Teach Call ICs how to call Wasm
[WebKit-https.git] / Source / JavaScriptCore / runtime / JSGlobalObject.cpp
1 /*
2  * Copyright (C) 2007-2019 Apple Inc. All rights reserved.
3  * Copyright (C) 2008 Cameron Zwarich (cwzwarich@uwaterloo.ca)
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *
9  * 1.  Redistributions of source code must retain the above copyright
10  *     notice, this list of conditions and the following disclaimer.
11  * 2.  Redistributions in binary form must reproduce the above copyright
12  *     notice, this list of conditions and the following disclaimer in the
13  *     documentation and/or other materials provided with the distribution.
14  * 3.  Neither the name of Apple Inc. ("Apple") nor the names of
15  *     its contributors may be used to endorse or promote products derived
16  *     from this software without specific prior written permission.
17  *
18  * THIS SOFTWARE IS PROVIDED BY APPLE AND ITS CONTRIBUTORS "AS IS" AND ANY
19  * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
20  * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
21  * DISCLAIMED. IN NO EVENT SHALL APPLE OR ITS CONTRIBUTORS BE LIABLE FOR ANY
22  * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
23  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
24  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
25  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
26  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
27  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
28  */
29
30 #include "config.h"
31 #include "JSGlobalObject.h"
32
33 #include "ArrayConstructor.h"
34 #include "ArrayIteratorPrototype.h"
35 #include "ArrayPrototype.h"
36 #include "AsyncFromSyncIteratorPrototype.h"
37 #include "AtomicsObject.h"
38 #include "AsyncFunctionConstructor.h"
39 #include "AsyncFunctionPrototype.h"
40 #include "AsyncGeneratorFunctionConstructor.h"
41 #include "AsyncGeneratorFunctionPrototype.h"
42 #include "AsyncGeneratorPrototype.h"
43 #include "AsyncIteratorPrototype.h"
44 #include "BigIntConstructor.h"
45 #include "BigIntObject.h"
46 #include "BigIntPrototype.h"
47 #include "BooleanConstructor.h"
48 #include "BooleanPrototype.h"
49 #include "BuiltinNames.h"
50 #include "CatchScope.h"
51 #include "ClonedArguments.h"
52 #include "CodeBlock.h"
53 #include "CodeBlockSetInlines.h"
54 #include "CodeCache.h"
55 #include "ConsoleObject.h"
56 #include "DateConstructor.h"
57 #include "DatePrototype.h"
58 #include "Debugger.h"
59 #include "DebuggerScope.h"
60 #include "DirectArguments.h"
61 #include "DirectEvalExecutable.h"
62 #include "ECMAScriptSpecInternalFunctions.h"
63 #include "Error.h"
64 #include "ErrorConstructor.h"
65 #include "ErrorPrototype.h"
66 #include "Exception.h"
67 #include "FunctionConstructor.h"
68 #include "FunctionPrototype.h"
69 #include "GeneratorFunctionConstructor.h"
70 #include "GeneratorFunctionPrototype.h"
71 #include "GeneratorPrototype.h"
72 #include "GetterSetter.h"
73 #include "HeapIterationScope.h"
74 #include "IndirectEvalExecutable.h"
75 #include "InspectorInstrumentationObject.h"
76 #include "Interpreter.h"
77 #include "IteratorPrototype.h"
78 #include "JSAPIWrapperObject.h"
79 #include "JSArrayBuffer.h"
80 #include "JSArrayBufferConstructor.h"
81 #include "JSArrayBufferPrototype.h"
82 #include "JSAsyncFunction.h"
83 #include "JSAsyncGeneratorFunction.h"
84 #include "JSBigInt.h"
85 #include "JSBoundFunction.h"
86 #include "JSCInlines.h"
87 #include "JSCallbackConstructor.h"
88 #include "JSCallbackFunction.h"
89 #include "JSCallbackObject.h"
90 #include "JSCustomGetterSetterFunction.h"
91 #include "JSDataView.h"
92 #include "JSDataViewPrototype.h"
93 #include "JSDollarVM.h"
94 #include "JSFunction.h"
95 #include "JSGeneratorFunction.h"
96 #include "JSGenericTypedArrayViewConstructorInlines.h"
97 #include "JSGenericTypedArrayViewInlines.h"
98 #include "JSGenericTypedArrayViewPrototypeInlines.h"
99 #include "JSGlobalObjectFunctions.h"
100 #include "JSInternalPromise.h"
101 #include "JSInternalPromiseConstructor.h"
102 #include "JSInternalPromisePrototype.h"
103 #include "JSLexicalEnvironment.h"
104 #include "JSLock.h"
105 #include "JSMap.h"
106 #include "JSMicrotask.h"
107 #include "JSModuleEnvironment.h"
108 #include "JSModuleLoader.h"
109 #include "JSModuleNamespaceObject.h"
110 #include "JSModuleRecord.h"
111 #include "JSNativeStdFunction.h"
112 #include "JSNonDestructibleProxy.h"
113 #include "JSONObject.h"
114 #include "JSPromise.h"
115 #include "JSPromiseConstructor.h"
116 #include "JSPromisePrototype.h"
117 #include "JSSet.h"
118 #include "JSStringIterator.h"
119 #include "JSTypedArrayConstructors.h"
120 #include "JSTypedArrayPrototypes.h"
121 #include "JSTypedArrayViewConstructor.h"
122 #include "JSTypedArrayViewPrototype.h"
123 #include "JSTypedArrays.h"
124 #include "JSWeakMap.h"
125 #include "JSWeakSet.h"
126 #include "JSWebAssembly.h"
127 #include "JSWithScope.h"
128 #include "LazyClassStructureInlines.h"
129 #include "LazyPropertyInlines.h"
130 #include "Lookup.h"
131 #include "MapConstructor.h"
132 #include "MapIteratorPrototype.h"
133 #include "MapPrototype.h"
134 #include "MarkedSpaceInlines.h"
135 #include "MathObject.h"
136 #include "Microtask.h"
137 #include "NativeErrorConstructor.h"
138 #include "NativeErrorPrototype.h"
139 #include "NullGetterFunction.h"
140 #include "NullSetterFunction.h"
141 #include "NumberConstructor.h"
142 #include "NumberPrototype.h"
143 #include "ObjCCallbackFunction.h"
144 #include "ObjectConstructor.h"
145 #include "ObjectPropertyChangeAdaptiveWatchpoint.h"
146 #include "ObjectPropertyConditionSet.h"
147 #include "ObjectPrototype.h"
148 #include "ParserError.h"
149 #include "ProxyConstructor.h"
150 #include "ProxyObject.h"
151 #include "ProxyRevoke.h"
152 #include "ReflectObject.h"
153 #include "RegExpCache.h"
154 #include "RegExpConstructor.h"
155 #include "RegExpMatchesArray.h"
156 #include "RegExpObject.h"
157 #include "RegExpPrototype.h"
158 #include "ScopedArguments.h"
159 #include "SetConstructor.h"
160 #include "SetIteratorPrototype.h"
161 #include "SetPrototype.h"
162 #include "StrictEvalActivation.h"
163 #include "StringConstructor.h"
164 #include "StringIteratorPrototype.h"
165 #include "StringPrototype.h"
166 #include "Symbol.h"
167 #include "SymbolConstructor.h"
168 #include "SymbolObject.h"
169 #include "SymbolPrototype.h"
170 #include "VariableWriteFireDetail.h"
171 #include "WasmCapabilities.h"
172 #include "WeakGCMapInlines.h"
173 #include "WeakMapConstructor.h"
174 #include "WeakMapPrototype.h"
175 #include "WeakSetConstructor.h"
176 #include "WeakSetPrototype.h"
177 #include "WebAssemblyPrototype.h"
178 #include "WebAssemblyToJSCallee.h"
179 #include <wtf/RandomNumber.h>
180
181 #if ENABLE(INTL)
182 #include "IntlCollator.h"
183 #include "IntlCollatorPrototype.h"
184 #include "IntlDateTimeFormat.h"
185 #include "IntlDateTimeFormatPrototype.h"
186 #include "IntlNumberFormat.h"
187 #include "IntlNumberFormatPrototype.h"
188 #include "IntlObject.h"
189 #include "IntlPluralRules.h"
190 #include "IntlPluralRulesPrototype.h"
191 #include <unicode/ucol.h>
192 #include <unicode/udat.h>
193 #include <unicode/unum.h>
194 #endif // ENABLE(INTL)
195
196 #if ENABLE(REMOTE_INSPECTOR)
197 #include "JSGlobalObjectDebuggable.h"
198 #include "JSGlobalObjectInspectorController.h"
199 #endif
200
201 #ifdef JSC_GLIB_API_ENABLED
202 #include "JSCCallbackFunction.h"
203 #include "JSCWrapperMap.h"
204 #endif
205
206 namespace JSC {
207
208 static JSValue createProxyProperty(VM& vm, JSObject* object)
209 {
210     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
211     return ProxyConstructor::create(vm, ProxyConstructor::createStructure(vm, global, global->functionPrototype()));
212 }
213
214 static JSValue createJSONProperty(VM& vm, JSObject* object)
215 {
216     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
217     return JSONObject::create(vm, JSONObject::createStructure(vm, global, global->objectPrototype()));
218 }
219
220 static JSValue createMathProperty(VM& vm, JSObject* object)
221 {
222     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
223     return MathObject::create(vm, global, MathObject::createStructure(vm, global, global->objectPrototype()));
224 }
225
226 static JSValue createReflectProperty(VM& vm, JSObject* object)
227 {
228     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
229     return ReflectObject::create(vm, global, ReflectObject::createStructure(vm, global, global->objectPrototype()));
230 }
231
232 static JSValue createConsoleProperty(VM& vm, JSObject* object)
233 {
234     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
235     return ConsoleObject::create(vm, global, ConsoleObject::createStructure(vm, global, constructEmptyObject(global->globalExec())));
236 }
237
238 static EncodedJSValue JSC_HOST_CALL makeBoundFunction(ExecState* exec)
239 {
240     VM& vm = exec->vm();
241     JSGlobalObject* globalObject = exec->lexicalGlobalObject();
242
243     JSObject* target = asObject(exec->uncheckedArgument(0));
244     JSValue boundThis = exec->uncheckedArgument(1);
245     JSValue boundArgs = exec->uncheckedArgument(2);
246     JSValue length = exec->uncheckedArgument(3);
247     JSString* name = asString(exec->uncheckedArgument(4));
248
249     return JSValue::encode(JSBoundFunction::create(
250         vm, exec, globalObject, target, boundThis, boundArgs.isCell() ? jsCast<JSArray*>(boundArgs) : nullptr, length.asInt32(), name->value(exec)));
251 }
252
253 static EncodedJSValue JSC_HOST_CALL hasOwnLengthProperty(ExecState* exec)
254 {
255     VM& vm = exec->vm();
256     JSObject* target = asObject(exec->uncheckedArgument(0));
257     return JSValue::encode(jsBoolean(target->hasOwnProperty(exec, vm.propertyNames->length)));
258 }
259
260 #if !ASSERT_DISABLED
261 static EncodedJSValue JSC_HOST_CALL assertCall(ExecState* exec)
262 {
263     RELEASE_ASSERT(exec->argument(0).isBoolean());
264     if (exec->argument(0).asBoolean())
265         return JSValue::encode(jsUndefined());
266
267     bool iteratedOnce = false;
268     CodeBlock* codeBlock = nullptr;
269     unsigned line;
270     exec->iterate([&] (StackVisitor& visitor) {
271         if (!iteratedOnce) {
272             iteratedOnce = true;
273             return StackVisitor::Continue;
274         }
275
276         RELEASE_ASSERT(visitor->hasLineAndColumnInfo());
277         unsigned column;
278         visitor->computeLineAndColumn(line, column);
279         codeBlock = visitor->codeBlock();
280         return StackVisitor::Done;
281     });
282     RELEASE_ASSERT(!!codeBlock);
283     RELEASE_ASSERT_WITH_MESSAGE(false, "JS assertion failed at line %u in:\n%s\n", line, codeBlock->sourceCodeForTools().data());
284     return JSValue::encode(jsUndefined());
285 }
286 #endif
287
288 } // namespace JSC
289
290 #include "JSGlobalObject.lut.h"
291
292 namespace JSC {
293
294 const ClassInfo JSGlobalObject::s_info = { "GlobalObject", &Base::s_info, &globalObjectTable, nullptr, CREATE_METHOD_TABLE(JSGlobalObject) };
295
296 const GlobalObjectMethodTable JSGlobalObject::s_globalObjectMethodTable = {
297     &supportsRichSourceInfo,
298     &shouldInterruptScript,
299     &javaScriptRuntimeFlags,
300     nullptr, // queueTaskToEventLoop
301     &shouldInterruptScriptBeforeTimeout,
302     nullptr, // moduleLoaderImportModule
303     nullptr, // moduleLoaderResolve
304     nullptr, // moduleLoaderFetch
305     nullptr, // moduleLoaderCreateImportMetaProperties
306     nullptr, // moduleLoaderEvaluate
307     nullptr, // promiseRejectionTracker
308     nullptr, // defaultLanguage
309     nullptr, // compileStreaming
310     nullptr, // instantiateStreaming
311 };
312
313 /* Source for JSGlobalObject.lut.h
314 @begin globalObjectTable
315   isNaN                 JSBuiltin                                    DontEnum|Function 1
316   isFinite              JSBuiltin                                    DontEnum|Function 1
317   escape                globalFuncEscape                             DontEnum|Function 1
318   unescape              globalFuncUnescape                           DontEnum|Function 1
319   decodeURI             globalFuncDecodeURI                          DontEnum|Function 1
320   decodeURIComponent    globalFuncDecodeURIComponent                 DontEnum|Function 1
321   encodeURI             globalFuncEncodeURI                          DontEnum|Function 1
322   encodeURIComponent    globalFuncEncodeURIComponent                 DontEnum|Function 1
323   eval                  JSGlobalObject::m_evalFunction               DontEnum|CellProperty
324   globalThis            JSGlobalObject::m_globalThis                 DontEnum|CellProperty
325   parseInt              JSGlobalObject::m_parseIntFunction           DontEnum|CellProperty
326   parseFloat            JSGlobalObject::m_parseFloatFunction         DontEnum|CellProperty
327   ArrayBuffer           JSGlobalObject::m_arrayBufferStructure       DontEnum|ClassStructure
328   EvalError             JSGlobalObject::m_evalErrorStructure         DontEnum|ClassStructure
329   RangeError            JSGlobalObject::m_rangeErrorStructure        DontEnum|ClassStructure
