d9569793d8291f3e1381795c2deefd8acdcd1780
[WebKit-https.git] / Source / JavaScriptCore / runtime / JSGlobalObject.cpp
1 /*
2  * Copyright (C) 2007-2019 Apple Inc. All rights reserved.
3  * Copyright (C) 2008 Cameron Zwarich (cwzwarich@uwaterloo.ca)
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *
9  * 1.  Redistributions of source code must retain the above copyright
10  *     notice, this list of conditions and the following disclaimer.
11  * 2.  Redistributions in binary form must reproduce the above copyright
12  *     notice, this list of conditions and the following disclaimer in the
13  *     documentation and/or other materials provided with the distribution.
14  * 3.  Neither the name of Apple Inc. ("Apple") nor the names of
15  *     its contributors may be used to endorse or promote products derived
16  *     from this software without specific prior written permission.
17  *
18  * THIS SOFTWARE IS PROVIDED BY APPLE AND ITS CONTRIBUTORS "AS IS" AND ANY
19  * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
20  * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
21  * DISCLAIMED. IN NO EVENT SHALL APPLE OR ITS CONTRIBUTORS BE LIABLE FOR ANY
22  * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
23  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
24  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
25  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
26  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
27  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
28  */
29
30 #include "config.h"
31 #include "JSGlobalObject.h"
32
33 #include "ArrayConstructor.h"
34 #include "ArrayIteratorPrototype.h"
35 #include "ArrayPrototype.h"
36 #include "AsyncFromSyncIteratorPrototype.h"
37 #include "AtomicsObject.h"
38 #include "AsyncFunctionConstructor.h"
39 #include "AsyncFunctionPrototype.h"
40 #include "AsyncGeneratorFunctionConstructor.h"
41 #include "AsyncGeneratorFunctionPrototype.h"
42 #include "AsyncGeneratorPrototype.h"
43 #include "AsyncIteratorPrototype.h"
44 #include "BigIntConstructor.h"
45 #include "BigIntObject.h"
46 #include "BigIntPrototype.h"
47 #include "BooleanConstructor.h"
48 #include "BooleanPrototype.h"
49 #include "BuiltinNames.h"
50 #include "CatchScope.h"
51 #include "ClonedArguments.h"
52 #include "CodeBlock.h"
53 #include "CodeBlockSetInlines.h"
54 #include "CodeCache.h"
55 #include "ConsoleObject.h"
56 #include "DateConstructor.h"
57 #include "DatePrototype.h"
58 #include "Debugger.h"
59 #include "DebuggerScope.h"
60 #include "DirectArguments.h"
61 #include "DirectEvalExecutable.h"
62 #include "ECMAScriptSpecInternalFunctions.h"
63 #include "Error.h"
64 #include "ErrorConstructor.h"
65 #include "ErrorPrototype.h"
66 #include "Exception.h"
67 #include "FunctionConstructor.h"
68 #include "FunctionPrototype.h"
69 #include "GeneratorFunctionConstructor.h"
70 #include "GeneratorFunctionPrototype.h"
71 #include "GeneratorPrototype.h"
72 #include "GetterSetter.h"
73 #include "HeapIterationScope.h"
74 #include "IndirectEvalExecutable.h"
75 #include "InspectorInstrumentationObject.h"
76 #include "Interpreter.h"
77 #include "IteratorPrototype.h"
78 #include "JSAPIWrapperObject.h"
79 #include "JSArrayBuffer.h"
80 #include "JSArrayBufferConstructor.h"
81 #include "JSArrayBufferPrototype.h"
82 #include "JSAsyncFunction.h"
83 #include "JSAsyncGeneratorFunction.h"
84 #include "JSBigInt.h"
85 #include "JSBoundFunction.h"
86 #include "JSCInlines.h"
87 #include "JSCallbackConstructor.h"
88 #include "JSCallbackFunction.h"
89 #include "JSCallbackObject.h"
90 #include "JSCustomGetterSetterFunction.h"
91 #include "JSDataView.h"
92 #include "JSDataViewPrototype.h"
93 #include "JSDollarVM.h"
94 #include "JSFunction.h"
95 #include "JSGeneratorFunction.h"
96 #include "JSGenericTypedArrayViewConstructorInlines.h"
97 #include "JSGenericTypedArrayViewInlines.h"
98 #include "JSGenericTypedArrayViewPrototypeInlines.h"
99 #include "JSGlobalObjectFunctions.h"
100 #include "JSInternalPromise.h"
101 #include "JSInternalPromiseConstructor.h"
102 #include "JSInternalPromisePrototype.h"
103 #include "JSLexicalEnvironment.h"
104 #include "JSLock.h"
105 #include "JSMap.h"
106 #include "JSMicrotask.h"
107 #include "JSModuleEnvironment.h"
108 #include "JSModuleLoader.h"
109 #include "JSModuleNamespaceObject.h"
110 #include "JSModuleRecord.h"
111 #include "JSNativeStdFunction.h"
112 #include "JSNonDestructibleProxy.h"
