExpStructure);
1222     visitor.append(&thisObject->m_generatorFunctionStructure);
1223     visitor.append(&thisObject->m_iteratorResultObjectStructure);
1224     visitor.append(&thisObject->m_regExpMatchesArrayStructure);
1225     visitor.append(&thisObject->m_moduleRecordStructure);
1226     visitor.append(&thisObject->m_moduleNamespaceObjectStructure);
1227     visitor.append(&thisObject->m_dollarVMStructure);
1228     visitor.append(&thisObject->m_proxyObjectStructure);
1229     visitor.append(&thisObject->m_callableProxyObjectStructure);
1230     visitor.append(&thisObject->m_proxyRevokeStructure);
1231     visitor.append(&thisObject->m_moduleLoaderStructure);
1232     
1233     visitor.append(&thisObject->m_arrayBufferPrototype);
1234     visitor.append(&thisObject->m_arrayBufferStructure);
1235     visitor.append(&thisObject->m_sharedArrayBufferPrototype);
1236     visitor.append(&thisObject->m_sharedArrayBufferStructure);
1237
1238 #define VISIT_SIMPLE_TYPE(CapitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
1239     visitor.append(&thisObject->m_ ## lowerName ## Prototype); \
1240     visitor.append(&thisObject->m_ ## properName ## Structure); \
1241
1242     FOR_EACH_SIMPLE_BUILTIN_TYPE(VISIT_SIMPLE_TYPE)
1243     
1244 #if ENABLE(WEBASSEMBLY)
1245     visitor.append(&thisObject->m_webAssemblyStructure);
1246     FOR_EACH_WEBASSEMBLY_CONSTRUCTOR_TYPE(VISIT_SIMPLE_TYPE)
1247 #endif // ENABLE(WEBASSEMBLY)
1248
1249 #undef VISIT_SIMPLE_TYPE
1250
1251 #define VISIT_LAZY_TYPE(CapitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
1252     thisObject->m_ ## properName ## Structure.visit(visitor);
1253     
1254     FOR_EACH_LAZY_BUILTIN_TYPE(VISIT_LAZY_TYPE)
1255     FOR_EACH_BUILTIN_DERIVED_ITERATOR_TYPE(VISIT_LAZY_TYPE)
1256
1257 #undef VISIT_LAZY_TYPE
1258
1259     for (unsigned i = NUMBER_OF_TYPED_ARRAY_TYPES; i--;)
1260         thisObject->lazyTypedArrayStructure(indexToTypedArrayType(i)).visit(visitor);
1261     
1262     visitor.append(&thisObject->m_speciesGetterSetter);
1263     thisObject->m_typedArrayProto.visit(visitor);
1264     thisObject->m_typedArraySuperConstructor.visit(visitor);
1265 }
1266
1267 JSValue JSGlobalObject::toThis(JSCell*, ExecState* exec, ECMAMode ecmaMode)
1268 {
1269     if (ecmaMode == StrictMode)
1270         return jsUndefined();
1271     return exec->globalThisValue();
1272 }
1273
1274 ExecState* JSGlobalObject::globalExec()
1275 {
1276     return CallFrame::create(m_globalCallFrame);
1277 }
1278
1279 void JSGlobalObject::addStaticGlobals(GlobalPropertyInfo* globals, int count)
1280 {
1281     ScopeOffset startOffset = addVariables(count, jsUndefined());
1282
1283     for (int i = 0; i < count; ++i) {
1284         GlobalPropertyInfo& global = globals[i];
1285         ASSERT(global.attributes & DontDelete);
1286         
1287         WatchpointSet* watchpointSet = nullptr;
1288         WriteBarrierBase<Unknown>* variable = nullptr;
1289         {
1290             ConcurrentJITLocker locker(symbolTable()->m_lock);
1291             ScopeOffset offset = symbolTable()->takeNextScopeOffset(locker);
1292             RELEASE_ASSERT(offset = startOffset + i);
1293             SymbolTableEntry newEntry(VarOffset(offset), global.attributes);
1294             newEntry.prepareToWatch();
1295             watchpointSet = newEntry.watchpointSet();
1296             symbolTable()->add(locker, global.identifier.impl(), WTFMove(newEntry));
1297             variable = &variableAt(offset);
1298         }
1299         symbolTablePutTouchWatchpointSet(vm(), this, global.identifier, global.value, variable, watchpointSet);
1300     }
1301 }
1302
1303 bool JSGlobalObject::getOwnPropertySlot(JSObject* object, ExecState* exec, PropertyName propertyName, PropertySlot& slot)
1304 {
1305     if (Base::getOwnPropertySlot(object, exec, propertyName, slot))
1306         return true;
1307     return symbolTableGet(jsCast<JSGlobalObject*>(object), propertyName, slot);
1308 }
1309
1310 void JSGlobalObject::clearRareData(JSCell* cell)
1311 {
1312     jsCast<JSGlobalObject*>(cell)->m_rareData = nullptr;
1313 }
1314
1315 void slowValidateCell(JSGlobalObject* globalObject)