330   ReferenceError        JSGlobalObject::m_referenceErrorStructure    DontEnum|ClassStructure
331   SyntaxError           JSGlobalObject::m_syntaxErrorStructure       DontEnum|ClassStructure
332   TypeError             JSGlobalObject::m_typeErrorStructure         DontEnum|ClassStructure
333   URIError              JSGlobalObject::m_URIErrorStructure          DontEnum|ClassStructure
334   Proxy                 createProxyProperty                          DontEnum|PropertyCallback
335   Reflect               createReflectProperty                        DontEnum|PropertyCallback
336   JSON                  createJSONProperty                           DontEnum|PropertyCallback
337   Math                  createMathProperty                           DontEnum|PropertyCallback
338   console               createConsoleProperty                        DontEnum|PropertyCallback
339   Int8Array             JSGlobalObject::m_typedArrayInt8             DontEnum|ClassStructure
340   Int16Array            JSGlobalObject::m_typedArrayInt16            DontEnum|ClassStructure
341   Int32Array            JSGlobalObject::m_typedArrayInt32            DontEnum|ClassStructure
342   Uint8Array            JSGlobalObject::m_typedArrayUint8            DontEnum|ClassStructure
343   Uint8ClampedArray     JSGlobalObject::m_typedArrayUint8Clamped     DontEnum|ClassStructure
344   Uint16Array           JSGlobalObject::m_typedArrayUint16           DontEnum|ClassStructure
345   Uint32Array           JSGlobalObject::m_typedArrayUint32           DontEnum|ClassStructure
346   Float32Array          JSGlobalObject::m_typedArrayFloat32          DontEnum|ClassStructure
347   Float64Array          JSGlobalObject::m_typedArrayFloat64          DontEnum|ClassStructure
348   DataView              JSGlobalObject::m_typedArrayDataView         DontEnum|ClassStructure
349   Date                  JSGlobalObject::m_dateStructure              DontEnum|ClassStructure
350   Error                 JSGlobalObject::m_errorStructure             DontEnum|ClassStructure
351   Boolean               JSGlobalObject::m_booleanObjectStructure     DontEnum|ClassStructure
352   Number                JSGlobalObject::m_numberObjectStructure      DontEnum|ClassStructure
353   Symbol                JSGlobalObject::m_symbolObjectStructure      DontEnum|ClassStructure
354   WeakMap               JSGlobalObject::m_weakMapStructure           DontEnum|ClassStructure
355   WeakSet               JSGlobalObject::m_weakSetStructure           DontEnum|ClassStructure
356 @end
357 */
358
359 static EncodedJSValue JSC_HOST_CALL enqueueJob(ExecState* exec)
360 {
361     VM& vm = exec->vm();
362     JSGlobalObject* globalObject = exec->lexicalGlobalObject();
363
364     JSValue job = exec->argument(0);
365     JSValue arguments = exec->argument(1);
366     ASSERT(arguments.inherits<JSArray>(vm));
367
368     globalObject->queueMicrotask(createJSMicrotask(vm, job, jsCast<JSArray*>(arguments)));
369
370     return JSValue::encode(jsUndefined());
371 }
372
373 JSGlobalObject::JSGlobalObject(VM& vm, Structure* structure, const GlobalObjectMethodTable* globalObjectMethodTable)
374     : Base(vm, structure, 0)
375     , m_vm(vm)
376     , m_masqueradesAsUndefinedWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
377     , m_havingABadTimeWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
378     , m_varInjectionWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
379     , m_weakRandom(Options::forceWeakRandomSeed() ? Options::forcedWeakRandomSeed() : static_cast<unsigned>(randomNumber() * (std::numeric_limits<unsigned>::max() + 1.0)))
380     , m_arrayIteratorProtocolWatchpoint(IsWatched)
381     , m_mapIteratorProtocolWatchpoint(IsWatched)
382     , m_setIteratorProtocolWatchpoint(IsWatched)
383     , m_stringIteratorProtocolWatchpoint(IsWatched)
384     , m_mapSetWatchpoint(IsWatched)
385     , m_setAddWatchpoint(IsWatched)
386     , m_arraySpeciesWatchpoint(ClearWatchpoint)
387     , m_numberToStringWatchpoint(IsWatched)
388     , m_runtimeFlags()
389     , m_stackTraceLimit(Options::defaultErrorStackTraceLimit())
390     , m_globalObjectMethodTable(globalObjectMethodTable ? globalObjectMethodTable : &s_globalObjectMethodTable)
391 {
392 }
393
394 JSGlobalObject::~JSGlobalObject()
395 {
396 #if ENABLE(REMOTE_INSPECTOR)
397     m_inspectorController->globalObjectDestroyed();
398 #endif
399
400     if (m_debugger)
401         m_debugger->detach(this, Debugger::GlobalObjectIsDestructing);
402 }
403
404 void JSGlobalObject::destroy(JSCell* cell)
405 {
406     static_cast<JSGlobalObject*>(cell)->JSGlobalObject::~JSGlobalObject();
407 }
408
409 void JSGlobalObject::setGlobalThis(VM& vm, JSObject* globalThis)
410 {
411     m_globalThis.set(vm, this, globalThis);
412 }
413
414 static JSObject* getGetterById(ExecState* exec, JSObject* base, const Identifier& ident)
415 {
416     JSValue baseValue = JSValue(base);
417     PropertySlot slot(baseValue, PropertySlot::InternalMethodType::VMInquiry);
418     baseValue.getPropertySlot(exec, ident, slot);
419     return slot.getPureResult().toObject(exec);
420 }
421
422 template<ErrorType errorType>
423 void JSGlobalObject::initializeErrorConstructor(LazyClassStructure::Initializer& init)
424 {
425     init.setPrototype(NativeErrorPrototype::create(init.vm, NativeErrorPrototype::createStructure(init.vm, this, m_errorStructure.prototype(this)), errorTypeName(errorType)));
426     init.setStructure(ErrorInstance::createStructure(init.vm, this, init.prototype));
427     init.setConstructor(NativeErrorConstructor<errorType>::create(init.vm, NativeErrorConstructor<errorType>::createStructure(init.vm, this, m_errorStructure.constructor(this)), jsCast<NativeErrorPrototype*>(init.prototype)));
428 }
429
430 void JSGlobalObject::init(VM& vm)
431 {
432     ASSERT(vm.currentThreadIsHoldingAPILock());
433     auto catchScope = DECLARE_CATCH_SCOPE(vm);
434
435     Base::setStructure(vm, Structure::toCacheableDictionaryTransition(vm, structure(vm)));
436
437     m_debugger = 0;
438
439 #if ENABLE(REMOTE_INSPECTOR)
440     m_inspectorController = std::make_unique<Inspector::JSGlobalObjectInspectorController>(*this);
441     m_inspectorDebuggable = std::make_unique<JSGlobalObjectDebuggable>(*this);
442     m_inspectorDebuggable->init();
443     m_consoleClient = m_inspectorController->consoleClient();
444 #endif
445
446     m_functionPrototype.set(vm, this, FunctionPrototype::create(vm, FunctionPrototype::createStructure(vm, this, jsNull()))); // The real prototype will be set once ObjectPrototype is created.
447     m_calleeStructure.set(vm, this, JSCallee::createStructure(vm, this, jsNull()));
448
449     m_globalLexicalEnvironment.set(vm, this, JSGlobalLexicalEnvironment::create(vm, JSGlobalLexicalEnvironment::createStructure(vm, this), this));
450     // Need to create the callee structure (above) before creating the callee.
451     JSCallee* globalCallee = JSCallee::create(vm, this, globalScope());
452     m_globalCallee.set(vm, this, globalCallee);
453
454     ExecState::initGlobalExec(JSGlobalObject::globalExec(), globalCallee);
455     ExecState* exec = JSGlobalObject::globalExec();
456
457     JSCallee* stackOverflowFrameCallee = JSCallee::create(vm, this, globalScope());
458     m_stackOverflowFrameCallee.set(vm, this, stackOverflowFrameCallee);
459
460     m_hostFunctionStructure.set(vm, this, JSFunction::createStructure(vm, this, m_functionPrototype.get()));
461
462     auto initFunctionStructures = [&] (FunctionStructures& structures) {
463         structures.strictFunctionStructure.set(vm, this, JSFunction::createStructure(vm, this, m_functionPrototype.get()));
464         structures.sloppyFunctionStructure.set(vm, this, JSFunction::createStructure(vm, this, m_functionPrototype.get()));
465         structures.arrowFunctionStructure.set(vm, this, JSFunction::createStructure(vm, this, m_functionPrototype.get()));
466     };
467     initFunctionStructures(m_builtinFunctions);
468     initFunctionStructures(m_ordinaryFunctions);
469
470     m_customGetterSetterFunctionStructure.initLater(
471         [] (const Initializer<Structure>& init) {
472             init.set(JSCustomGetterSetterFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
473         });
474     m_boundFunctionStructure.initLater(
475         [] (const Initializer<Structure>& init) {
476             init.set(JSBoundFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
477         });
478     m_getterSetterStructure.set(vm, this, GetterSetter::createStructure(vm, this, jsNull()));
479     m_nativeStdFunctionStructure.initLater(
480         [] (const Initializer<Structure>& init) {
481             init.set(JSNativeStdFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
482         });
483     JSFunction* callFunction = nullptr;
484     JSFunction* applyFunction = nullptr;
485     JSFunction* hasInstanceSymbolFunction = nullptr;
486     m_functionPrototype->addFunctionProperties(vm, this, &callFunction, &applyFunction, &hasInstanceSymbolFunction);
487     m_callFunction.set(vm, this, callFunction);
488     m_applyFunction.set(vm, this, applyFunction);
489     m_arrayProtoToStringFunction.initLater(
490         [] (const Initializer<JSFunction>& init) {
491             init.set(JSFunction::create(init.vm, init.owner, 0, init.vm.propertyNames->toString.string(), arrayProtoFuncToString, NoIntrinsic));
492         });
493     m_arrayProtoValuesFunction.initLater(
494         [] (const Initializer<JSFunction>& init) {
495             init.set(JSFunction::create(init.vm, arrayPrototypeValuesCodeGenerator(init.vm), init.owner));
496         });
497     m_initializePromiseFunction.initLater(
498         [] (const Initializer<JSFunction>& init) {
499             init.set(JSFunction::create(init.vm, promiseOperationsInitializePromiseCodeGenerator(init.vm), init.owner));
500         });
501
502     m_iteratorProtocolFunction.initLater(
503         [] (const Initializer<JSFunction>& init) {
504             init.set(JSFunction::create(init.vm, iteratorHelpersPerformIterationCodeGenerator(init.vm), init.owner));
505         });
506
507     m_promiseResolveFunction.initLater(
508         [] (const Initializer<JSFunction>& init) {
509             init.set(JSFunction::create(init.vm, promiseConstructorResolveCodeGenerator(init.vm), init.owner));
510         });
511
512     m_newPromiseCapabilityFunction.set(vm, this, JSFunction::create(vm, promiseOperationsNewPromiseCapabilityCodeGenerator(vm), this));
513     m_functionProtoHasInstanceSymbolFunction.set(vm, this, hasInstanceSymbolFunction);
514     m_throwTypeErrorGetterSetter.initLater(
515         [] (const Initializer<GetterSetter>& init) {
516             JSFunction* thrower = init.owner->throwTypeErrorFunction();
517             GetterSetter* getterSetter = GetterSetter::create(init.vm, init.owner, thrower, thrower);
518             init.set(getterSetter);
519         });
520
521     m_nullGetterFunction.set(vm, this, NullGetterFunction::create(vm, NullGetterFunction::createStructure(vm, this, m_functionPrototype.get())));
522     m_nullSetterFunction.set(vm, this, NullSetterFunction::create(vm, NullSetterFunction::createStructure(vm, this, m_functionPrototype.get())));
523     m_objectPrototype.set(vm, this, ObjectPrototype::create(vm, this, ObjectPrototype::createStructure(vm, this, jsNull())));
524     GetterSetter* protoAccessor = GetterSetter::create(vm, this,
525         JSFunction::create(vm, this, 0, makeString("get ", vm.propertyNames->underscoreProto.string()), globalFuncProtoGetter, UnderscoreProtoIntrinsic),
526         JSFunction::create(vm, this, 0, makeString("set ", vm.propertyNames->underscoreProto.string()), globalFuncProtoSetter));
527     m_objectPrototype->putDirectNonIndexAccessorWithoutTransition(vm, vm.propertyNames->underscoreProto, protoAccessor, PropertyAttribute::Accessor | PropertyAttribute::DontEnum);
528     m_functionPrototype->structure(vm)->setPrototypeWithoutTransition(vm, m_objectPrototype.get());
529     m_objectStructureForObjectConstructor.set(vm, this, vm.structureCache.emptyObjectStructureForPrototype(this, m_objectPrototype.get(), JSFinalObject::defaultInlineCapacity()));
530     m_objectProtoValueOfFunction.set(vm, this, jsCast<JSFunction*>(objectPrototype()->getDirect(vm, vm.propertyNames->valueOf)));
531     
532     JSFunction* thrower = JSFunction::create(vm, this, 0, String(), globalFuncThrowTypeErrorArgumentsCalleeAndCaller);
533     GetterSetter* getterSetter = GetterSetter::create(vm, this, thrower, thrower);
534     m_throwTypeErrorArgumentsCalleeAndCallerGetterSetter.set(vm, this, getterSetter);
535     
536     m_functionPrototype->initRestrictedProperties(vm, this);
537
538     m_speciesGetterSetter.set(vm, this, GetterSetter::create(vm, this, JSFunction::create(vm, globalOperationsSpeciesGetterCodeGenerator(vm), this), nullptr));
539
540     m_typedArrayProto.initLater(
541         [] (const Initializer<JSTypedArrayViewPrototype>& init) {
542             init.set(JSTypedArrayViewPrototype::create(init.vm, init.owner, JSTypedArrayViewPrototype::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get())));
543             
544             // Make sure that the constructor gets initialized, too.