113 #include "JSONObject.h"
114 #include "JSPromise.h"
115 #include "JSPromiseConstructor.h"
116 #include "JSPromisePrototype.h"
117 #include "JSSet.h"
118 #include "JSStringIterator.h"
119 #include "JSTypedArrayConstructors.h"
120 #include "JSTypedArrayPrototypes.h"
121 #include "JSTypedArrayViewConstructor.h"
122 #include "JSTypedArrayViewPrototype.h"
123 #include "JSTypedArrays.h"
124 #include "JSWeakMap.h"
125 #include "JSWeakObjectRef.h"
126 #include "JSWeakSet.h"
127 #include "JSWebAssembly.h"
128 #include "JSWebAssemblyCompileError.h"
129 #include "JSWebAssemblyInstance.h"
130 #include "JSWebAssemblyLinkError.h"
131 #include "JSWebAssemblyMemory.h"
132 #include "JSWebAssemblyModule.h"
133 #include "JSWebAssemblyRuntimeError.h"
134 #include "JSWebAssemblyTable.h"
135 #include "JSWithScope.h"
136 #include "LazyClassStructureInlines.h"
137 #include "LazyPropertyInlines.h"
138 #include "Lookup.h"
139 #include "MapConstructor.h"
140 #include "MapIteratorPrototype.h"
141 #include "MapPrototype.h"
142 #include "MarkedSpaceInlines.h"
143 #include "MathObject.h"
144 #include "Microtask.h"
145 #include "NativeErrorConstructor.h"
146 #include "NativeErrorPrototype.h"
147 #include "NullGetterFunction.h"
148 #include "NullSetterFunction.h"
149 #include "NumberConstructor.h"
150 #include "NumberPrototype.h"
151 #include "ObjCCallbackFunction.h"
152 #include "ObjectConstructor.h"
153 #include "ObjectPropertyChangeAdaptiveWatchpoint.h"
154 #include "ObjectPropertyConditionSet.h"
155 #include "ObjectPrototype.h"
156 #include "ParserError.h"
157 #include "ProxyConstructor.h"
158 #include "ProxyObject.h"
159 #include "ProxyRevoke.h"
160 #include "ReflectObject.h"
161 #include "RegExpCache.h"
162 #include "RegExpConstructor.h"
163 #include "RegExpMatchesArray.h"
164 #include "RegExpObject.h"
165 #include "RegExpPrototype.h"
166 #include "RegExpStringIteratorPrototype.h"
167 #include "ScopedArguments.h"
168 #include "SetConstructor.h"
169 #include "SetIteratorPrototype.h"
170 #include "SetPrototype.h"
171 #include "StrictEvalActivation.h"
172 #include "StringConstructor.h"
173 #include "StringIteratorPrototype.h"
174 #include "StringPrototype.h"
175 #include "Symbol.h"
176 #include "SymbolConstructor.h"
177 #include "SymbolObject.h"
178 #include "SymbolPrototype.h"
179 #include "VariableWriteFireDetail.h"
180 #include "WasmCapabilities.h"
181 #include "WeakGCMapInlines.h"
182 #include "WeakMapConstructor.h"
183 #include "WeakMapPrototype.h"
184 #include "WeakObjectRefConstructor.h"
185 #include "WeakObjectRefPrototype.h"
186 #include "WeakSetConstructor.h"
187 #include "WeakSetPrototype.h"
188 #include "WebAssemblyCompileErrorConstructor.h"
189 #include "WebAssemblyCompileErrorPrototype.h"
190 #include "WebAssemblyFunction.h"
191 #include "WebAssemblyInstanceConstructor.h"
192 #include "WebAssemblyInstancePrototype.h"
193 #include "WebAssemblyLinkErrorConstructor.h"
194 #include "WebAssemblyLinkErrorPrototype.h"
195 #include "WebAssemblyMemoryConstructor.h"
196 #include "WebAssemblyMemoryPrototype.h"
197 #include "WebAssemblyModuleConstructor.h"
198 #include "WebAssemblyModulePrototype.h"
199 #include "WebAssemblyModuleRecord.h"
200 #include "WebAssemblyRuntimeErrorConstructor.h"
201 #include "WebAssemblyRuntimeErrorPrototype.h"
202 #include "WebAssemblyTableConstructor.h"
203 #include "WebAssemblyTablePrototype.h"
204 #include "WebAssemblyToJSCallee.h"
205 #include <wtf/RandomNumber.h>
206
207 #if ENABLE(INTL)
208 #include "IntlCollator.h"
209 #include "IntlCollatorPrototype.h"
210 #include "IntlDateTimeFormat.h"
211 #include "IntlDateTimeFormatPrototype.h"
212 #include "IntlNumberFormat.h"
213 #include "IntlNumberFormatPrototype.h"
214 #include "IntlObject.h"
215 #include "IntlPluralRules.h"
216 #include "IntlPluralRulesPrototype.h"
217 #include <unicode/ucol.h>
218 #include <unicode/udat.h>
219 #include <unicode/unum.h>
220 #endif // ENABLE(INTL)
221
222 #if ENABLE(REMOTE_INSPECTOR)
223 #include "JSGlobalObjectDebuggable.h"
224 #include "JSGlobalObjectInspectorController.h"
225 #endif
226
227 #ifdef JSC_GLIB_API_ENABLED
228 #include "JSCCallbackFunction.h"
229 #include "JSCWrapperMap.h"
230 #endif
231
232 namespace JSC {
233
234 #define CHECK_FEATURE_FLAG_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase, featureFlag) \
235 static_assert(std::is_same_v<std::remove_cv_t<decltype(featureFlag)>, bool> || std::is_same_v<std::remove_cv_t<decltype(featureFlag)>, bool&>);