1316 {
1317     RELEASE_ASSERT(globalObject->isGlobalObject());
1318     ASSERT_GC_OBJECT_INHERITS(globalObject, JSGlobalObject::info());
1319 }
1320
1321 UnlinkedProgramCodeBlock* JSGlobalObject::createProgramCodeBlock(CallFrame* callFrame, ProgramExecutable* executable, JSObject** exception)
1322 {
1323     ParserError error;
1324     JSParserStrictMode strictMode = executable->isStrictMode() ? JSParserStrictMode::Strict : JSParserStrictMode::NotStrict;
1325     DebuggerMode debuggerMode = hasInteractiveDebugger() ? DebuggerOn : DebuggerOff;
1326     UnlinkedProgramCodeBlock* unlinkedCodeBlock = vm().codeCache()->getProgramCodeBlock(
1327         vm(), executable, executable->source(), JSParserBuiltinMode::NotBuiltin, strictMode, 
1328         debuggerMode, error);
1329
1330     if (hasDebugger())
1331         debugger()->sourceParsed(callFrame, executable->source().provider(), error.line(), error.message());
1332
1333     if (error.isValid()) {
1334         *exception = error.toErrorObject(this, executable->source());
1335         return nullptr;
1336     }
1337     
1338     return unlinkedCodeBlock;
1339 }
1340
1341 UnlinkedEvalCodeBlock* JSGlobalObject::createEvalCodeBlock(CallFrame* callFrame, EvalExecutable* executable, const VariableEnvironment* variablesUnderTDZ)
1342 {
1343     VM& vm = this->vm();
1344     auto scope = DECLARE_THROW_SCOPE(vm);
1345
1346     ParserError error;
1347     JSParserStrictMode strictMode = executable->isStrictMode() ? JSParserStrictMode::Strict : JSParserStrictMode::NotStrict;
1348     DebuggerMode debuggerMode = hasInteractiveDebugger() ? DebuggerOn : DebuggerOff;
1349     EvalContextType evalContextType = executable->executableInfo().evalContextType();
1350     
1351     UnlinkedEvalCodeBlock* unlinkedCodeBlock = vm.codeCache()->getEvalCodeBlock(
1352         vm, executable, executable->source(), JSParserBuiltinMode::NotBuiltin, strictMode, debuggerMode, error, evalContextType, variablesUnderTDZ);
1353
1354     if (hasDebugger())
1355         debugger()->sourceParsed(callFrame, executable->source().provider(), error.line(), error.message());
1356
1357     if (error.isValid()) {
1358         throwVMError(callFrame, scope, error.toErrorObject(this, executable->source()));
1359         return nullptr;
1360     }
1361
1362     return unlinkedCodeBlock;
1363 }
1364
1365 UnlinkedModuleProgramCodeBlock* JSGlobalObject::createModuleProgramCodeBlock(CallFrame* callFrame, ModuleProgramExecutable* executable)
1366 {
1367     VM& vm = this->vm();
1368     auto scope = DECLARE_THROW_SCOPE(vm);
1369
1370     ParserError error;
1371     DebuggerMode debuggerMode = hasInteractiveDebugger() ? DebuggerOn : DebuggerOff;
1372     UnlinkedModuleProgramCodeBlock* unlinkedCodeBlock = vm.codeCache()->getModuleProgramCodeBlock(
1373         vm, executable, executable->source(), JSParserBuiltinMode::NotBuiltin, debuggerMode, error);
1374
1375     if (hasDebugger())
1376         debugger()->sourceParsed(callFrame, executable->source().provider(), error.line(), error.message());
1377
1378     if (error.isValid()) {
1379         throwVMError(callFrame, scope, error.toErrorObject(this, executable->source()));
1380         return nullptr;
1381     }
1382
1383     return unlinkedCodeBlock;
1384 }
1385
1386 void JSGlobalObject::setRemoteDebuggingEnabled(bool enabled)
1387 {
1388 #if ENABLE(REMOTE_INSPECTOR)
1389     m_inspectorDebuggable->setRemoteDebuggingAllowed(enabled);
1390 #else
1391     UNUSED_PARAM(enabled);
1392 #endif
1393 }
1394
1395 bool JSGlobalObject::remoteDebuggingEnabled() const
1396 {
1397 #if ENABLE(REMOTE_INSPECTOR)
1398     return m_inspectorDebuggable->remoteDebuggingAllowed();
1399 #else
1400     return false;
1401 #endif
1402 }
1403
1404 #if ENABLE(WEB_REPLAY)
1405 void JSGlobalObject::setInputCursor(PassRefPtr<InputCursor> prpCursor)
1406 {
1407     m_inputCursor = prpCursor;
1408     ASSERT(m_inputCursor);
1409
1410     InputCursor& cursor = inputCursor();
1411     // Save or set the random seed. This performed here rather than the constructor
1412     // to avoid threading the input cursor through all the abstraction layers.