545             init.owner->m_typedArraySuperConstructor.get(init.owner);
546         });
547     m_typedArraySuperConstructor.initLater(
548         [] (const Initializer<JSTypedArrayViewConstructor>& init) {
549             JSTypedArrayViewPrototype* prototype = init.owner->m_typedArrayProto.get(init.owner);
550             JSTypedArrayViewConstructor* constructor = JSTypedArrayViewConstructor::create(init.vm, init.owner, JSTypedArrayViewConstructor::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()), prototype, init.owner->m_speciesGetterSetter.get());
551             prototype->putDirectWithoutTransition(init.vm, init.vm.propertyNames->constructor, constructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
552             init.set(constructor);
553         });
554     
555 #define INIT_TYPED_ARRAY_LATER(type) \
556     m_typedArray ## type.initLater( \
557         [] (LazyClassStructure::Initializer& init) { \
558             init.setPrototype(JS ## type ## ArrayPrototype::create(init.vm, init.global, JS ## type ## ArrayPrototype::createStructure(init.vm, init.global, init.global->m_typedArrayProto.get(init.global)))); \
559             init.setStructure(JS ## type ## Array::createStructure(init.vm, init.global, init.prototype)); \
560             init.setConstructor(JS ## type ## ArrayConstructor::create(init.vm, init.global, JS ## type ## ArrayConstructor::createStructure(init.vm, init.global, init.global->m_typedArraySuperConstructor.get(init.global)), init.prototype, #type "Array"_s, typedArrayConstructorAllocate ## type ## ArrayCodeGenerator(init.vm))); \
561             init.global->putDirectWithoutTransition(init.vm, init.vm.propertyNames->builtinNames().type ## ArrayPrivateName(), init.constructor, static_cast<unsigned>(PropertyAttribute::DontEnum)); \
562         });
563     FOR_EACH_TYPED_ARRAY_TYPE_EXCLUDING_DATA_VIEW(INIT_TYPED_ARRAY_LATER)
564 #undef INIT_TYPED_ARRAY_LATER
565     
566     m_typedArrayDataView.initLater(
567         [] (LazyClassStructure::Initializer& init) {
568             init.setPrototype(JSDataViewPrototype::create(init.vm, JSDataViewPrototype::createStructure(init.vm, init.global, init.global->m_objectPrototype.get())));
569             init.setStructure(JSDataView::createStructure(init.vm, init.global, init.prototype));
570             init.setConstructor(JSDataViewConstructor::create(init.vm, init.global, JSDataViewConstructor::createStructure(init.vm, init.global, init.global->m_functionPrototype.get()), init.prototype, "DataView"_s, nullptr));
571         });
572     
573     m_lexicalEnvironmentStructure.set(vm, this, JSLexicalEnvironment::createStructure(vm, this));
574     m_moduleEnvironmentStructure.initLater(
575         [] (const Initializer<Structure>& init) {
576             init.set(JSModuleEnvironment::createStructure(init.vm, init.owner));
577         });
578     m_strictEvalActivationStructure.initLater(
579         [] (const Initializer<Structure>& init) {
580             init.set(StrictEvalActivation::createStructure(init.vm, init.owner, jsNull()));
581         });
582     m_debuggerScopeStructure.initLater(
583         [] (const Initializer<Structure>& init) {
584             init.set(DebuggerScope::createStructure(init.vm, init.owner));
585         });
586     m_withScopeStructure.initLater(
587         [] (const Initializer<Structure>& init) {
588             init.set(JSWithScope::createStructure(init.vm, init.owner, jsNull()));
589         });
590     
591     m_nullPrototypeObjectStructure.set(vm, this, JSFinalObject::createStructure(vm, this, jsNull(), JSFinalObject::defaultInlineCapacity()));
592     
593     m_callbackFunctionStructure.initLater(
594         [] (const Initializer<Structure>& init) {
595             init.set(JSCallbackFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
596         });
597     m_directArgumentsStructure.set(vm, this, DirectArguments::createStructure(vm, this, m_objectPrototype.get()));
598     m_scopedArgumentsStructure.set(vm, this, ScopedArguments::createStructure(vm, this, m_objectPrototype.get()));
599     m_clonedArgumentsStructure.set(vm, this, ClonedArguments::createStructure(vm, this, m_objectPrototype.get()));
600     m_callbackConstructorStructure.initLater(
601         [] (const Initializer<Structure>& init) {
602             init.set(JSCallbackConstructor::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
603         });
604     m_callbackObjectStructure.initLater(
605         [] (const Initializer<Structure>& init) {
606             init.set(JSCallbackObject<JSDestructibleObject>::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
607         });
608
609 #if JSC_OBJC_API_ENABLED
610     m_objcCallbackFunctionStructure.initLater(
611         [] (const Initializer<Structure>& init) {
612             init.set(ObjCCallbackFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
613         });
614     m_objcWrapperObjectStructure.initLater(
615         [] (const Initializer<Structure>& init) {
616             init.set(JSCallbackObject<JSAPIWrapperObject>::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
617         });
618 #endif
619 #ifdef JSC_GLIB_API_ENABLED
620     m_glibCallbackFunctionStructure.initLater(
621         [] (const Initializer<Structure>& init) {
622             init.set(JSCCallbackFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
623         });
624     m_glibWrapperObjectStructure.initLater(
625         [] (const Initializer<Structure>& init) {
626             init.set(JSCallbackObject<JSAPIWrapperObject>::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
627         });
628 #endif
629     m_arrayPrototype.set(vm, this, ArrayPrototype::create(vm, this, ArrayPrototype::createStructure(vm, this, m_objectPrototype.get())));
630     
631     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(UndecidedShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithUndecided));
632     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(Int32Shape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithInt32));
633     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(DoubleShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithDouble));
634     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(ContiguousShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithContiguous));
635     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(ArrayStorageShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithArrayStorage));
636     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(SlowPutArrayStorageShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithSlowPutArrayStorage));
637     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(CopyOnWriteArrayWithInt32)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), CopyOnWriteArrayWithInt32));
638     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(CopyOnWriteArrayWithDouble)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), CopyOnWriteArrayWithDouble));
639     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(CopyOnWriteArrayWithContiguous)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), CopyOnWriteArrayWithContiguous));
640     for (unsigned i = 0; i < NumberOfArrayIndexingModes; ++i)
641         m_arrayStructureForIndexingShapeDuringAllocation[i] = m_originalArrayStructureForIndexingShape[i];
642
643     m_regExpPrototype.set(vm, this, RegExpPrototype::create(vm, this, RegExpPrototype::createStructure(vm, this, m_objectPrototype.get())));
644     m_regExpStructure.set(vm, this, RegExpObject::createStructure(vm, this, m_regExpPrototype.get()));
645     m_regExpMatchesArrayStructure.set(vm, this, createRegExpMatchesArrayStructure(vm, this));
646     m_regExpMatchesArrayWithGroupsStructure.set(vm, this, createRegExpMatchesArrayWithGroupsStructure(vm, this));
647
648     m_moduleRecordStructure.initLater(
649         [] (const Initializer<Structure>& init) {
650             init.set(JSModuleRecord::createStructure(init.vm, init.owner, jsNull()));
651         });
652     m_moduleNamespaceObjectStructure.initLater(
653         [] (const Initializer<Structure>& init) {
654             init.set(JSModuleNamespaceObject::createStructure(init.vm, init.owner, jsNull()));
655         });
656     m_proxyObjectStructure.initLater(
657         [] (const Initializer<Structure>& init) {
658             bool isCallable = false;
659             init.set(ProxyObject::createStructure(init.vm, init.owner, jsNull(), isCallable));
660         });
661     m_callableProxyObjectStructure.initLater(
662         [] (const Initializer<Structure>& init) {
663             bool isCallable = true;
664             init.set(ProxyObject::createStructure(init.vm, init.owner, jsNull(), isCallable));
665         });
666     m_proxyRevokeStructure.initLater(
667         [] (const Initializer<Structure>& init) {
668             init.set(ProxyRevoke::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
669         });
670
671     m_parseIntFunction.initLater(
672         [] (const Initializer<JSFunction>& init) {
673             init.set(JSFunction::create(init.vm, init.owner, 2, init.vm.propertyNames->parseInt.string(), globalFuncParseInt, ParseIntIntrinsic));
674         });
675     m_parseFloatFunction.initLater(
676         [] (const Initializer<JSFunction>& init) {
677             init.set(JSFunction::create(init.vm, init.owner, 1, init.vm.propertyNames->parseFloat.string(), globalFuncParseFloat, NoIntrinsic));
678         });
679     
680 #if ENABLE(SHARED_ARRAY_BUFFER)
681     m_sharedArrayBufferPrototype.set(vm, this, JSArrayBufferPrototype::create(vm, this, JSArrayBufferPrototype::createStructure(vm, this, m_objectPrototype.get()), ArrayBufferSharingMode::Shared));
682     m_sharedArrayBufferStructure.set(vm, this, JSArrayBuffer::createStructure(vm, this, m_sharedArrayBufferPrototype.get()));
683 #endif
684
685     m_iteratorPrototype.set(vm, this, IteratorPrototype::create(vm, this, IteratorPrototype::createStructure(vm, this, m_objectPrototype.get())));
686     m_asyncIteratorPrototype.set(vm, this, AsyncIteratorPrototype::create(vm, this, AsyncIteratorPrototype::createStructure(vm, this, m_objectPrototype.get())));
687
688     m_generatorPrototype.set(vm, this, GeneratorPrototype::create(vm, this, GeneratorPrototype::createStructure(vm, this, m_iteratorPrototype.get())));
689     m_asyncGeneratorPrototype.set(vm, this, AsyncGeneratorPrototype::create(vm, this, AsyncGeneratorPrototype::createStructure(vm, this, m_asyncIteratorPrototype.get())));
690
691 #define CREATE_PROTOTYPE_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) do { \
692         m_ ## lowerName ## Prototype.set(vm, this, capitalName##Prototype::create(vm, this, capitalName##Prototype::createStructure(vm, this, m_ ## prototypeBase ## Prototype.get()))); \
693         m_ ## properName ## Structure.set(vm, this, instanceType::createStructure(vm, this, m_ ## lowerName ## Prototype.get())); \
694     } while (0);
695     
696     FOR_EACH_SIMPLE_BUILTIN_TYPE(CREATE_PROTOTYPE_FOR_SIMPLE_TYPE)
697
698     if (UNLIKELY(Options::useBigInt()))
699         FOR_BIG_INT_BUILTIN_TYPE_WITH_CONSTRUCTOR(CREATE_PROTOTYPE_FOR_SIMPLE_TYPE)
700
701     FOR_EACH_BUILTIN_DERIVED_ITERATOR_TYPE(CREATE_PROTOTYPE_FOR_SIMPLE_TYPE)
702     
703 #undef CREATE_PROTOTYPE_FOR_SIMPLE_TYPE
704
705 #define CREATE_PROTOTYPE_FOR_LAZY_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
706     m_ ## properName ## Structure.initLater(\
707         [] (LazyClassStructure::Initializer& init) { \
708             init.setPrototype(capitalName##Prototype::create(init.vm, init.global, capitalName##Prototype::createStructure(init.vm, init.global, init.global->m_ ## prototypeBase ## Prototype.get()))); \
709             init.setStructure(instanceType::createStructure(init.vm, init.global, init.prototype)); \
710             init.setConstructor(capitalName ## Constructor::create(init.vm, capitalName ## Constructor::createStructure(init.vm, init.global, init.global->m_functionPrototype.get()), jsCast<capitalName ## Prototype*>(init.prototype), init.global->m_speciesGetterSetter.get())); \
711         });
712     
713     FOR_EACH_LAZY_BUILTIN_TYPE(CREATE_PROTOTYPE_FOR_LAZY_TYPE)
714     
715     // Constructors
716
717     ObjectConstructor* objectConstructor = ObjectConstructor::create(vm, this, ObjectConstructor::createStructure(vm, this, m_functionPrototype.get()), m_objectPrototype.get());
718     m_objectConstructor.set(vm, this, objectConstructor);
719
720     JSFunction* throwTypeErrorFunction = JSFunction::create(vm, this, 0, String(), globalFuncThrowTypeError);
721     m_throwTypeErrorFunction.set(vm, this, throwTypeErrorFunction);
722
723     JSCell* functionConstructor = FunctionConstructor::create(vm, FunctionConstructor::createStructure(vm, this, m_functionPrototype.get()), m_functionPrototype.get());
724
725     ArrayConstructor* arrayConstructor = ArrayConstructor::create(vm, this, ArrayConstructor::createStructure(vm, this, m_functionPrototype.get()), m_arrayPrototype.get(), m_speciesGetterSetter.get());
726     m_arrayConstructor.set(vm, this, arrayConstructor);
727     
728     RegExpConstructor* regExpConstructor = RegExpConstructor::create(vm, RegExpConstructor::createStructure(vm, this, m_functionPrototype.get()), m_regExpPrototype.get(), m_speciesGetterSetter.get());
729     m_regExpGlobalData.cachedResult().record(vm, this, nullptr, jsEmptyString(&vm), MatchResult(0, 0));
730     
731 #if ENABLE(SHARED_ARRAY_BUFFER)
732     JSSharedArrayBufferConstructor* sharedArrayBufferConstructor = nullptr;
733     sharedArrayBufferConstructor = JSSharedArrayBufferConstructor::create(vm, JSSharedArrayBufferConstructor::createStructure(vm, this, m_functionPrototype.get()), m_sharedArrayBufferPrototype.get(), m_speciesGetterSetter.get());
734     m_sharedArrayBufferPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, sharedArrayBufferConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
735
736     AtomicsObject* atomicsObject = AtomicsObject::create(vm, this, AtomicsObject::createStructure(vm, this, m_objectPrototype.get()));
737 #endif
738
739 #define CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
740 capitalName ## Constructor* lowerName ## Constructor = capitalName ## Constructor::create(vm, capitalName ## Constructor::createStructure(vm, this, m_functionPrototype.get()), m_ ## lowerName ## Prototype.get(), m_speciesGetterSetter.get()); \
741 m_ ## lowerName ## Prototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, lowerName ## Constructor, static_cast<unsigned>(PropertyAttribute::DontEnum)); \
742
743     FOR_EACH_SIMPLE_BUILTIN_TYPE(CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE)
744     BigIntConstructor* bigIntConstructor = nullptr;
745     if (UNLIKELY(Options::useBigInt())) {
746         bigIntConstructor = BigIntConstructor::create(vm, BigIntConstructor::createStructure(vm, this, m_functionPrototype.get()), m_bigIntPrototype.get(), m_speciesGetterSetter.get());
747         m_bigIntPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, bigIntConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
748     }
749     
750 #undef CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE
751
752     m_promiseConstructor.set(vm, this, promiseConstructor);
753     m_internalPromiseConstructor.set(vm, this, internalPromiseConstructor);
754     
755     m_evalErrorStructure.initLater(
756         [] (LazyClassStructure::Initializer& init) {
757             init.global->initializeErrorConstructor<ErrorType::EvalError>(init);
758         });
759     m_rangeErrorStructure.initLater(
760         [] (LazyClassStructure::Initializer& init) {
761             init.global->initializeErrorConstructor<ErrorType::RangeError>(init);
762         });
763     m_referenceErrorStructure.initLater(
764         [] (LazyClassStructure::Initializer& init) {
765             init.global->initializeErrorConstructor<ErrorType::ReferenceError>(init);
766         });
767     m_syntaxErrorStructure.initLater(
768         [] (LazyClassStructure::Initializer& init) {
769             init.global->initializeErrorConstructor<ErrorType::SyntaxError>(init);
770         });
771     m_typeErrorStructure.initLater(
772         [] (LazyClassStructure::Initializer& init) {
773             init.global->initializeErrorConstructor<ErrorType::TypeError>(init);
774         });
775     m_URIErrorStructure.initLater(
776         [] (LazyClassStructure::Initializer& init) {
777             init.global->initializeErrorConstructor<ErrorType::URIError>(init);
778         });
779
780     m_generatorFunctionPrototype.set(vm, this, GeneratorFunctionPrototype::create(vm, GeneratorFunctionPrototype::createStructure(vm, this, m_functionPrototype.get())));
781     GeneratorFunctionConstructor* generatorFunctionConstructor = GeneratorFunctionConstructor::create(vm, GeneratorFunctionConstructor::createStructure(vm, this, functionConstructor), m_generatorFunctionPrototype.get());
782     m_generatorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, generatorFunctionConstructor, PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
783     m_generatorFunctionStructure.set(vm, this, JSGeneratorFunction::createStructure(vm, this, m_generatorFunctionPrototype.get()));
784
785     m_generatorPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_generatorFunctionPrototype.get(), PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
786     m_generatorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->prototype, m_generatorPrototype.get(), PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
787
788     m_asyncFunctionPrototype.set(vm, this, AsyncFunctionPrototype::create(vm, AsyncFunctionPrototype::createStructure(vm, this, m_functionPrototype.get())));
789     AsyncFunctionConstructor* asyncFunctionConstructor = AsyncFunctionConstructor::create(vm, AsyncFunctionConstructor::createStructure(vm, this, functionConstructor), m_asyncFunctionPrototype.get());
790     m_asyncFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, asyncFunctionConstructor, PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
791     m_asyncFunctionStructure.set(vm, this, JSAsyncFunction::createStructure(vm, this, m_asyncFunctionPrototype.get()));
792
793     m_asyncGeneratorFunctionPrototype.set(vm, this, AsyncGeneratorFunctionPrototype::create(vm, AsyncGeneratorFunctionPrototype::createStructure(vm, this, m_functionPrototype.get())));
794     AsyncGeneratorFunctionConstructor* asyncGeneratorFunctionConstructor = AsyncGeneratorFunctionConstructor::create(vm, AsyncGeneratorFunctionConstructor::createStructure(vm, this, functionConstructor), m_asyncGeneratorFunctionPrototype.get());
795     m_asyncGeneratorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, asyncGeneratorFunctionConstructor, PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
796     m_asyncGeneratorFunctionStructure.set(vm, this, JSAsyncGeneratorFunction::createStructure(vm, this, m_asyncGeneratorFunctionPrototype.get()));
797
798     m_asyncGeneratorPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_asyncGeneratorFunctionPrototype.get(), PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
799     m_asyncGeneratorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->prototype, m_asyncGeneratorPrototype.get(), PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
800     
801     m_objectPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, objectConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
802     m_functionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, functionConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