236
237 FOR_EACH_SIMPLE_BUILTIN_TYPE(CHECK_FEATURE_FLAG_TYPE)
238 FOR_EACH_BUILTIN_DERIVED_ITERATOR_TYPE(CHECK_FEATURE_FLAG_TYPE)
239 FOR_EACH_LAZY_BUILTIN_TYPE(CHECK_FEATURE_FLAG_TYPE)
240
241 static JSValue createProxyProperty(VM& vm, JSObject* object)
242 {
243     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
244     return ProxyConstructor::create(vm, ProxyConstructor::createStructure(vm, global, global->functionPrototype()));
245 }
246
247 static JSValue createJSONProperty(VM& vm, JSObject* object)
248 {
249     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
250     return JSONObject::create(vm, JSONObject::createStructure(vm, global, global->objectPrototype()));
251 }
252
253 static JSValue createMathProperty(VM& vm, JSObject* object)
254 {
255     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
256     return MathObject::create(vm, global, MathObject::createStructure(vm, global, global->objectPrototype()));
257 }
258
259 static JSValue createReflectProperty(VM& vm, JSObject* object)
260 {
261     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
262     return ReflectObject::create(vm, global, ReflectObject::createStructure(vm, global, global->objectPrototype()));
263 }
264
265 static JSValue createConsoleProperty(VM& vm, JSObject* object)
266 {
267     JSGlobalObject* global = jsCast<JSGlobalObject*>(object);
268     return ConsoleObject::create(vm, global, ConsoleObject::createStructure(vm, global, constructEmptyObject(global->globalExec())));
269 }
270
271 static EncodedJSValue JSC_HOST_CALL makeBoundFunction(JSGlobalObject* globalObject, CallFrame* callFrame)
272 {
273     VM& vm = globalObject->vm();
274     auto scope = DECLARE_THROW_SCOPE(vm);
275
276     JSObject* target = asObject(callFrame->uncheckedArgument(0));
277     JSValue boundThis = callFrame->uncheckedArgument(1);
278     JSValue boundArgs = callFrame->uncheckedArgument(2);
279     JSValue lengthValue = callFrame->uncheckedArgument(3);
280     JSString* nameString = asString(callFrame->uncheckedArgument(4));
281
282     ASSERT(lengthValue.isInt32AsAnyInt());
283     int32_t length = lengthValue.asInt32AsAnyInt();
284
285     String name = nameString->value(callFrame);
286     RETURN_IF_EXCEPTION(scope, { });
287
288     RELEASE_AND_RETURN(scope, JSValue::encode(JSBoundFunction::create(vm, callFrame, globalObject, target, boundThis, boundArgs.isCell() ? jsCast<JSArray*>(boundArgs) : nullptr, length, WTFMove(name))));
289 }
290
291 static EncodedJSValue JSC_HOST_CALL hasOwnLengthProperty(JSGlobalObject* globalObject, CallFrame* callFrame)
292 {
293     VM& vm = globalObject->vm();
294     JSObject* target = asObject(callFrame->uncheckedArgument(0));
295     return JSValue::encode(jsBoolean(target->hasOwnProperty(callFrame, vm.propertyNames->length)));
296 }
297
298 #if !ASSERT_DISABLED
299 static EncodedJSValue JSC_HOST_CALL assertCall(JSGlobalObject*, CallFrame* callFrame)
300 {
301     RELEASE_ASSERT(callFrame->argument(0).isBoolean());
302     if (callFrame->argument(0).asBoolean())
303         return JSValue::encode(jsUndefined());
304
305     bool iteratedOnce = false;
306     CodeBlock* codeBlock = nullptr;
307     unsigned line;
308     callFrame->iterate([&] (StackVisitor& visitor) {
309         if (!iteratedOnce) {
310             iteratedOnce = true;
311             return StackVisitor::Continue;
312         }
313
314         RELEASE_ASSERT(visitor->hasLineAndColumnInfo());
315         unsigned column;
316         visitor->computeLineAndColumn(line, column);
317         codeBlock = visitor->codeBlock();
318         return StackVisitor::Done;
319     });
320     RELEASE_ASSERT(!!codeBlock);
321     RELEASE_ASSERT_WITH_MESSAGE(false, "JS assertion failed at line %u in:\n%s\n", line, codeBlock->sourceCodeForTools().data());
322     return JSValue::encode(jsUndefined());
323 }
324 #endif
325
326 } // namespace JSC
327
328 #include "JSGlobalObject.lut.h"
329
330 namespace JSC {
331
332 const ClassInfo JSGlobalObject::s_info = { "GlobalObject", &Base::s_info, &globalObjectTable, nullptr, CREATE_METHOD_TABLE(JSGlobalObject) };
333
334 const GlobalObjectMethodTable JSGlobalObject::s_globalObjectMethodTable = {
335     &supportsRichSourceInfo,
336     &shouldInterruptScript,
337     &javaScriptRuntimeFlags,
338     nullptr, // queueTaskToEventLoop
339     &shouldInterruptScriptBeforeTimeout,
340     nullptr, // moduleLoaderImportModule