1413     if (cursor.isCapturing())
1414         cursor.appendInput<SetRandomSeed>(m_weakRandom.seed());
1415     else if (cursor.isReplaying()) {
1416         if (SetRandomSeed* input = cursor.fetchInput<SetRandomSeed>())
1417             m_weakRandom.setSeed(static_cast<unsigned>(input->randomSeed()));
1418     }
1419 }
1420 #endif
1421
1422 void JSGlobalObject::setName(const String& name)
1423 {
1424     m_name = name;
1425
1426 #if ENABLE(REMOTE_INSPECTOR)
1427     m_inspectorDebuggable->update();
1428 #endif
1429 }
1430
1431 # if ENABLE(INTL)
1432 const HashSet<String>& JSGlobalObject::intlCollatorAvailableLocales()
1433 {
1434     if (m_intlCollatorAvailableLocales.isEmpty()) {
1435         int32_t count = ucol_countAvailable();
1436         for (int32_t i = 0; i < count; ++i) {
1437             String locale(ucol_getAvailable(i));
1438             convertICULocaleToBCP47LanguageTag(locale);
1439             m_intlCollatorAvailableLocales.add(locale);
1440         }
1441     }
1442     return m_intlCollatorAvailableLocales;
1443 }
1444
1445 const HashSet<String>& JSGlobalObject::intlDateTimeFormatAvailableLocales()
1446 {
1447     if (m_intlDateTimeFormatAvailableLocales.isEmpty()) {
1448         int32_t count = udat_countAvailable();
1449         for (int32_t i = 0; i < count; ++i) {
1450             String locale(udat_getAvailable(i));
1451             convertICULocaleToBCP47LanguageTag(locale);
1452             m_intlDateTimeFormatAvailableLocales.add(locale);
1453         }
1454     }
1455     return m_intlDateTimeFormatAvailableLocales;
1456 }
1457
1458 const HashSet<String>& JSGlobalObject::intlNumberFormatAvailableLocales()
1459 {
1460     if (m_intlNumberFormatAvailableLocales.isEmpty()) {
1461         int32_t count = unum_countAvailable();
1462         for (int32_t i = 0; i < count; ++i) {
1463             String locale(unum_getAvailable(i));
1464             convertICULocaleToBCP47LanguageTag(locale);
1465             m_intlNumberFormatAvailableLocales.add(locale);
1466         }
1467     }
1468     return m_intlNumberFormatAvailableLocales;
1469 }
1470 #endif // ENABLE(INTL)
1471
1472 void JSGlobalObject::queueMicrotask(Ref<Microtask>&& task)
1473 {
1474     if (globalObjectMethodTable()->queueTaskToEventLoop) {
1475         globalObjectMethodTable()->queueTaskToEventLoop(this, WTFMove(task));
1476         return;
1477     }
1478
1479     vm().queueMicrotask(this, WTFMove(task));
1480 }
1481
1482 bool JSGlobalObject::hasDebugger() const
1483
1484     return m_debugger;
1485 }
1486
1487 bool JSGlobalObject::hasInteractiveDebugger() const 
1488
1489     return m_debugger && m_debugger->isInteractivelyDebugging();
1490 }
1491
1492 } // namespace JSC