803     m_arrayPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, arrayConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
804     m_regExpPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, regExpConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
805     
806     putDirectWithoutTransition(vm, vm.propertyNames->Object, objectConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
807     putDirectWithoutTransition(vm, vm.propertyNames->Function, functionConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
808     putDirectWithoutTransition(vm, vm.propertyNames->Array, arrayConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
809     putDirectWithoutTransition(vm, vm.propertyNames->RegExp, regExpConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
810
811     putDirectWithoutTransition(vm, vm.propertyNames->builtinNames().ObjectPrivateName(), objectConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly);
812     putDirectWithoutTransition(vm, vm.propertyNames->builtinNames().ArrayPrivateName(), arrayConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly);
813
814 #if ENABLE(SHARED_ARRAY_BUFFER)
815     putDirectWithoutTransition(vm, vm.propertyNames->SharedArrayBuffer, sharedArrayBufferConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
816     putDirectWithoutTransition(vm, Identifier::fromString(exec, "Atomics"), atomicsObject, static_cast<unsigned>(PropertyAttribute::DontEnum));
817 #endif
818
819 #define PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
820 putDirectWithoutTransition(vm, vm.propertyNames-> jsName, lowerName ## Constructor, static_cast<unsigned>(PropertyAttribute::DontEnum)); \
821
822     FOR_EACH_SIMPLE_BUILTIN_TYPE_WITH_CONSTRUCTOR(PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE)
823     if (UNLIKELY(Options::useBigInt()))
824         FOR_BIG_INT_BUILTIN_TYPE_WITH_CONSTRUCTOR(PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE)
825
826 #undef PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE
827     m_iteratorResultObjectStructure.initLater(
828         [] (const Initializer<Structure>& init) {
829             init.set(createIteratorResultObjectStructure(init.vm, *init.owner));
830         });
831     
832     m_evalFunction.initLater(
833         [] (const Initializer<JSFunction>& init) {
834             init.set(JSFunction::create(init.vm, init.owner, 1, init.vm.propertyNames->eval.string(), globalFuncEval, NoIntrinsic));
835         });
836     
837 #if ENABLE(INTL)
838     m_collatorStructure.initLater(
839         [] (const Initializer<Structure>& init) {
840             JSGlobalObject* globalObject = jsCast<JSGlobalObject*>(init.owner);
841             IntlCollatorPrototype* collatorPrototype = IntlCollatorPrototype::create(init.vm, globalObject, IntlCollatorPrototype::createStructure(init.vm, globalObject, globalObject->objectPrototype()));
842             init.set(IntlCollator::createStructure(init.vm, globalObject, collatorPrototype));
843         });
844     m_numberFormatStructure.initLater(
845         [] (const Initializer<Structure>& init) {
846             JSGlobalObject* globalObject = jsCast<JSGlobalObject*>(init.owner);
847             IntlNumberFormatPrototype* numberFormatPrototype = IntlNumberFormatPrototype::create(init.vm, globalObject, IntlNumberFormatPrototype::createStructure(init.vm, globalObject, globalObject->objectPrototype()));
848             init.set(IntlNumberFormat::createStructure(init.vm, globalObject, numberFormatPrototype));
849         });
850     m_dateTimeFormatStructure.initLater(
851         [] (const Initializer<Structure>& init) {
852             JSGlobalObject* globalObject = jsCast<JSGlobalObject*>(init.owner);
853             IntlDateTimeFormatPrototype* dateTimeFormatPrototype = IntlDateTimeFormatPrototype::create(init.vm, globalObject, IntlDateTimeFormatPrototype::createStructure(init.vm, globalObject, globalObject->objectPrototype()));
854             init.set(IntlDateTimeFormat::createStructure(init.vm, globalObject, dateTimeFormatPrototype));
855         });
856     m_pluralRulesStructure.initLater(
857         [] (const Initializer<Structure>& init) {
858             JSGlobalObject* globalObject = jsCast<JSGlobalObject*>(init.owner);
859             IntlPluralRulesPrototype* pluralRulesPrototype = IntlPluralRulesPrototype::create(init.vm, globalObject, IntlPluralRulesPrototype::createStructure(init.vm, globalObject, globalObject->objectPrototype()));
860             init.set(IntlPluralRules::createStructure(init.vm, globalObject, pluralRulesPrototype));
861         });
862
863     IntlObject* intl = IntlObject::create(vm, IntlObject::createStructure(vm, this, m_objectPrototype.get()));
864     putDirectWithoutTransition(vm, vm.propertyNames->Intl, intl, static_cast<unsigned>(PropertyAttribute::DontEnum));
865 #endif // ENABLE(INTL)
866
867     m_moduleLoader.initLater(
868         [] (const Initializer<JSModuleLoader>& init) {
869             auto catchScope = DECLARE_CATCH_SCOPE(init.vm);
870             init.set(JSModuleLoader::create(init.owner->globalExec(), init.vm, init.owner, JSModuleLoader::createStructure(init.vm, init.owner, jsNull())));
871             catchScope.releaseAssertNoException();
872         });
873     if (Options::exposeInternalModuleLoader())
874         putDirectWithoutTransition(vm, vm.propertyNames->Loader, moduleLoader(), static_cast<unsigned>(PropertyAttribute::DontEnum));
875
876     JSFunction* builtinLog = JSFunction::create(vm, this, 1, vm.propertyNames->emptyIdentifier.string(), globalFuncBuiltinLog);
877     JSFunction* builtinDescribe = JSFunction::create(vm, this, 1, vm.propertyNames->emptyIdentifier.string(), globalFuncBuiltinDescribe);
878
879     JSFunction* privateFuncTrunc = JSFunction::create(vm, this, 0, String(), mathProtoFuncTrunc, TruncIntrinsic);
880
881     JSFunction* privateFuncPropertyIsEnumerable = JSFunction::create(vm, this, 0, String(), globalFuncPropertyIsEnumerable);
882     JSFunction* privateFuncOwnKeys = JSFunction::create(vm, this, 0, String(), globalFuncOwnKeys);
883     JSFunction* privateFuncImportModule = JSFunction::create(vm, this, 0, String(), globalFuncImportModule);
884     JSFunction* privateFuncMakeTypeError = JSFunction::create(vm, this, 0, String(), globalFuncMakeTypeError);
885     JSFunction* privateFuncTypedArrayLength = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncLength);
886     JSFunction* privateFuncTypedArrayGetOriginalConstructor = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncGetOriginalConstructor);
887     JSFunction* privateFuncTypedArraySort = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncSort);
888     JSFunction* privateFuncIsTypedArrayView = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncIsTypedArrayView, IsTypedArrayViewIntrinsic);
889     JSFunction* privateFuncTypedArraySubarrayCreate = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncSubarrayCreate);
890     JSFunction* privateFuncIsBoundFunction = JSFunction::create(vm, this, 0, String(), isBoundFunction);
891     JSFunction* privateFuncHasInstanceBoundFunction = JSFunction::create(vm, this, 0, String(), hasInstanceBoundFunction);
892     JSFunction* privateFuncInstanceOf = JSFunction::create(vm, this, 0, String(), objectPrivateFuncInstanceOf);
893     JSFunction* privateFuncThisTimeValue = JSFunction::create(vm, this, 0, String(), dateProtoFuncGetTime);
894 #if ENABLE(INTL)
895     JSFunction* privateFuncDateTimeFormat = JSFunction::create(vm, this, 0, String(), globalFuncDateTimeFormat);
896 #endif
897     JSFunction* privateFuncIsArrayConstructor = JSFunction::create(vm, this, 0, String(), arrayConstructorPrivateFuncIsArrayConstructor);
898     JSFunction* privateFuncIsArraySlow = JSFunction::create(vm, this, 0, String(), arrayConstructorPrivateFuncIsArraySlow);
899     JSFunction* privateFuncConcatMemcpy = JSFunction::create(vm, this, 0, String(), arrayProtoPrivateFuncConcatMemcpy);
900     JSFunction* privateFuncAppendMemcpy = JSFunction::create(vm, this, 0, String(), arrayProtoPrivateFuncAppendMemcpy);
901     JSFunction* privateFuncMapBucketHead = JSFunction::create(vm, this, 0, String(), mapPrivateFuncMapBucketHead, JSMapBucketHeadIntrinsic);
902     JSFunction* privateFuncMapBucketNext = JSFunction::create(vm, this, 0, String(), mapPrivateFuncMapBucketNext, JSMapBucketNextIntrinsic);
903     JSFunction* privateFuncMapBucketKey = JSFunction::create(vm, this, 0, String(), mapPrivateFuncMapBucketKey, JSMapBucketKeyIntrinsic);
904     JSFunction* privateFuncMapBucketValue = JSFunction::create(vm, this, 0, String(), mapPrivateFuncMapBucketValue, JSMapBucketValueIntrinsic);
905     JSFunction* privateFuncSetBucketHead = JSFunction::create(vm, this, 0, String(), setPrivateFuncSetBucketHead, JSSetBucketHeadIntrinsic);
906     JSFunction* privateFuncSetBucketNext = JSFunction::create(vm, this, 0, String(), setPrivateFuncSetBucketNext, JSSetBucketNextIntrinsic);
907     JSFunction* privateFuncSetBucketKey = JSFunction::create(vm, this, 0, String(), setPrivateFuncSetBucketKey, JSSetBucketKeyIntrinsic);
908
909     JSObject* regExpProtoFlagsGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->flags);
910     catchScope.assertNoException();
911     JSObject* regExpProtoGlobalGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->global);
912     catchScope.assertNoException();
913     m_regExpProtoGlobalGetter.set(vm, this, regExpProtoGlobalGetterObject);
914     JSObject* regExpProtoIgnoreCaseGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->ignoreCase);
915     catchScope.assertNoException();
916     JSObject* regExpProtoMultilineGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->multiline);
917     catchScope.assertNoException();
918     JSObject* regExpProtoSourceGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->source);
919     catchScope.assertNoException();
920     JSObject* regExpProtoStickyGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->sticky);
921     catchScope.assertNoException();
922     JSObject* regExpProtoUnicodeGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->unicode);
923     catchScope.assertNoException();
924     m_regExpProtoUnicodeGetter.set(vm, this, regExpProtoUnicodeGetterObject);
925     JSObject* builtinRegExpExec = asObject(m_regExpPrototype->getDirect(vm, vm.propertyNames->exec).asCell());
926     m_regExpProtoExec.set(vm, this, builtinRegExpExec);
927     JSObject* regExpSymbolReplace = asObject(m_regExpPrototype->getDirect(vm, vm.propertyNames->replaceSymbol).asCell());
928     m_regExpProtoSymbolReplace.set(vm, this, regExpSymbolReplace);
929
930 #define CREATE_PRIVATE_GLOBAL_FUNCTION(name, code) JSFunction* name ## PrivateFunction = JSFunction::create(vm, code ## CodeGenerator(vm), this);
931     JSC_FOREACH_BUILTIN_FUNCTION_PRIVATE_GLOBAL_NAME(CREATE_PRIVATE_GLOBAL_FUNCTION)
932 #undef CREATE_PRIVATE_GLOBAL_FUNCTION
933
934     JSObject* arrayIteratorPrototype = ArrayIteratorPrototype::create(vm, this, ArrayIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
935     createArrayIteratorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, arrayIteratorPrototype);
936
937     JSObject* asyncFromSyncIteratorPrototype = AsyncFromSyncIteratorPrototype::create(vm, this, AsyncFromSyncIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
938     AsyncFromSyncIteratorConstructorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, asyncFromSyncIteratorPrototype);
939
940     JSObject* mapIteratorPrototype = MapIteratorPrototype::create(vm, this, MapIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
941     createMapIteratorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, mapIteratorPrototype);
942
943     JSObject* setIteratorPrototype = SetIteratorPrototype::create(vm, this, SetIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
944     createSetIteratorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, setIteratorPrototype);
945
946     GlobalPropertyInfo staticGlobals[] = {
947 #define INIT_PRIVATE_GLOBAL(name, code) GlobalPropertyInfo(vm.propertyNames->builtinNames().name ## PrivateName(), name ## PrivateFunction, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
948         JSC_FOREACH_BUILTIN_FUNCTION_PRIVATE_GLOBAL_NAME(INIT_PRIVATE_GLOBAL)
949 #undef INIT_PRIVATE_GLOBAL
950         GlobalPropertyInfo(vm.propertyNames->NaN, jsNaN(), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
951         GlobalPropertyInfo(vm.propertyNames->Infinity, jsNumber(std::numeric_limits<double>::infinity()), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
952         GlobalPropertyInfo(vm.propertyNames->undefinedKeyword, jsUndefined(), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
953         GlobalPropertyInfo(vm.propertyNames->builtinNames().propertyIsEnumerablePrivateName(), privateFuncPropertyIsEnumerable, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
954         GlobalPropertyInfo(vm.propertyNames->builtinNames().ownKeysPrivateName(), privateFuncOwnKeys, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
955         GlobalPropertyInfo(vm.propertyNames->builtinNames().importModulePrivateName(), privateFuncImportModule, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
956         GlobalPropertyInfo(vm.propertyNames->builtinNames().enqueueJobPrivateName(), JSFunction::create(vm, this, 0, String(), enqueueJob), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
957         GlobalPropertyInfo(vm.propertyNames->builtinNames().makeTypeErrorPrivateName(), privateFuncMakeTypeError, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
958         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArrayLengthPrivateName(), privateFuncTypedArrayLength, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
959         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArrayGetOriginalConstructorPrivateName(), privateFuncTypedArrayGetOriginalConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
960         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArraySortPrivateName(), privateFuncTypedArraySort, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
961         GlobalPropertyInfo(vm.propertyNames->builtinNames().isTypedArrayViewPrivateName(), privateFuncIsTypedArrayView, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
962         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArraySubarrayCreatePrivateName(), privateFuncTypedArraySubarrayCreate, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
963         GlobalPropertyInfo(vm.propertyNames->builtinNames().isBoundFunctionPrivateName(), privateFuncIsBoundFunction, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
964         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasInstanceBoundFunctionPrivateName(), privateFuncHasInstanceBoundFunction, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
965         GlobalPropertyInfo(vm.propertyNames->builtinNames().instanceOfPrivateName(), privateFuncInstanceOf, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
966         GlobalPropertyInfo(vm.propertyNames->builtinNames().BuiltinLogPrivateName(), builtinLog, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
967         GlobalPropertyInfo(vm.propertyNames->builtinNames().BuiltinDescribePrivateName(), builtinDescribe, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
968         GlobalPropertyInfo(vm.propertyNames->builtinNames().RegExpPrivateName(), regExpConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
969         GlobalPropertyInfo(vm.propertyNames->builtinNames().truncPrivateName(), privateFuncTrunc, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
970         GlobalPropertyInfo(vm.propertyNames->builtinNames().PromisePrivateName(), promiseConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
971         GlobalPropertyInfo(vm.propertyNames->builtinNames().InternalPromisePrivateName(), internalPromiseConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
972
973         GlobalPropertyInfo(vm.propertyNames->builtinNames().repeatCharacterPrivateName(), JSFunction::create(vm, this, 2, String(), stringProtoFuncRepeatCharacter), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
974         GlobalPropertyInfo(vm.propertyNames->builtinNames().isArrayPrivateName(), arrayConstructor->getDirect(vm, vm.propertyNames->isArray), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
975         GlobalPropertyInfo(vm.propertyNames->builtinNames().isArraySlowPrivateName(), privateFuncIsArraySlow, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
976         GlobalPropertyInfo(vm.propertyNames->builtinNames().isArrayConstructorPrivateName(), privateFuncIsArrayConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
977         GlobalPropertyInfo(vm.propertyNames->builtinNames().concatMemcpyPrivateName(), privateFuncConcatMemcpy, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
978         GlobalPropertyInfo(vm.propertyNames->builtinNames().appendMemcpyPrivateName(), privateFuncAppendMemcpy, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
979
980         GlobalPropertyInfo(vm.propertyNames->builtinNames().hostPromiseRejectionTrackerPrivateName(), JSFunction::create(vm, this, 2, String(), globalFuncHostPromiseRejectionTracker), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
981         GlobalPropertyInfo(vm.propertyNames->builtinNames().InspectorInstrumentationPrivateName(), InspectorInstrumentationObject::create(vm, this, InspectorInstrumentationObject::createStructure(vm, this, m_objectPrototype.get())), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
982         GlobalPropertyInfo(vm.propertyNames->builtinNames().SetPrivateName(), setConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
983         GlobalPropertyInfo(vm.propertyNames->builtinNames().thisTimeValuePrivateName(), privateFuncThisTimeValue, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
984 #if ENABLE(INTL)
985         GlobalPropertyInfo(vm.propertyNames->builtinNames().dateTimeFormatPrivateName(), privateFuncDateTimeFormat, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
986 #endif // ENABLE(INTL)
987
988         GlobalPropertyInfo(vm.propertyNames->builtinNames().isConstructorPrivateName(), JSFunction::create(vm, this, 1, String(), esSpecIsConstructor, NoIntrinsic), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
989
990         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoFlagsGetterPrivateName(), regExpProtoFlagsGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
991         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoGlobalGetterPrivateName(), regExpProtoGlobalGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
992         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoIgnoreCaseGetterPrivateName(), regExpProtoIgnoreCaseGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
993         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoMultilineGetterPrivateName(), regExpProtoMultilineGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
994         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoSourceGetterPrivateName(), regExpProtoSourceGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
995         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoStickyGetterPrivateName(), regExpProtoStickyGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
996         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoUnicodeGetterPrivateName(), regExpProtoUnicodeGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
997
998         // RegExp.prototype helpers.