341     nullptr, // moduleLoaderResolve
342     nullptr, // moduleLoaderFetch
343     nullptr, // moduleLoaderCreateImportMetaProperties
344     nullptr, // moduleLoaderEvaluate
345     nullptr, // promiseRejectionTracker
346     nullptr, // defaultLanguage
347     nullptr, // compileStreaming
348     nullptr, // instantiateStreaming
349 };
350
351 /* Source for JSGlobalObject.lut.h
352 @begin globalObjectTable
353   isNaN                 JSBuiltin                                    DontEnum|Function 1
354   isFinite              JSBuiltin                                    DontEnum|Function 1
355   escape                globalFuncEscape                             DontEnum|Function 1
356   unescape              globalFuncUnescape                           DontEnum|Function 1
357   decodeURI             globalFuncDecodeURI                          DontEnum|Function 1
358   decodeURIComponent    globalFuncDecodeURIComponent                 DontEnum|Function 1
359   encodeURI             globalFuncEncodeURI                          DontEnum|Function 1
360   encodeURIComponent    globalFuncEncodeURIComponent                 DontEnum|Function 1
361   eval                  JSGlobalObject::m_evalFunction               DontEnum|CellProperty
362   globalThis            JSGlobalObject::m_globalThis                 DontEnum|CellProperty
363   parseInt              JSGlobalObject::m_parseIntFunction           DontEnum|CellProperty
364   parseFloat            JSGlobalObject::m_parseFloatFunction         DontEnum|CellProperty
365   ArrayBuffer           JSGlobalObject::m_arrayBufferStructure       DontEnum|ClassStructure
366   EvalError             JSGlobalObject::m_evalErrorStructure         DontEnum|ClassStructure
367   RangeError            JSGlobalObject::m_rangeErrorStructure        DontEnum|ClassStructure
368   ReferenceError        JSGlobalObject::m_referenceErrorStructure    DontEnum|ClassStructure
369   SyntaxError           JSGlobalObject::m_syntaxErrorStructure       DontEnum|ClassStructure
370   TypeError             JSGlobalObject::m_typeErrorStructure         DontEnum|ClassStructure
371   URIError              JSGlobalObject::m_URIErrorStructure          DontEnum|ClassStructure
372   Proxy                 createProxyProperty                          DontEnum|PropertyCallback
373   Reflect               createReflectProperty                        DontEnum|PropertyCallback
374   JSON                  createJSONProperty                           DontEnum|PropertyCallback
375   Math                  createMathProperty                           DontEnum|PropertyCallback
376   console               createConsoleProperty                        DontEnum|PropertyCallback
377   Int8Array             JSGlobalObject::m_typedArrayInt8             DontEnum|ClassStructure
378   Int16Array            JSGlobalObject::m_typedArrayInt16            DontEnum|ClassStructure
379   Int32Array            JSGlobalObject::m_typedArrayInt32            DontEnum|ClassStructure
380   Uint8Array            JSGlobalObject::m_typedArrayUint8            DontEnum|ClassStructure
381   Uint8ClampedArray     JSGlobalObject::m_typedArrayUint8Clamped     DontEnum|ClassStructure
382   Uint16Array           JSGlobalObject::m_typedArrayUint16           DontEnum|ClassStructure
383   Uint32Array           JSGlobalObject::m_typedArrayUint32           DontEnum|ClassStructure
384   Float32Array          JSGlobalObject::m_typedArrayFloat32          DontEnum|ClassStructure
385   Float64Array          JSGlobalObject::m_typedArrayFloat64          DontEnum|ClassStructure
386   DataView              JSGlobalObject::m_typedArrayDataView         DontEnum|ClassStructure
387   Date                  JSGlobalObject::m_dateStructure              DontEnum|ClassStructure
388   Error                 JSGlobalObject::m_errorStructure             DontEnum|ClassStructure
389   Boolean               JSGlobalObject::m_booleanObjectStructure     DontEnum|ClassStructure
390   Number                JSGlobalObject::m_numberObjectStructure      DontEnum|ClassStructure
391   Symbol                JSGlobalObject::m_symbolObjectStructure      DontEnum|ClassStructure
392   WeakMap               JSGlobalObject::m_weakMapStructure           DontEnum|ClassStructure
393   WeakSet               JSGlobalObject::m_weakSetStructure           DontEnum|ClassStructure
394 @end
395 */
396