999         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpBuiltinExecPrivateName(), builtinRegExpExec, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1000         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpCreatePrivateName(), JSFunction::create(vm, this, 2, String(), esSpecRegExpCreate, NoIntrinsic), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1001         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpMatchFastPrivateName(), JSFunction::create(vm, this, 1, String(), regExpProtoFuncMatchFast, RegExpMatchFastIntrinsic), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1002         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpSearchFastPrivateName(), JSFunction::create(vm, this, 1, String(), regExpProtoFuncSearchFast), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1003         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpSplitFastPrivateName(), JSFunction::create(vm, this, 2, String(), regExpProtoFuncSplitFast), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1004         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpPrototypeSymbolReplacePrivateName(), m_regExpPrototype->getDirect(vm, vm.propertyNames->replaceSymbol), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1005         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpTestFastPrivateName(), JSFunction::create(vm, this, 1, String(), regExpProtoFuncTestFast, RegExpTestFastIntrinsic), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1006
1007         // String.prototype helpers.
1008         GlobalPropertyInfo(vm.propertyNames->builtinNames().stringIncludesInternalPrivateName(), JSFunction::create(vm, this, 1, String(), builtinStringIncludesInternal), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1009         GlobalPropertyInfo(vm.propertyNames->builtinNames().stringSplitFastPrivateName(), JSFunction::create(vm, this, 2, String(), stringProtoFuncSplitFast), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1010         GlobalPropertyInfo(vm.propertyNames->builtinNames().stringSubstrInternalPrivateName(), JSFunction::create(vm, this, 2, String(), builtinStringSubstrInternal), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1011
1012         // Function prototype helpers.
1013         GlobalPropertyInfo(vm.propertyNames->builtinNames().makeBoundFunctionPrivateName(), JSFunction::create(vm, this, 5, String(), makeBoundFunction), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1014         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasOwnLengthPropertyPrivateName(), JSFunction::create(vm, this, 1, String(), hasOwnLengthProperty), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1015
1016         // Map and Set helpers.
1017         GlobalPropertyInfo(vm.propertyNames->builtinNames().mapBucketHeadPrivateName(), privateFuncMapBucketHead, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1018         GlobalPropertyInfo(vm.propertyNames->builtinNames().mapBucketNextPrivateName(), privateFuncMapBucketNext, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1019         GlobalPropertyInfo(vm.propertyNames->builtinNames().mapBucketKeyPrivateName(), privateFuncMapBucketKey, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1020         GlobalPropertyInfo(vm.propertyNames->builtinNames().mapBucketValuePrivateName(), privateFuncMapBucketValue, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1021         GlobalPropertyInfo(vm.propertyNames->builtinNames().setBucketHeadPrivateName(), privateFuncSetBucketHead, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1022         GlobalPropertyInfo(vm.propertyNames->builtinNames().setBucketNextPrivateName(), privateFuncSetBucketNext, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1023         GlobalPropertyInfo(vm.propertyNames->builtinNames().setBucketKeyPrivateName(), privateFuncSetBucketKey, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1024 #if ENABLE(WEBASSEMBLY) && ENABLE(WEBASSEMBLY_STREAMING_API)
1025         // WebAssembly Streaming API
1026         GlobalPropertyInfo(vm.propertyNames->builtinNames().webAssemblyCompileStreamingInternalPrivateName(), JSFunction::create(vm, this, 1, String(), webAssemblyCompileStreamingInternal), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1027         GlobalPropertyInfo(vm.propertyNames->builtinNames().webAssemblyInstantiateStreamingInternalPrivateName(), JSFunction::create(vm, this, 1, String(), webAssemblyInstantiateStreamingInternal), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1028 #endif
1029 #if !ASSERT_DISABLED
1030         GlobalPropertyInfo(vm.propertyNames->builtinNames().assertPrivateName(), JSFunction::create(vm, this, 1, String(), assertCall), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1031 #endif
1032     };
1033     addStaticGlobals(staticGlobals, WTF_ARRAY_LENGTH(staticGlobals));
1034     
1035     m_specialPointers[Special::CallFunction] = m_callFunction.get();
1036     m_specialPointers[Special::ApplyFunction] = m_applyFunction.get();
1037     m_specialPointers[Special::ObjectConstructor] = objectConstructor;
1038     m_specialPointers[Special::ArrayConstructor] = arrayConstructor;
1039
1040     m_linkTimeConstants[static_cast<unsigned>(LinkTimeConstant::ThrowTypeErrorFunction)] = m_throwTypeErrorFunction.get();
1041
1042     if (UNLIKELY(Options::useDollarVM()))
1043         exposeDollarVM(vm);
1044
1045 #if ENABLE(WEBASSEMBLY)
1046     if (Wasm::isSupported()) {
1047         auto* webAssemblyPrototype = WebAssemblyPrototype::create(vm, this, WebAssemblyPrototype::createStructure(vm, this, m_objectPrototype.get()));
1048         m_webAssemblyModuleRecordStructure.initLater(
1049             [] (const Initializer<Structure>& init) {
1050                 init.set(WebAssemblyModuleRecord::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
1051             });
1052         m_webAssemblyFunctionStructure.initLater(
1053             [] (const Initializer<Structure>& init) {
1054                 init.set(WebAssemblyFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
1055             });
1056         m_jsToWasmICCalleeStructure.initLater(
1057             [] (const Initializer<Structure>& init) {
1058                 init.set(JSToWasmICCallee::createStructure(init.vm, init.owner, JSValue()));
1059             });
1060         m_webAssemblyWrapperFunctionStructure.initLater(
1061             [] (const Initializer<Structure>& init) {
1062                 init.set(WebAssemblyWrapperFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
1063             });
1064         m_webAssemblyToJSCalleeStructure.initLater(
1065             [] (const Initializer<Structure>& init) {
1066                 init.set(WebAssemblyToJSCallee::createStructure(init.vm, init.owner, jsNull()));
1067             });
1068         auto* webAssembly = JSWebAssembly::create(vm, this, JSWebAssembly::createStructure(vm, this, webAssemblyPrototype));
1069         putDirectWithoutTransition(vm, Identifier::fromString(exec, "WebAssembly"), webAssembly, static_cast<unsigned>(PropertyAttribute::DontEnum));
1070
1071 #define CREATE_WEBASSEMBLY_PROTOTYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
1072     m_ ## properName ## Structure.initLater(\
1073         [] (LazyClassStructure::Initializer& init) { \
1074             init.setPrototype(capitalName##Prototype::create(init.vm, init.global, capitalName##Prototype::createStructure(init.vm, init.global, init.global->prototypeBase ## Prototype()))); \
1075             init.setStructure(instanceType::createStructure(init.vm, init.global, init.prototype)); \
1076             init.setConstructor(capitalName ## Constructor::create(init.vm, capitalName ## Constructor::createStructure(init.vm, init.global, init.global->functionPrototype()), jsCast<capitalName ## Prototype*>(init.prototype))); \
1077         });
1078
1079         FOR_EACH_WEBASSEMBLY_CONSTRUCTOR_TYPE(CREATE_WEBASSEMBLY_PROTOTYPE)
1080
1081 #undef CREATE_WEBASSEMBLY_CONSTRUCTOR
1082     }
1083 #endif // ENABLE(WEBASSEMBLY)
1084
1085 #undef CREATE_PROTOTYPE_FOR_LAZY_TYPE
1086
1087     auto setupAdaptiveWatchpoint = [&] (JSObject* base, const Identifier& ident) -> ObjectPropertyCondition {
1088         // Performing these gets should not throw.
1089         ExecState* exec = globalExec();
1090         PropertySlot slot(base, PropertySlot::InternalMethodType::Get);
1091         bool result = base->getOwnPropertySlot(base, exec, ident, slot);
1092         ASSERT_UNUSED(result, result);
1093         catchScope.assertNoException();
1094         RELEASE_ASSERT(slot.isCacheableValue());
1095         JSValue functionValue = slot.getValue(exec, ident);
1096         catchScope.assertNoException();
1097         ASSERT(jsDynamicCast<JSFunction*>(vm, functionValue));
1098
1099         ObjectPropertyCondition condition = generateConditionForSelfEquivalence(m_vm, nullptr, base, ident.impl());
1100         RELEASE_ASSERT(condition.requiredValue() == functionValue);
1101
1102         bool isWatchable = condition.isWatchable(PropertyCondition::EnsureWatchability);
1103         RELEASE_ASSERT(isWatchable); // We allow this to install the necessary watchpoints.
1104
1105         return condition;
1106     };
1107
1108     {
1109         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(arrayIteratorPrototype, m_vm.propertyNames->next);
1110         m_arrayIteratorPrototypeNext = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_arrayIteratorProtocolWatchpoint);
1111         m_arrayIteratorPrototypeNext->install(vm);
1112     }
1113     {
1114         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(this->arrayPrototype(), m_vm.propertyNames->iteratorSymbol);
1115         m_arrayPrototypeSymbolIteratorWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_arrayIteratorProtocolWatchpoint);
1116         m_arrayPrototypeSymbolIteratorWatchpoint->install(vm);
1117     }
1118
1119     {
1120         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(mapIteratorPrototype, m_vm.propertyNames->next);
1121         m_mapIteratorPrototypeNextWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_mapIteratorProtocolWatchpoint);
1122         m_mapIteratorPrototypeNextWatchpoint->install(vm);
1123     }
1124     {
1125         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_mapPrototype.get(), m_vm.propertyNames->iteratorSymbol);
1126         m_mapPrototypeSymbolIteratorWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_mapIteratorProtocolWatchpoint);
1127         m_mapPrototypeSymbolIteratorWatchpoint->install(vm);
1128     }
1129
1130     {
1131         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(setIteratorPrototype, m_vm.propertyNames->next);
1132         m_setIteratorPrototypeNextWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_setIteratorProtocolWatchpoint);
1133         m_setIteratorPrototypeNextWatchpoint->install(vm);
1134     }
1135     {
1136         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_setPrototype.get(), m_vm.propertyNames->iteratorSymbol);
1137         m_setPrototypeSymbolIteratorWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_setIteratorProtocolWatchpoint);
1138         m_setPrototypeSymbolIteratorWatchpoint->install(vm);
1139     }
1140
1141     {
1142         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_stringIteratorPrototype.get(), m_vm.propertyNames->next);
1143         m_stringIteratorPrototypeNextWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_stringIteratorProtocolWatchpoint);
1144         m_stringIteratorPrototypeNextWatchpoint->install(vm);
1145     }
1146     {
1147         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_stringPrototype.get(), m_vm.propertyNames->iteratorSymbol);
1148         m_stringPrototypeSymbolIteratorWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_stringIteratorProtocolWatchpoint);
1149         m_stringPrototypeSymbolIteratorWatchpoint->install(vm);
1150     }
1151
1152     {
1153         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_mapPrototype.get(), m_vm.propertyNames->set);
1154         m_mapPrototypeSetWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_mapSetWatchpoint);
1155         m_mapPrototypeSetWatchpoint->install(vm);
1156     }
1157
1158     {
1159         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_setPrototype.get(), m_vm.propertyNames->add);
1160         m_setPrototypeAddWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_setAddWatchpoint);
1161         m_setPrototypeAddWatchpoint->install(vm);
1162     }
1163
1164     // Unfortunately, the prototype objects of the builtin objects can be touched from concurrent compilers. So eagerly initialize them only if we use JIT.
1165     if (VM::canUseJIT()) {
1166         this->booleanPrototype();
1167         auto* numberPrototype = this->numberPrototype();
1168         this->symbolPrototype();
1169
1170         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(numberPrototype, m_vm.propertyNames->toString);
1171         m_numberPrototypeToStringWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_numberToStringWatchpoint);
1172         m_numberPrototypeToStringWatchpoint->install(vm);
1173         m_numberProtoToStringFunction.set(vm, this, jsCast<JSFunction*>(numberPrototype->getDirect(vm, vm.propertyNames->toString)));
1174     }
1175
1176     fixupPrototypeChainWithObjectPrototype(vm);
1177 }
1178
1179 bool JSGlobalObject::put(JSCell* cell, ExecState* exec, PropertyName propertyName, JSValue value, PutPropertySlot& slot)
1180 {
1181     VM& vm = exec->vm();
1182     auto scope = DECLARE_THROW_SCOPE(vm);
1183     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(cell);
1184     ASSERT(!Heap::heap(value) || Heap::heap(value) == Heap::heap(thisObject));
1185
1186     if (UNLIKELY(isThisValueAltered(slot, thisObject)))
1187         RELEASE_AND_RETURN(scope, ordinarySetSlow(exec, thisObject, propertyName, value, slot.thisValue(), slot.isStrictMode()));
1188
1189     bool shouldThrowReadOnlyError = slot.isStrictMode();
1190     bool ignoreReadOnlyErrors = false;
1191     bool putResult = false;
1192     bool done = symbolTablePutTouchWatchpointSet(thisObject, exec, propertyName, value, shouldThrowReadOnlyError, ignoreReadOnlyErrors, putResult);
1193     EXCEPTION_ASSERT((!!scope.exception() == (done && !putResult)) || !shouldThrowReadOnlyError);
1194     if (done)
1195         return putResult;
1196     RELEASE_AND_RETURN(scope, Base::put(thisObject, exec, propertyName, value, slot));
1197 }
1198
1199 bool JSGlobalObject::defineOwnProperty(JSObject* object, ExecState* exec, PropertyName propertyName, const PropertyDescriptor& descriptor, bool shouldThrow)
1200 {
1201     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(object);
1202     PropertySlot slot(thisObject, PropertySlot::InternalMethodType::VMInquiry);
1203     // silently ignore attempts to add accessors aliasing vars.
1204     if (descriptor.isAccessorDescriptor() && symbolTableGet(thisObject, propertyName, slot))
1205         return false;
1206     return Base::defineOwnProperty(thisObject, exec, propertyName, descriptor, shouldThrow);
1207 }
1208
1209 void JSGlobalObject::addGlobalVar(const Identifier& ident)
1210 {
1211     ConcurrentJSLocker locker(symbolTable()->m_lock);
1212     SymbolTableEntry entry = symbolTable()->get(locker, ident.impl());
1213     if (!entry.isNull())
1214         return;
1215     
1216     ScopeOffset offset = symbolTable()->takeNextScopeOffset(locker);
1217     SymbolTableEntry newEntry(VarOffset(offset), 0);
1218     newEntry.prepareToWatch();
1219     symbolTable()->add(locker, ident.impl(), WTFMove(newEntry));
1220     
1221     ScopeOffset offsetForAssert = addVariables(1, jsUndefined());
1222     RELEASE_ASSERT(offsetForAssert == offset);
1223 }
1224
1225 void JSGlobalObject::addFunction(ExecState* exec, const Identifier& propertyName)
1226 {
1227     VM& vm = exec->vm();
1228     VM::DeletePropertyModeScope scope(vm, VM::DeletePropertyMode::IgnoreConfigurable);
1229     methodTable(vm)->deleteProperty(this, exec, propertyName);
1230     addGlobalVar(propertyName);
1231 }
1232
1233 void JSGlobalObject::setGlobalScopeExtension(JSScope* scope)
1234 {
1235     m_globalScopeExtension.set(vm(), this, scope);
1236 }
1237
1238 void JSGlobalObject::clearGlobalScopeExtension()
1239 {
1240     m_globalScopeExtension.clear();
1241 }
1242
1243 static inline JSObject* lastInPrototypeChain(VM& vm, JSObject* object)
1244 {
1245     JSObject* o = object;
1246     while (o->getPrototypeDirect(vm).isObject())
1247         o = asObject(o->getPrototypeDirect(vm));
1248     return o;
1249 }
1250
1251 // Private namespace for helpers for JSGlobalObject::haveABadTime()
1252 namespace {
1253
1254 class GlobalObjectDependencyFinder : public MarkedBlock::VoidFunctor {
1255 public:
1256     GlobalObjectDependencyFinder(VM& vm)
1257         : m_vm(vm)
1258     { }
1259
1260     IterationStatus operator()(HeapCell*, HeapCell::Kind) const;
1261
1262     void addDependency(JSGlobalObject* key, JSGlobalObject* dependent);
1263     HashSet<JSGlobalObject*>* dependentsFor(JSGlobalObject* key);
1264
1265 private:
1266     void visit(JSObject*);
1267
1268     VM& m_vm;
1269     HashMap<JSGlobalObject*, HashSet<JSGlobalObject*>> m_dependencies;
1270 };
1271
1272 inline void GlobalObjectDependencyFinder::addDependency(JSGlobalObject* key, JSGlobalObject* dependent)
1273 {
1274     auto keyResult = m_dependencies.add(key, HashSet<JSGlobalObject*>());
1275     keyResult.iterator->value.add(dependent);
1276 }
1277
1278 inline HashSet<JSGlobalObject*>* GlobalObjectDependencyFinder::dependentsFor(JSGlobalObject* key)
1279 {
1280     auto iterator = m_dependencies.find(key);
1281     if (iterator == m_dependencies.end())
1282         return nullptr;
1283     return &iterator->value;
1284 }
1285
1286 inline void GlobalObjectDependencyFinder::visit(JSObject* object)
1287 {
1288     VM& vm = m_vm;
1289
1290     if (!object->mayBePrototype())
1291         return;
1292
1293     JSObject* current = object;
1294     JSGlobalObject* objectGlobalObject = object->globalObject(vm);
1295     do {
1296         JSValue prototypeValue = current->getPrototypeDirect(vm);
1297         if (prototypeValue.isNull())
1298             return;
1299         current = asObject(prototypeValue);
1300
1301         JSGlobalObject* protoGlobalObject = current->globalObject(vm);
1302         if (protoGlobalObject != objectGlobalObject)
1303             addDependency(protoGlobalObject, objectGlobalObject);
1304     } while (true);
1305 }
1306
1307 IterationStatus GlobalObjectDependencyFinder::operator()(HeapCell* cell, HeapCell::Kind kind) const
1308 {
1309     if (isJSCellKind(kind) && static_cast<JSCell*>(cell)->isObject()) {
1310         // FIXME: This const_cast exists because this isn't a C++ lambda.
1311         // https://bugs.webkit.org/show_bug.cgi?id=159644
1312         const_cast<GlobalObjectDependencyFinder*>(this)->visit(jsCast<JSObject*>(static_cast<JSCell*>(cell)));
1313     }
1314     return IterationStatus::Continue;
1315 }
1316
1317 enum class BadTimeFinderMode {
1318     SingleGlobal,
1319     MultipleGlobals
1320 };
1321
1322 template<BadTimeFinderMode mode>
1323 class ObjectsWithBrokenIndexingFinder : public MarkedBlock::VoidFunctor {
1324 public:
1325     ObjectsWithBrokenIndexingFinder(VM&, Vector<JSObject*>&, JSGlobalObject*);
1326     ObjectsWithBrokenIndexingFinder(VM&, Vector<JSObject*>&, HashSet<JSGlobalObject*>&);
1327
1328     bool needsMultiGlobalsScan() const { return m_needsMultiGlobalsScan; }
1329     IterationStatus operator()(HeapCell*, HeapCell::Kind) const;
1330
1331 private:
1332     IterationStatus visit(JSObject*);
1333
1334     VM& m_vm;
1335     Vector<JSObject*>& m_foundObjects;
1336     JSGlobalObject* m_globalObject { nullptr }; // Only used for SingleBadTimeGlobal mode.
1337     HashSet<JSGlobalObject*>* m_globalObjects { nullptr }; // Only used for BadTimeGlobalGraph mode;
1338     bool m_needsMultiGlobalsScan { false };
1339 };
1340
1341 template<>
1342 ObjectsWithBrokenIndexingFinder<BadTimeFinderMode::SingleGlobal>::ObjectsWithBrokenIndexingFinder(
1343     VM& vm, Vector<JSObject*>& foundObjects, JSGlobalObject* globalObject)
1344     : m_vm(vm)
1345     , m_foundObjects(foundObjects)
1346     , m_globalObject(globalObject)
1347 {
1348 }
1349
1350 template<>
1351 ObjectsWithBrokenIndexingFinder<BadTimeFinderMode::MultipleGlobals>::ObjectsWithBrokenIndexingFinder(
1352     VM& vm, Vector<JSObject*>& foundObjects, HashSet<JSGlobalObject*>& globalObjects)
1353     : m_vm(vm)
1354     , m_foundObjects(foundObjects)
1355     , m_globalObjects(&globalObjects)
1356 {
1357 }
1358
1359 inline bool hasBrokenIndexing(IndexingType type)
1360 {
1361     return type && !hasSlowPutArrayStorage(type);
1362 }
1363
1364 inline bool hasBrokenIndexing(JSObject* object)
1365 {
1366     IndexingType type = object->indexingType();
1367     return hasBrokenIndexing(type);
1368 }
1369
1370 template<BadTimeFinderMode mode>
1371 inline IterationStatus ObjectsWithBrokenIndexingFinder<mode>::visit(JSObject* object)
1372 {
1373     VM& vm = m_vm;
1374
1375     // We only want to have a bad time in the affected global object, not in the entire
1376     // VM. But we have to be careful, since there may be objects that claim to belong to
1377     // a different global object that have prototypes from our global object.
1378     auto isInAffectedGlobalObject = [&] (JSObject* object) {
1379         JSGlobalObject* objectGlobalObject { nullptr };
1380         bool objectMayBePrototype { false };
1381
1382         if (mode == BadTimeFinderMode::SingleGlobal) {
1383             objectGlobalObject = object->globalObject(vm);
1384             if (objectGlobalObject == m_globalObject)
1385                 return true;
1386
1387             objectMayBePrototype = object->mayBePrototype();
1388         }
1389
1390         for (JSObject* current = object; ;) {
1391             JSGlobalObject* currentGlobalObject = current->globalObject(vm);
1392             if (mode == BadTimeFinderMode::SingleGlobal) {
1393                 if (objectMayBePrototype && currentGlobalObject != objectGlobalObject)
1394                     m_needsMultiGlobalsScan = true;
1395                 if (currentGlobalObject == m_globalObject)
1396                     return true;
1397             } else {
1398                 if (m_globalObjects->contains(currentGlobalObject))
1399                     return true;
1400             }
1401
1402             JSValue prototypeValue = current->getPrototypeDirect(vm);
1403             if (prototypeValue.isNull())
1404                 return false;
1405             current = asObject(prototypeValue);
1406         }
1407         RELEASE_ASSERT_NOT_REACHED();
1408     };
1409
1410     if (JSFunction* function = jsDynamicCast<JSFunction*>(vm, object)) {
1411         if (FunctionRareData* rareData = function->rareData()) {
1412             // We only use this to cache JSFinalObjects. They do not start off with a broken indexing type.
1413             ASSERT(!(rareData->objectAllocationStructure() && hasBrokenIndexing(rareData->objectAllocationStructure()->indexingType())));
1414
1415             if (Structure* structure = rareData->internalFunctionAllocationStructure()) {
1416                 if (hasBrokenIndexing(structure->indexingType())) {
1417                     bool isRelevantGlobalObject =
1418                         (mode == BadTimeFinderMode::SingleGlobal
1419                             ? m_globalObject == structure->globalObject()
1420                             : m_globalObjects->contains(structure->globalObject()))
1421                         || (structure->hasMonoProto() && !structure->storedPrototype().isNull() && isInAffectedGlobalObject(asObject(structure->storedPrototype())));
1422                     if (mode == BadTimeFinderMode::SingleGlobal && m_needsMultiGlobalsScan)
1423                         return IterationStatus::Done; // Bailing early and let the MultipleGlobals path handle everything.
1424                     if (isRelevantGlobalObject)
1425                         rareData->clearInternalFunctionAllocationProfile();
1426                 }
1427             }
1428         }
1429     }
1430
1431     // Run this filter first, since it's cheap, and ought to filter out a lot of objects.
1432     if (!hasBrokenIndexing(object))
1433         return IterationStatus::Continue;
1434
1435     if (isInAffectedGlobalObject(object))
1436         m_foundObjects.append(object);
1437
1438     if (mode == BadTimeFinderMode::SingleGlobal && m_needsMultiGlobalsScan)
1439         return IterationStatus::Done; // Bailing early and let the MultipleGlobals path handle everything.
1440
1441     return IterationStatus::Continue;
1442 }
1443
1444 template<BadTimeFinderMode mode>
1445 IterationStatus ObjectsWithBrokenIndexingFinder<mode>::operator()(HeapCell* cell, HeapCell::Kind kind) const
1446 {
1447     if (isJSCellKind(kind) && static_cast<JSCell*>(cell)->isObject()) {
1448         // FIXME: This const_cast exists because this isn't a C++ lambda.
1449         // https://bugs.webkit.org/show_bug.cgi?id=159644
1450         return const_cast<ObjectsWithBrokenIndexingFinder*>(this)->visit(jsCast<JSObject*>(static_cast<JSCell*>(cell)));
1451     }
1452     return IterationStatus::Continue;
1453 }
1454
1455 } // end private namespace for helpers for JSGlobalObject::haveABadTime()
1456
1457 void JSGlobalObject::fireWatchpointAndMakeAllArrayStructuresSlowPut(VM& vm)
1458 {
1459     if (isHavingABadTime())
1460         return;
1461
1462     // Make sure that all allocations or indexed storage transitions that are inlining
1463     // the assumption that it's safe to transition to a non-SlowPut array storage don't
1464     // do so anymore.
1465     m_havingABadTimeWatchpoint->fireAll(vm, "Having a bad time");
1466     ASSERT(isHavingABadTime()); // The watchpoint is what tells us that we're having a bad time.
1467     
1468     // Make sure that all JSArray allocations that load the appropriate structure from
1469     // this object now load a structure that uses SlowPut.
1470     for (unsigned i = 0; i < NumberOfArrayIndexingModes; ++i)
1471         m_arrayStructureForIndexingShapeDuringAllocation[i].set(vm, this, originalArrayStructureForIndexingType(ArrayWithSlowPutArrayStorage));
1472
1473     // Same for any special array structures.
1474     Structure* slowPutStructure;
1475     slowPutStructure = createRegExpMatchesArraySlowPutStructure(vm, this);
1476     m_regExpMatchesArrayStructure.set(vm, this, slowPutStructure);
1477     slowPutStructure = createRegExpMatchesArrayWithGroupsSlowPutStructure(vm, this);
1478     m_regExpMatchesArrayWithGroupsStructure.set(vm, this, slowPutStructure);
1479     slowPutStructure = ClonedArguments::createSlowPutStructure(vm, this, m_objectPrototype.get());
1480     m_clonedArgumentsStructure.set(vm, this, slowPutStructure);
1481 };
1482
1483 void JSGlobalObject::haveABadTime(VM& vm)
1484 {
1485     ASSERT(&vm == &this->vm());
1486     
1487     if (isHavingABadTime())
1488         return;
1489
1490     vm.structureCache.clear(); // We may be caching array structures in here.
1491
1492     DeferGC deferGC(vm.heap);
1493
1494     // Consider the following objects and prototype chains:
1495     //    O (of global G1) -> A (of global G1)
1496     //    B (of global G2) where G2 has a bad time
1497     //
1498     // If we set B as the prototype of A, G1 will need to have a bad time.
1499     // See comments in Structure::mayInterceptIndexedAccesses() for why.
1500     //
1501     // Now, consider the following objects and prototype chains:
1502     //    O1 (of global G1) -> A1 (of global G1) -> B1 (of global G2)
1503     //    O2 (of global G2) -> A2 (of global G2)
1504     //    B2 (of global G3) where G3 has a bad time.
1505     //
1506     // G1 and G2 does not have a bad time, but G3 already has a bad time.
1507     // If we set B2 as the prototype of A2, then G2 needs to have a bad time.
1508     // Note that by induction, G1 also now needs to have a bad time because of
1509     // O1 -> A1 -> B1.
1510     //
1511     // We describe this as global G1 being affected by global G2, and G2 by G3.
1512     // Similarly, we say that G1 is dependent on G2, and G2 on G3.
1513     // Hence, when G3 has a bad time, we need to ensure that all globals that
1514     // are transitively dependent on it also have a bad time (G2 and G1 in this
1515     // example).
1516     //
1517     // Apart from clearing the VM structure cache above, there are 2 more things
1518     // that we have to do when globals have a bad time:
1519     // 1. For each affected global:
1520     //    a. Fire its HaveABadTime watchpoint.
1521     //    b. Convert all of its array structures to SlowPutArrayStorage.