397 static EncodedJSValue JSC_HOST_CALL enqueueJob(JSGlobalObject* globalObject, CallFrame* callFrame)
398 {
399     VM& vm = globalObject->vm();
400
401     JSValue job = callFrame->argument(0);
402     JSValue argument0 = callFrame->argument(1);
403     JSValue argument1 = callFrame->argument(2);
404     JSValue argument2 = callFrame->argument(3);
405
406     globalObject->queueMicrotask(createJSMicrotask(vm, job, argument0, argument1, argument2));
407
408     return JSValue::encode(jsUndefined());
409 }
410
411 JSGlobalObject::JSGlobalObject(VM& vm, Structure* structure, const GlobalObjectMethodTable* globalObjectMethodTable)
412     : Base(vm, structure, 0)
413     , m_vm(vm)
414     , m_masqueradesAsUndefinedWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
415     , m_havingABadTimeWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
416     , m_varInjectionWatchpoint(adoptRef(new WatchpointSet(IsWatched)))
417     , m_weakRandom(Options::forceWeakRandomSeed() ? Options::forcedWeakRandomSeed() : static_cast<unsigned>(randomNumber() * (std::numeric_limits<unsigned>::max() + 1.0)))
418     , m_arrayIteratorProtocolWatchpointSet(IsWatched)
419     , m_mapIteratorProtocolWatchpointSet(IsWatched)
420     , m_setIteratorProtocolWatchpointSet(IsWatched)
421     , m_stringIteratorProtocolWatchpointSet(IsWatched)
422     , m_mapSetWatchpointSet(IsWatched)
423     , m_setAddWatchpointSet(IsWatched)
424     , m_arraySpeciesWatchpointSet(ClearWatchpoint)
425     , m_arrayJoinWatchpointSet(IsWatched)
426     , m_numberToStringWatchpointSet(IsWatched)
427     , m_runtimeFlags()
428     , m_stackTraceLimit(Options::defaultErrorStackTraceLimit())
429     , m_globalObjectMethodTable(globalObjectMethodTable ? globalObjectMethodTable : &s_globalObjectMethodTable)
430 {
431 }
432
433 JSGlobalObject::~JSGlobalObject()
434 {
435 #if ENABLE(REMOTE_INSPECTOR)
436     m_inspectorController->globalObjectDestroyed();
437 #endif
438
439     if (m_debugger)
440         m_debugger->detach(this, Debugger::GlobalObjectIsDestructing);
441 }
442
443 void JSGlobalObject::destroy(JSCell* cell)
444 {
445     static_cast<JSGlobalObject*>(cell)->JSGlobalObject::~JSGlobalObject();
446 }
447
448 void JSGlobalObject::setGlobalThis(VM& vm, JSObject* globalThis)
449 {
450     m_globalThis.set(vm, this, globalThis);
451 }
452
453 static JSObject* getGetterById(ExecState* exec, JSObject* base, const Identifier& ident)
454 {
455     JSValue baseValue = JSValue(base);
456     PropertySlot slot(baseValue, PropertySlot::InternalMethodType::VMInquiry);
457     baseValue.getPropertySlot(exec, ident, slot);
458     return slot.getPureResult().toObject(exec);
459 }
460
461 template<ErrorType errorType>
462 void JSGlobalObject::initializeErrorConstructor(LazyClassStructure::Initializer& init)
463 {
464     init.setPrototype(NativeErrorPrototype::create(init.vm, NativeErrorPrototype::createStructure(init.vm, this, m_errorStructure.prototype(this)), errorTypeName(errorType)));
465     init.setStructure(ErrorInstance::createStructure(init.vm, this, init.prototype));
466     init.setConstructor(NativeErrorConstructor<errorType>::create(init.vm, NativeErrorConstructor<errorType>::createStructure(init.vm, this, m_errorStructure.constructor(this)), jsCast<NativeErrorPrototype*>(init.prototype)));
467 }
468
469 void JSGlobalObject::init(VM& vm)
470 {
471     ASSERT(vm.currentThreadIsHoldingAPILock());
472     auto catchScope = DECLARE_CATCH_SCOPE(vm);
473
474     Base::setStructure(vm, Structure::toCacheableDictionaryTransition(vm, structure(vm)));
475
476     m_debugger = 0;
477
478 #if ENABLE(REMOTE_INSPECTOR)
479     m_inspectorController = makeUnique<Inspector::JSGlobalObjectInspectorController>(*this);
480     m_inspectorDebuggable = makeUnique<JSGlobalObjectDebuggable>(*this);
481     m_inspectorDebuggable->init();
482     m_consoleClient = m_inspectorController->consoleClient();
483 #endif
484
485     m_functionPrototype.set(vm, this, FunctionPrototype::create(vm, FunctionPrototype::createStructure(vm, this, jsNull()))); // The real prototype will be set once ObjectPrototype is created.
486     m_calleeStructure.set(vm, this, JSCallee::createStructure(vm, this, jsNull()));
487
488     m_globalLexicalEnvironment.set(vm, this, JSGlobalLexicalEnvironment::create(vm, JSGlobalLexicalEnvironment::createStructure(vm, this), this));
489     // Need to create the callee structure (above) before creating the callee.