1522     // 2. Make sure that all affected objects  switch to the slow kind of
1523     //    indexed storage. An object is considered to be affected if it has
1524     //    indexed storage and has a prototype object which may have indexed
1525     //    accessors. If the prototype object belongs to a global having a bad
1526     //    time, then the prototype object is considered to possibly have indexed
1527     //    accessors. See comments in Structure::mayInterceptIndexedAccesses()
1528     //    for details.
1529     //
1530     // Note: step 1 must be completed before step 2 because step 2 relies on
1531     // the HaveABadTime watchpoint having already been fired on all affected
1532     // globals.
1533     //
1534     // In the common case, only this global will start having a bad time here,
1535     // and no other globals are affected by it. So, we first proceed on this assumption
1536     // with a simpler ObjectsWithBrokenIndexingFinder scan to find heap objects
1537     // affected by this global that need to be converted to SlowPutArrayStorage.
1538     // We'll also have the finder check for the presence of other global objects
1539     // depending on this one.
1540     //
1541     // If we do discover other globals depending on this one, we'll abort this
1542     // first ObjectsWithBrokenIndexingFinder scan because it will be insufficient
1543     // to find all affected objects that need to be converted to SlowPutArrayStorage.
1544     // It also does not make dependent globals have a bad time. Instead, we'll
1545     // take a more comprehensive approach of first creating a dependency graph
1546     // between globals, and then using that graph to determine all affected
1547     // globals and objects. With that, we can make all affected globals have a
1548     // bad time, and convert all affected objects to SlowPutArrayStorage.
1549
1550     fireWatchpointAndMakeAllArrayStructuresSlowPut(vm); // Step 1 above.
1551     
1552     Vector<JSObject*> foundObjects;
1553     ObjectsWithBrokenIndexingFinder<BadTimeFinderMode::SingleGlobal> finder(vm, foundObjects, this);
1554     {
1555         HeapIterationScope iterationScope(vm.heap);
1556         vm.heap.objectSpace().forEachLiveCell(iterationScope, finder); // Attempt step 2 above.
1557     }
1558
1559     if (finder.needsMultiGlobalsScan()) {
1560         foundObjects.clear();
1561
1562         // Find all globals that will also have a bad time as a side effect of
1563         // this global having a bad time.
1564         GlobalObjectDependencyFinder dependencies(vm);
1565         {
1566             HeapIterationScope iterationScope(vm.heap);
1567             vm.heap.objectSpace().forEachLiveCell(iterationScope, dependencies);
1568         }
1569
1570         HashSet<JSGlobalObject*> globalsHavingABadTime;
1571         Deque<JSGlobalObject*> globals;
1572
1573         globals.append(this);
1574         while (!globals.isEmpty()) {
1575             JSGlobalObject* global = globals.takeFirst();
1576             global->fireWatchpointAndMakeAllArrayStructuresSlowPut(vm); // Step 1 above.
1577             auto result = globalsHavingABadTime.add(global);
1578             if (result.isNewEntry) {
1579                 if (HashSet<JSGlobalObject*>* dependents = dependencies.dependentsFor(global)) {
1580                     for (JSGlobalObject* dependentGlobal : *dependents)
1581                         globals.append(dependentGlobal);
1582                 }
1583             }
1584         }
1585
1586         ObjectsWithBrokenIndexingFinder<BadTimeFinderMode::MultipleGlobals> finder(vm, foundObjects, globalsHavingABadTime);
1587         {
1588             HeapIterationScope iterationScope(vm.heap);
1589             vm.heap.objectSpace().forEachLiveCell(iterationScope, finder); // Step 2 above.
1590         }
1591     }
1592
1593     while (!foundObjects.isEmpty()) {
1594         JSObject* object = asObject(foundObjects.last());
1595         foundObjects.removeLast();
1596         ASSERT(hasBrokenIndexing(object));
1597         object->switchToSlowPutArrayStorage(vm);
1598     }
1599 }
1600
1601 void JSGlobalObject::fixupPrototypeChainWithObjectPrototype(VM& vm)
1602 {
1603     JSObject* oldLastInPrototypeChain = lastInPrototypeChain(vm, this);
1604     JSObject* objectPrototype = m_objectPrototype.get();
1605     if (oldLastInPrototypeChain != objectPrototype)
1606         oldLastInPrototypeChain->setPrototypeDirect(vm, objectPrototype);
1607 }
1608
1609 // Set prototype, and also insert the object prototype at the end of the chain.
1610 void JSGlobalObject::resetPrototype(VM& vm, JSValue prototype)
1611 {
1612     if (getPrototypeDirect(vm) == prototype)
1613         return;
1614     setPrototypeDirect(vm, prototype);
1615     fixupPrototypeChainWithObjectPrototype(vm);
1616     // Whenever we change the prototype of the global object, we need to create a new JSProxy with the correct prototype.
1617     setGlobalThis(vm, JSNonDestructibleProxy::create(vm, JSNonDestructibleProxy::createStructure(vm, this, prototype, PureForwardingProxyType), this));
1618 }
1619
1620 void JSGlobalObject::visitChildren(JSCell* cell, SlotVisitor& visitor)
1621
1622     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(cell);
1623     ASSERT_GC_OBJECT_INHERITS(thisObject, info());
1624     Base::visitChildren(thisObject, visitor);
1625
1626     visitor.append(thisObject->m_globalThis);
1627
1628     visitor.append(thisObject->m_globalLexicalEnvironment);
1629     visitor.append(thisObject->m_globalScopeExtension);
1630     visitor.append(thisObject->m_globalCallee);
1631     visitor.append(thisObject->m_stackOverflowFrameCallee);
1632     thisObject->m_evalErrorStructure.visit(visitor);
1633     thisObject->m_rangeErrorStructure.visit(visitor);
1634     thisObject->m_referenceErrorStructure.visit(visitor);
1635     thisObject->m_syntaxErrorStructure.visit(visitor);
1636     thisObject->m_typeErrorStructure.visit(visitor);
1637     thisObject->m_URIErrorStructure.visit(visitor);
1638     visitor.append(thisObject->m_objectConstructor);
1639     visitor.append(thisObject->m_promiseConstructor);
1640
1641 #if ENABLE(INTL)
1642     visitor.append(thisObject->m_defaultCollator);
1643     thisObject->m_collatorStructure.visit(visitor);
1644     thisObject->m_numberFormatStructure.visit(visitor);
1645     thisObject->m_dateTimeFormatStructure.visit(visitor);
1646     thisObject->m_pluralRulesStructure.visit(visitor);
1647 #endif
1648     visitor.append(thisObject->m_nullGetterFunction);
1649     visitor.append(thisObject->m_nullSetterFunction);
1650
1651     thisObject->m_parseIntFunction.visit(visitor);
1652     thisObject->m_parseFloatFunction.visit(visitor);
1653     visitor.append(thisObject->m_callFunction);
1654     visitor.append(thisObject->m_applyFunction);
1655     visitor.append(thisObject->m_throwTypeErrorFunction);
1656     thisObject->m_arrayProtoToStringFunction.visit(visitor);
1657     thisObject->m_arrayProtoValuesFunction.visit(visitor);
1658     thisObject->m_evalFunction.visit(visitor);
1659     thisObject->m_initializePromiseFunction.visit(visitor);
1660     thisObject->m_iteratorProtocolFunction.visit(visitor);
1661     thisObject->m_promiseResolveFunction.visit(visitor);
1662     visitor.append(thisObject->m_objectProtoValueOfFunction);
1663     visitor.append(thisObject->m_numberProtoToStringFunction);
1664     visitor.append(thisObject->m_newPromiseCapabilityFunction);
1665     visitor.append(thisObject->m_functionProtoHasInstanceSymbolFunction);
1666     thisObject->m_throwTypeErrorGetterSetter.visit(visitor);
1667     visitor.append(thisObject->m_throwTypeErrorArgumentsCalleeAndCallerGetterSetter);
1668     thisObject->m_moduleLoader.visit(visitor);
1669
1670     visitor.append(thisObject->m_objectPrototype);
1671     visitor.append(thisObject->m_functionPrototype);
1672     visitor.append(thisObject->m_arrayPrototype);
1673     visitor.append(thisObject->m_iteratorPrototype);
1674     visitor.append(thisObject->m_generatorFunctionPrototype);
1675     visitor.append(thisObject->m_generatorPrototype);
1676     visitor.append(thisObject->m_asyncFunctionPrototype);
1677     visitor.append(thisObject->m_asyncGeneratorPrototype);
1678     visitor.append(thisObject->m_asyncIteratorPrototype);
1679     visitor.append(thisObject->m_asyncGeneratorFunctionPrototype);
1680
1681     thisObject->m_debuggerScopeStructure.visit(visitor);
1682     thisObject->m_withScopeStructure.visit(visitor);
1683     thisObject->m_strictEvalActivationStructure.visit(visitor);
1684     visitor.append(thisObject->m_lexicalEnvironmentStructure);
1685     thisObject->m_moduleEnvironmentStructure.visit(visitor);
1686     visitor.append(thisObject->m_directArgumentsStructure);
1687     visitor.append(thisObject->m_scopedArgumentsStructure);
1688     visitor.append(thisObject->m_clonedArgumentsStructure);
1689     visitor.append(thisObject->m_objectStructureForObjectConstructor);
1690     for (unsigned i = 0; i < NumberOfArrayIndexingModes; ++i)
1691         visitor.append(thisObject->m_originalArrayStructureForIndexingShape[i]);
1692     for (unsigned i = 0; i < NumberOfArrayIndexingModes; ++i)
1693         visitor.append(thisObject->m_arrayStructureForIndexingShapeDuringAllocation[i]);
1694     thisObject->m_callbackConstructorStructure.visit(visitor);
1695     thisObject->m_callbackFunctionStructure.visit(visitor);
1696     thisObject->m_callbackObjectStructure.visit(visitor);
1697 #if JSC_OBJC_API_ENABLED
1698     thisObject->m_objcCallbackFunctionStructure.visit(visitor);
1699     thisObject->m_objcWrapperObjectStructure.visit(visitor);
1700 #endif
1701 #ifdef JSC_GLIB_API_ENABLED
1702     thisObject->m_glibCallbackFunctionStructure.visit(visitor);
1703     thisObject->m_glibWrapperObjectStructure.visit(visitor);
1704 #endif
1705     visitor.append(thisObject->m_nullPrototypeObjectStructure);
1706     visitor.append(thisObject->m_calleeStructure);
1707
1708     visitor.append(thisObject->m_hostFunctionStructure);
1709     auto visitFunctionStructures = [&] (FunctionStructures& structures) {
1710         visitor.append(structures.arrowFunctionStructure);
1711         visitor.append(structures.sloppyFunctionStructure);
1712         visitor.append(structures.strictFunctionStructure);
1713     };
1714     visitFunctionStructures(thisObject->m_builtinFunctions);
1715     visitFunctionStructures(thisObject->m_ordinaryFunctions);
1716
1717     thisObject->m_customGetterSetterFunctionStructure.visit(visitor);
1718     thisObject->m_boundFunctionStructure.visit(visitor);
1719     visitor.append(thisObject->m_getterSetterStructure);
1720     thisObject->m_nativeStdFunctionStructure.visit(visitor);
1721     visitor.append(thisObject->m_bigIntObjectStructure);
1722     visitor.append(thisObject->m_regExpStructure);
1723     visitor.append(thisObject->m_generatorFunctionStructure);
1724     visitor.append(thisObject->m_asyncFunctionStructure);
1725     visitor.append(thisObject->m_asyncGeneratorFunctionStructure);
1726     thisObject->m_iteratorResultObjectStructure.visit(visitor);
1727     visitor.append(thisObject->m_regExpMatchesArrayStructure);
1728     visitor.append(thisObject->m_regExpMatchesArrayWithGroupsStructure);
1729     thisObject->m_moduleRecordStructure.visit(visitor);
1730     thisObject->m_moduleNamespaceObjectStructure.visit(visitor);
1731     thisObject->m_proxyObjectStructure.visit(visitor);
1732     thisObject->m_callableProxyObjectStructure.visit(visitor);
1733     thisObject->m_proxyRevokeStructure.visit(visitor);
1734     
1735 #if ENABLE(SHARED_ARRAY_BUFFER)
1736     visitor.append(thisObject->m_sharedArrayBufferPrototype);
1737     visitor.append(thisObject->m_sharedArrayBufferStructure);
1738 #endif
1739
1740 #define VISIT_SIMPLE_TYPE(CapitalName, lowerName, properName, instanceType, jsName, prototypeBase) do { \
1741         visitor.append(thisObject->m_ ## lowerName ## Prototype); \
1742         visitor.append(thisObject->m_ ## properName ## Structure); \
1743     } while (0);
1744
1745 #define VISIT_LAZY_TYPE(CapitalName, lowerName, properName, instanceType, jsName, prototypeBase) \
1746     thisObject->m_ ## properName ## Structure.visit(visitor);
1747
1748     FOR_EACH_SIMPLE_BUILTIN_TYPE(VISIT_SIMPLE_TYPE)
1749     if (UNLIKELY(Options::useBigInt()))
1750         FOR_BIG_INT_BUILTIN_TYPE_WITH_CONSTRUCTOR(VISIT_SIMPLE_TYPE)
1751     FOR_EACH_BUILTIN_DERIVED_ITERATOR_TYPE(VISIT_SIMPLE_TYPE)
1752
1753     FOR_EACH_LAZY_BUILTIN_TYPE(VISIT_LAZY_TYPE)
1754     
1755 #if ENABLE(WEBASSEMBLY)
1756     thisObject->m_webAssemblyModuleRecordStructure.visit(visitor);
1757     thisObject->m_webAssemblyFunctionStructure.visit(visitor);
1758     thisObject->m_jsToWasmICCalleeStructure.visit(visitor);
1759     thisObject->m_webAssemblyWrapperFunctionStructure.visit(visitor);
1760     thisObject->m_webAssemblyToJSCalleeStructure.visit(visitor);
1761     FOR_EACH_WEBASSEMBLY_CONSTRUCTOR_TYPE(VISIT_LAZY_TYPE)
1762 #endif // ENABLE(WEBASSEMBLY)
1763
1764 #undef VISIT_SIMPLE_TYPE
1765 #undef VISIT_LAZY_TYPE
1766
1767     for (unsigned i = NumberOfTypedArrayTypes; i--;)
1768         thisObject->lazyTypedArrayStructure(indexToTypedArrayType(i)).visit(visitor);
1769     
1770     visitor.append(thisObject->m_speciesGetterSetter);
1771     thisObject->m_typedArrayProto.visit(visitor);
1772     thisObject->m_typedArraySuperConstructor.visit(visitor);
1773     thisObject->m_regExpGlobalData.visitAggregate(visitor);
1774 }
1775
1776 ExecState* JSGlobalObject::globalExec()
1777 {
1778     return CallFrame::create(m_globalCallFrame);
1779 }
1780
1781 void JSGlobalObject::exposeDollarVM(VM& vm)
1782 {
1783     if (hasOwnProperty(globalExec(), vm.propertyNames->builtinNames().dollarVMPrivateName()))
1784         return;
1785
1786     JSDollarVM* dollarVM = JSDollarVM::create(vm, JSDollarVM::createStructure(vm, this, m_objectPrototype.get()));
1787
1788     GlobalPropertyInfo extraStaticGlobals[] = {
1789         GlobalPropertyInfo(vm.propertyNames->builtinNames().dollarVMPrivateName(), dollarVM, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1790     };
1791     addStaticGlobals(extraStaticGlobals, WTF_ARRAY_LENGTH(extraStaticGlobals));
1792
1793     putDirect(vm, Identifier::fromString(globalExec(), "$vm"), dollarVM, static_cast<unsigned>(PropertyAttribute::DontEnum));
1794 }
1795
1796 void JSGlobalObject::addStaticGlobals(GlobalPropertyInfo* globals, int count)
1797 {
1798     ScopeOffset startOffset = addVariables(count, jsUndefined());
1799
1800     for (int i = 0; i < count; ++i) {
1801         GlobalPropertyInfo& global = globals[i];
1802         // This `configurable = false` is necessary condition for static globals,
1803         // otherwise lexical bindings can change the result of GlobalVar queries too.
1804         // We won't be able to declare a global lexical variable with the sanem name to
1805         // the static globals because configurable = false.
1806         ASSERT(global.attributes & PropertyAttribute::DontDelete);
1807         
1808         WatchpointSet* watchpointSet = nullptr;
1809         WriteBarrierBase<Unknown>* variable = nullptr;
1810         {
1811             ConcurrentJSLocker locker(symbolTable()->m_lock);
1812             ScopeOffset offset = symbolTable()->takeNextScopeOffset(locker);
1813             RELEASE_ASSERT(offset == startOffset + i);
1814             SymbolTableEntry newEntry(VarOffset(offset), global.attributes);
1815             newEntry.prepareToWatch();
1816             watchpointSet = newEntry.watchpointSet();
1817             symbolTable()->add(locker, global.identifier.impl(), WTFMove(newEntry));
1818             variable = &variableAt(offset);
1819         }
1820         symbolTablePutTouchWatchpointSet(vm(), this, global.identifier, global.value, variable, watchpointSet);
1821     }
1822 }
1823
1824 bool JSGlobalObject::getOwnPropertySlot(JSObject* object, ExecState* exec, PropertyName propertyName, PropertySlot& slot)
1825 {
1826     if (Base::getOwnPropertySlot(object, exec, propertyName, slot))
1827         return true;
1828     return symbolTableGet(jsCast<JSGlobalObject*>(object), propertyName, slot);
1829 }
1830
1831 void JSGlobalObject::clearRareData(JSCell* cell)
1832 {
1833     jsCast<JSGlobalObject*>(cell)->m_rareData = nullptr;
1834 }
1835
1836 void JSGlobalObject::tryInstallArraySpeciesWatchpoint(ExecState* exec)
1837 {
1838     RELEASE_ASSERT(!m_arrayPrototypeConstructorWatchpoint);
1839     RELEASE_ASSERT(!m_arrayConstructorSpeciesWatchpoint);
1840
1841     VM& vm = exec->vm();
1842     auto scope = DECLARE_THROW_SCOPE(vm);
1843
1844     // First we need to make sure that the Array.prototype.constructor property points to Array
1845     // and that Array[Symbol.species] is the primordial GetterSetter.
1846     ArrayPrototype* arrayPrototype = this->arrayPrototype();
1847
1848     // We only initialize once so flattening the structures does not have any real cost.
1849     Structure* prototypeStructure = arrayPrototype->structure(vm);
1850     if (prototypeStructure->isDictionary())
1851         prototypeStructure = prototypeStructure->flattenDictionaryStructure(vm, arrayPrototype);
1852     RELEASE_ASSERT(!prototypeStructure->isDictionary());
1853
1854     ArrayConstructor* arrayConstructor = this->arrayConstructor();
1855
1856     auto invalidateWatchpoint = [&] {
1857         m_arraySpeciesWatchpoint.invalidate(vm, StringFireDetail("Was not able to set up array species watchpoint."));
1858     };
1859
1860     PropertySlot constructorSlot(arrayPrototype, PropertySlot::InternalMethodType::VMInquiry);
1861     arrayPrototype->getOwnPropertySlot(arrayPrototype, exec, vm.propertyNames->constructor, constructorSlot);
1862     scope.assertNoException();
1863     if (constructorSlot.slotBase() != arrayPrototype
1864         || !constructorSlot.isCacheableValue()
1865         || constructorSlot.getValue(exec, vm.propertyNames->constructor) != arrayConstructor) {
1866         invalidateWatchpoint();
1867         return;
1868     }
1869
1870     Structure* constructorStructure = arrayConstructor->structure(vm);
1871     if (constructorStructure->isDictionary())
1872         constructorStructure = constructorStructure->flattenDictionaryStructure(vm, arrayConstructor);
1873
1874     PropertySlot speciesSlot(arrayConstructor, PropertySlot::InternalMethodType::VMInquiry);
1875     arrayConstructor->getOwnPropertySlot(arrayConstructor, exec, vm.propertyNames->speciesSymbol, speciesSlot);
1876     scope.assertNoException();
1877     if (speciesSlot.slotBase() != arrayConstructor
1878         || !speciesSlot.isCacheableGetter()
1879         || speciesSlot.getterSetter() != speciesGetterSetter()) {
1880         invalidateWatchpoint();
1881         return;
1882     }
1883
1884     // Now we need to setup the watchpoints to make sure these conditions remain valid.
1885     prototypeStructure->startWatchingPropertyForReplacements(vm, constructorSlot.cachedOffset());
1886     constructorStructure->startWatchingPropertyForReplacements(vm, speciesSlot.cachedOffset());
1887
1888     ObjectPropertyCondition constructorCondition = ObjectPropertyCondition::equivalence(vm, arrayPrototype, arrayPrototype, vm.propertyNames->constructor.impl(), arrayConstructor);
1889     ObjectPropertyCondition speciesCondition = ObjectPropertyCondition::equivalence(vm, arrayPrototype, arrayConstructor, vm.propertyNames->speciesSymbol.impl(), speciesGetterSetter());
1890
1891     if (!constructorCondition.isWatchable() || !speciesCondition.isWatchable()) {
1892         invalidateWatchpoint();
1893         return;
1894     }
1895
1896     // We only watch this from the DFG, and the DFG makes sure to only start watching if the watchpoint is in the IsWatched state.
1897     RELEASE_ASSERT(!m_arraySpeciesWatchpoint.isBeingWatched());
1898     m_arraySpeciesWatchpoint.touch(vm, "Set up array species watchpoint.");
1899
1900     m_arrayPrototypeConstructorWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, constructorCondition, m_arraySpeciesWatchpoint);
1901     m_arrayPrototypeConstructorWatchpoint->install(vm);
1902
1903     m_arrayConstructorSpeciesWatchpoint = std::make_unique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, speciesCondition, m_arraySpeciesWatchpoint);
1904     m_arrayConstructorSpeciesWatchpoint->install(vm);
1905 }
1906
1907 void slowValidateCell(JSGlobalObject* globalObject)
1908 {
1909     RELEASE_ASSERT(globalObject->isGlobalObject());
1910     ASSERT_GC_OBJECT_INHERITS(globalObject, JSGlobalObject::info());
1911 }
1912
1913 void JSGlobalObject::setRemoteDebuggingEnabled(bool enabled)
1914 {
1915 #if ENABLE(REMOTE_INSPECTOR)
1916     m_inspectorDebuggable->setRemoteDebuggingAllowed(enabled);
1917 #else
1918     UNUSED_PARAM(enabled);
1919 #endif
1920 }
1921
1922 bool JSGlobalObject::remoteDebuggingEnabled() const
1923 {
1924 #if ENABLE(REMOTE_INSPECTOR)
1925     return m_inspectorDebuggable->remoteDebuggingAllowed();
1926 #else
1927     return false;
1928 #endif
1929 }
1930
1931 void JSGlobalObject::setName(const String& name)
1932 {
1933     m_name = name;
1934
1935 #if ENABLE(REMOTE_INSPECTOR)
1936     m_inspectorDebuggable->update();
1937 #endif
1938 }
1939
1940 # if ENABLE(INTL)
1941 static void addMissingScriptLocales(HashSet<String>& availableLocales)
1942 {
1943     if (availableLocales.contains("pa-Arab-PK"))
1944         availableLocales.add("pa-PK"_s);
1945     if (availableLocales.contains("zh-Hans-CN"))
1946         availableLocales.add("zh-CN"_s);
1947     if (availableLocales.contains("zh-Hant-HK"))
1948         availableLocales.add("zh-HK"_s);
1949     if (availableLocales.contains("zh-Hans-SG"))
1950         availableLocales.add("zh-SG"_s);
1951     if (availableLocales.contains("zh-Hant-TW"))
1952         availableLocales.add("zh-TW"_s);
1953 }
1954
1955 const HashSet<String>& JSGlobalObject::intlCollatorAvailableLocales()
1956 {
1957     if (m_intlCollatorAvailableLocales.isEmpty()) {
1958         int32_t count = ucol_countAvailable();
1959         for (int32_t i = 0; i < count; ++i) {
1960             String locale = convertICULocaleToBCP47LanguageTag(ucol_getAvailable(i));
1961             if (!locale.isEmpty())
1962                 m_intlCollatorAvailableLocales.add(locale);
1963         }
1964         addMissingScriptLocales(m_intlCollatorAvailableLocales);
1965     }
1966     return m_intlCollatorAvailableLocales;
1967 }
1968
1969 const HashSet<String>& JSGlobalObject::intlDateTimeFormatAvailableLocales()
1970 {
1971     if (m_intlDateTimeFormatAvailableLocales.isEmpty()) {
1972         int32_t count = udat_countAvailable();
1973         for (int32_t i = 0; i < count; ++i) {
1974             String locale = convertICULocaleToBCP47LanguageTag(udat_getAvailable(i));
1975             if (!locale.isEmpty())
1976                 m_intlDateTimeFormatAvailableLocales.add(locale);
1977         }
1978         addMissingScriptLocales(m_intlDateTimeFormatAvailableLocales);
1979     }
1980     return m_intlDateTimeFormatAvailableLocales;
1981 }
1982
1983 const HashSet<String>& JSGlobalObject::intlNumberFormatAvailableLocales()
1984 {
1985     if (m_intlNumberFormatAvailableLocales.isEmpty()) {
1986         int32_t count = unum_countAvailable();
1987         for (int32_t i = 0; i < count; ++i) {
1988             String locale = convertICULocaleToBCP47LanguageTag(unum_getAvailable(i));
1989             if (!locale.isEmpty())
1990                 m_intlNumberFormatAvailableLocales.add(locale);
1991         }
1992         addMissingScriptLocales(m_intlNumberFormatAvailableLocales);
1993     }
1994     return m_intlNumberFormatAvailableLocales;
1995 }
1996
1997 const HashSet<String>& JSGlobalObject::intlPluralRulesAvailableLocales()
1998 {
1999     if (m_intlPluralRulesAvailableLocales.isEmpty()) {
2000         int32_t count = uloc_countAvailable();
2001         for (int32_t i = 0; i < count; ++i) {
2002             String locale = convertICULocaleToBCP47LanguageTag(uloc_getAvailable(i));
2003             if (!locale.isEmpty())
2004                 m_intlPluralRulesAvailableLocales.add(locale);
2005         }
2006         addMissingScriptLocales(m_intlPluralRulesAvailableLocales);
2007     }
2008     return m_intlPluralRulesAvailableLocales;
2009 }
2010
2011 IntlCollator* JSGlobalObject::defaultCollator(ExecState* exec)
2012 {
2013     VM& vm = exec->vm();
2014     auto scope = DECLARE_THROW_SCOPE(vm);
2015
2016     if (m_defaultCollator)
2017         return m_defaultCollator.get();
2018
2019     IntlCollator* collator = IntlCollator::create(vm, collatorStructure());
2020     collator->initializeCollator(*exec, jsUndefined(), jsUndefined());
2021     RETURN_IF_EXCEPTION(scope, nullptr);
2022     m_defaultCollator.set(vm, this, collator);
2023     return collator;
2024 }
2025
2026 #endif // ENABLE(INTL)
2027
2028 void JSGlobalObject::bumpGlobalLexicalBindingEpoch(VM& vm)
2029 {
2030     if (++m_globalLexicalBindingEpoch == Options::thresholdForGlobalLexicalBindingEpoch()) {
2031         // Since the epoch overflows, we should rewrite all the CodeBlock to adjust to the newly started generation.
2032         m_globalLexicalBindingEpoch = 1;
2033         vm.heap.codeBlockSet().iterate([&] (CodeBlock* codeBlock) {
2034             if (codeBlock->globalObject() != this)
2035                 return;
2036             codeBlock->notifyLexicalBindingUpdate();
2037         });
2038     }
2039 }
2040
2041 void JSGlobalObject::queueMicrotask(Ref<Microtask>&& task)
2042 {
2043     if (globalObjectMethodTable()->queueTaskToEventLoop) {
2044         globalObjectMethodTable()->queueTaskToEventLoop(*this, WTFMove(task));
2045         return;
2046     }
2047
2048     vm().queueMicrotask(*this, WTFMove(task));
2049 }
2050
2051 void JSGlobalObject::setDebugger(Debugger* debugger)
2052 {
2053     m_debugger = debugger;
2054     if (debugger)
2055         vm().ensureShadowChicken();
2056 }
2057
2058 bool JSGlobalObject::hasDebugger() const
2059
2060     return m_debugger;
2061 }
2062
2063 bool JSGlobalObject::hasInteractiveDebugger() const 
2064
2065     return m_debugger && m_debugger->isInteractivelyDebugging();
2066 }
2067
2068 #if ENABLE(DFG_JIT)
2069 WatchpointSet* JSGlobalObject::getReferencedPropertyWatchpointSet(UniquedStringImpl* uid)
2070 {
2071     ConcurrentJSLocker locker(m_referencedGlobalPropertyWatchpointSetsLock);
2072     return m_referencedGlobalPropertyWatchpointSets.get(uid);
2073 }
2074
2075 WatchpointSet& JSGlobalObject::ensureReferencedPropertyWatchpointSet(UniquedStringImpl* uid)
2076 {
2077     ConcurrentJSLocker locker(m_referencedGlobalPropertyWatchpointSetsLock);
2078     return m_referencedGlobalPropertyWatchpointSets.ensure(uid, [] {
2079         return WatchpointSet::create(IsWatched);
2080     }).iterator->value.get();
2081 }
2082 #endif
2083
2084 JSGlobalObject* JSGlobalObject::create(VM& vm, Structure* structure)
2085 {
2086     JSGlobalObject* globalObject = new (NotNull, allocateCell<JSGlobalObject>(vm.heap)) JSGlobalObject(vm, structure);
2087     globalObject->finishCreation(vm);
2088     return globalObject;
2089 }
2090
2091 void JSGlobalObject::finishCreation(VM& vm)
2092 {
2093     Base::finishCreation(vm);
2094     structure(vm)->setGlobalObject(vm, this);
2095     m_runtimeFlags = m_globalObjectMethodTable->javaScriptRuntimeFlags(this);
2096     init(vm);
2097     setGlobalThis(vm, JSNonDestructibleProxy::create(vm, JSNonDestructibleProxy::createStructure(vm, this, getPrototypeDirect(vm), PureForwardingProxyType), this));
2098     ASSERT(type() == GlobalObjectType);
2099 }
2100
2101 void JSGlobalObject::finishCreation(VM& vm, JSObject* thisValue)
2102 {
2103     Base::finishCreation(vm);
2104     structure(vm)->setGlobalObject(vm, this);
2105     m_runtimeFlags = m_globalObjectMethodTable->javaScriptRuntimeFlags(this);
2106     init(vm);
2107     setGlobalThis(vm, thisValue);
2108     ASSERT(type() == GlobalObjectType);
2109 }
2110
2111 #ifdef JSC_GLIB_API_ENABLED
2112 void JSGlobalObject::setWrapperMap(std::unique_ptr<WrapperMap>&& map)
2113 {
2114     m_wrapperMap = WTFMove(map);
2115 }
2116 #endif
2117
2118 } // namespace JSC