490     JSCallee* globalCallee = JSCallee::create(vm, this, globalScope());
491     m_globalCallee.set(vm, this, globalCallee);
492
493     ExecState::initGlobalExec(JSGlobalObject::globalExec(), globalCallee);
494     ExecState* exec = JSGlobalObject::globalExec();
495
496     JSCallee* stackOverflowFrameCallee = JSCallee::create(vm, this, globalScope());
497     m_stackOverflowFrameCallee.set(vm, this, stackOverflowFrameCallee);
498
499     m_hostFunctionStructure.set(vm, this, JSFunction::createStructure(vm, this, m_functionPrototype.get()));
500
501     auto initFunctionStructures = [&] (FunctionStructures& structures) {
502         structures.strictFunctionStructure.set(vm, this, JSStrictFunction::createStructure(vm, this, m_functionPrototype.get()));
503         structures.sloppyFunctionStructure.set(vm, this, JSSloppyFunction::createStructure(vm, this, m_functionPrototype.get()));
504         structures.arrowFunctionStructure.set(vm, this, JSArrowFunction::createStructure(vm, this, m_functionPrototype.get()));
505     };
506     initFunctionStructures(m_builtinFunctions);
507     initFunctionStructures(m_ordinaryFunctions);
508
509     m_customGetterSetterFunctionStructure.initLater(
510         [] (const Initializer<Structure>& init) {
511             init.set(JSCustomGetterSetterFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
512         });
513     m_boundFunctionStructure.initLater(
514         [] (const Initializer<Structure>& init) {
515             init.set(JSBoundFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
516         });
517     m_getterSetterStructure.set(vm, this, GetterSetter::createStructure(vm, this, jsNull()));
518     m_nativeStdFunctionStructure.initLater(
519         [] (const Initializer<Structure>& init) {
520             init.set(JSNativeStdFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
521         });
522     JSFunction* callFunction = nullptr;
523     JSFunction* applyFunction = nullptr;
524     JSFunction* hasInstanceSymbolFunction = nullptr;
525     m_functionPrototype->addFunctionProperties(vm, this, &callFunction, &applyFunction, &hasInstanceSymbolFunction);
526     m_callFunction.set(vm, this, callFunction);
527     m_applyFunction.set(vm, this, applyFunction);
528     m_arrayProtoToStringFunction.initLater(
529         [] (const Initializer<JSFunction>& init) {
530             init.set(JSFunction::create(init.vm, init.owner, 0, init.vm.propertyNames->toString.string(), arrayProtoFuncToString, NoIntrinsic));
531         });
532     m_arrayProtoValuesFunction.initLater(
533         [] (const Initializer<JSFunction>& init) {
534             init.set(JSFunction::create(init.vm, arrayPrototypeValuesCodeGenerator(init.vm), init.owner));
535         });
536
537     m_iteratorProtocolFunction.initLater(
538         [] (const Initializer<JSFunction>& init) {
539             init.set(JSFunction::create(init.vm, iteratorHelpersPerformIterationCodeGenerator(init.vm), init.owner));
540         });
541
542     m_promiseResolveFunction.initLater(
543         [] (const Initializer<JSFunction>& init) {
544             init.set(JSFunction::create(init.vm, promiseConstructorResolveCodeGenerator(init.vm), init.owner));
545         });
546
547     m_newPromiseCapabilityFunction.set(vm, this, JSFunction::create(vm, promiseOperationsNewPromiseCapabilityCodeGenerator(vm), this));
548     m_functionProtoHasInstanceSymbolFunction.set(vm, this, hasInstanceSymbolFunction);
549     m_throwTypeErrorGetterSetter.initLater(
550         [] (const Initializer<GetterSetter>& init) {
551             JSFunction* thrower = init.owner->throwTypeErrorFunction();
552             GetterSetter* getterSetter = GetterSetter::create(init.vm, init.owner, thrower, thrower);
553             init.set(getterSetter);
554         });
555
556     m_nullGetterFunction.set(vm, this, NullGetterFunction::create(vm, NullGetterFunction::createStructure(vm, this, m_functionPrototype.get())));
557     m_nullSetterFunction.set(vm, this, NullSetterFunction::create(vm, NullSetterFunction::createStructure(vm, this, m_functionPrototype.get())));
558     m_objectPrototype.set(vm, this, ObjectPrototype::create(vm, this, ObjectPrototype::createStructure(vm, this, jsNull())));
559     // We have to manually set this here because we make it a prototype without transition below.
560     m_objectPrototype.get()->didBecomePrototype();
561     GetterSetter* protoAccessor = GetterSetter::create(vm, this,
562         JSFunction::create(vm, this, 0, makeString("get ", vm.propertyNames->underscoreProto.string()), globalFuncProtoGetter, UnderscoreProtoIntrinsic),
563         JSFunction::create(vm, this, 0, makeString("set ", vm.propertyNames->underscoreProto.string()), globalFuncProtoSetter));
564     m_objectPrototype->putDirectNonIndexAccessorWithoutTransition(vm, vm.propertyNames->underscoreProto, protoAccessor, PropertyAttribute::Accessor | PropertyAttribute::DontEnum);
565     m_functionPrototype->structure(vm)->setPrototypeWithoutTransition(vm, m_objectPrototype.get());
566     m_objectStructureForObjectConstructor.set(vm, this, vm.structureCache.emptyObjectStructureForPrototype(this, m_objectPrototype.get(), JSFinalObject::defaultInlineCapacity()));
567     m_objectProtoValueOfFunction.set(vm, this, jsCast<JSFunction*>(objectPrototype()->getDirect(vm, vm.propertyNames->valueOf)));
568     
569     JSFunction* thrower = JSFunction::create(vm, this, 0, String(), globalFuncThrowTypeErrorArgumentsCalleeAndCaller);
570     GetterSetter* getterSetter = GetterSetter::create(vm, this, thrower, thrower);
571     m_throwTypeErrorArgumentsCalleeAndCallerGetterSetter.set(vm, this, getterSetter);
572     
573     m_functionPrototype->initRestrictedProperties(vm, this);
574
575     m_speciesGetterSetter.set(vm, this, GetterSetter::create(vm, this, JSFunction::create(vm, globalOperationsSpeciesGetterCodeGenerator(vm), this), nullptr));
576
577     m_typedArrayProto.initLater(
578         [] (const Initializer<JSTypedArrayViewPrototype>& init) {
579             init.set(JSTypedArrayViewPrototype::create(init.vm, init.owner, JSTypedArrayViewPrototype::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get())));
580             
581             // Make sure that the constructor gets initialized, too.
582             init.owner->m_typedArraySuperConstructor.get(init.owner);
583         });
584     m_typedArraySuperConstructor.initLater(
585         [] (const Initializer<JSTypedArrayViewConstructor>& init) {
586             JSTypedArrayViewPrototype* prototype = init.owner->m_typedArrayProto.get(init.owner);
587             JSTypedArrayViewConstructor* constructor = JSTypedArrayViewConstructor::create(init.vm, init.owner, JSTypedArrayViewConstructor::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()), prototype, init.owner->m_speciesGetterSetter.get());
588             prototype->putDirectWithoutTransition(init.vm, init.vm.propertyNames->constructor, constructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
589             init.set(constructor);
590         });
591     
592 #define INIT_TYPED_ARRAY_LATER(type) \
593     m_typedArray ## type.initLater( \
594         [] (LazyClassStructure::Initializer& init) { \
595             init.setPrototype(JS ## type ## ArrayPrototype::create(init.vm, init.global, JS ## type ## ArrayPrototype::createStructure(init.vm, init.global, init.global->m_typedArrayProto.get(init.global)))); \
596             init.setStructure(JS ## type ## Array::createStructure(init.vm, init.global, init.prototype)); \
597             init.setConstructor(JS ## type ## ArrayConstructor::create(init.vm, init.global, JS ## type ## ArrayConstructor::createStructure(init.vm, init.global, init.global->m_typedArraySuperConstructor.get(init.global)), init.prototype, #type "Array"_s, typedArrayConstructorAllocate ## type ## ArrayCodeGenerator(init.vm))); \
598             init.global->putDirect(init.vm, init.vm.propertyNames->builtinNames().type ## ArrayPrivateName(), init.constructor, static_cast<unsigned>(PropertyAttribute::DontEnum)); \
599         });
600     FOR_EACH_TYPED_ARRAY_TYPE_EXCLUDING_DATA_VIEW(INIT_TYPED_ARRAY_LATER)
601 #undef INIT_TYPED_ARRAY_LATER
602     
603     m_typedArrayDataView.initLater(
604         [] (LazyClassStructure::Initializer& init) {
605             init.setPrototype(JSDataViewPrototype::create(init.vm, JSDataViewPrototype::createStructure(init.vm, init.global, init.global->m_objectPrototype.get())));
606             init.setStructure(JSDataView::createStructure(init.vm, init.global, init.prototype));
607             init.setConstructor(JSDataViewConstructor::create(init.vm, init.global, JSDataViewConstructor::createStructure(init.vm, init.global, init.global->m_functionPrototype.get()), init.prototype, "DataView"_s, nullptr));
608         });
609     
610     m_lexicalEnvironmentStructure.set(vm, this, JSLexicalEnvironment::createStructure(vm, this));
611     m_moduleEnvironmentStructure.initLater(
612         [] (const Initializer<Structure>& init) {
613             init.set(JSModuleEnvironment::createStructure(init.vm, init.owner));
614         });
615     m_strictEvalActivationStructure.initLater(
616         [] (const Initializer<Structure>& init) {
617             init.set(StrictEvalActivation::createStructure(init.vm, init.owner, jsNull()));
618         });
619     m_debuggerScopeStructure.initLater(
620         [] (const Initializer<Structure>& init) {
621             init.set(DebuggerScope::createStructure(init.vm, init.owner));
622         });
623     m_withScopeStructure.initLater(
624         [] (const Initializer<Structure>& init) {
625             init.set(JSWithScope::createStructure(init.vm, init.owner, jsNull()));
626         });
627     
628     m_nullPrototypeObjectStructure.set(vm, this, JSFinalObject::createStructure(vm, this, jsNull(), JSFinalObject::defaultInlineCapacity()));
629     
630     m_callbackFunctionStructure.initLater(
631         [] (const Initializer<Structure>& init) {
632             init.set(JSCallbackFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
633         });
634     m_directArgumentsStructure.set(vm, this, DirectArguments::createStructure(vm, this, m_objectPrototype.get()));
635     m_scopedArgumentsStructure.set(vm, this, ScopedArguments::createStructure(vm, this, m_objectPrototype.get()));
636     m_clonedArgumentsStructure.set(vm, this, ClonedArguments::createStructure(vm, this, m_objectPrototype.get()));
637     m_callbackConstructorStructure.initLater(
638         [] (const Initializer<Structure>& init) {
639             init.set(JSCallbackConstructor::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
640         });
641     m_callbackObjectStructure.initLater(
642         [] (const Initializer<Structure>& init) {
643             init.set(JSCallbackObject<JSDestructibleObject>::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
644         });
645
646 #if JSC_OBJC_API_ENABLED
647     m_objcCallbackFunctionStructure.initLater(
648         [] (const Initializer<Structure>& init) {
649             init.set(ObjCCallbackFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
650         });
651     m_objcWrapperObjectStructure.initLater(
652         [] (const Initializer<Structure>& init) {
653             init.set(JSCallbackObject<JSAPIWrapperObject>::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
654         });
655 #endif
656 #ifdef JSC_GLIB_API_ENABLED
657     m_glibCallbackFunctionStructure.initLater(
658         [] (const Initializer<Structure>& init) {
659             init.set(JSCCallbackFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
660         });
661     m_glibWrapperObjectStructure.initLater(
662         [] (const Initializer<Structure>& init) {
663             init.set(JSCallbackObject<JSAPIWrapperObject>::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
664         });
665 #endif
666     m_arrayPrototype.set(vm, this, ArrayPrototype::create(vm, this, ArrayPrototype::createStructure(vm, this, m_objectPrototype.get())));
667     
668     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(UndecidedShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithUndecided));
669     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(Int32Shape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithInt32));
670     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(DoubleShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithDouble));
671     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(ContiguousShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithContiguous));
672     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(ArrayStorageShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithArrayStorage));
673     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(SlowPutArrayStorageShape)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), ArrayWithSlowPutArrayStorage));
674     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(CopyOnWriteArrayWithInt32)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), CopyOnWriteArrayWithInt32));
675     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(CopyOnWriteArrayWithDouble)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), CopyOnWriteArrayWithDouble));
676     m_originalArrayStructureForIndexingShape[arrayIndexFromIndexingType(CopyOnWriteArrayWithContiguous)].set(vm, this, JSArray::createStructure(vm, this, m_arrayPrototype.get(), CopyOnWriteArrayWithContiguous));
677     for (unsigned i = 0; i < NumberOfArrayIndexingModes; ++i)
678         m_arrayStructureForIndexingShapeDuringAllocation[i] = m_originalArrayStructureForIndexingShape[i];
679
680     m_regExpPrototype.set(vm, this, RegExpPrototype::create(vm, this, RegExpPrototype::createStructure(vm, this, m_objectPrototype.get())));
681     m_regExpStructure.set(vm, this, RegExpObject::createStructure(vm, this, m_regExpPrototype.get()));
682     m_regExpMatchesArrayStructure.set(vm, this, createRegExpMatchesArrayStructure(vm, this));
683     m_regExpMatchesArrayWithGroupsStructure.set(vm, this, createRegExpMatchesArrayWithGroupsStructure(vm, this));
684
685     m_moduleRecordStructure.initLater(
686         [] (const Initializer<Structure>& init) {
687             init.set(JSModuleRecord::createStructure(init.vm, init.owner, jsNull()));
688         });
689     m_moduleNamespaceObjectStructure.initLater(
690         [] (const Initializer<Structure>& init) {
691             init.set(JSModuleNamespaceObject::createStructure(init.vm, init.owner, jsNull()));
692         });
693     m_proxyObjectStructure.initLater(
694         [] (const Initializer<Structure>& init) {
695             bool isCallable = false;
696             init.set(ProxyObject::createStructure(init.vm, init.owner, jsNull(), isCallable));
697         });
698     m_callableProxyObjectStructure.initLater(
699         [] (const Initializer<Structure>& init) {
700             bool isCallable = true;
701             init.set(ProxyObject::createStructure(init.vm, init.owner, jsNull(), isCallable));
702         });
703     m_proxyRevokeStructure.initLater(
704         [] (const Initializer<Structure>& init) {
705             init.set(ProxyRevoke::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
706         });
707
708     m_parseIntFunction.initLater(
709         [] (const Initializer<JSFunction>& init) {
710             init.set(JSFunction::create(init.vm, init.owner, 2, init.vm.propertyNames->parseInt.string(), globalFuncParseInt, ParseIntIntrinsic));
711         });
712     m_parseFloatFunction.initLater(
713         [] (const Initializer<JSFunction>& init) {
714             init.set(JSFunction::create(init.vm, init.owner, 1, init.vm.propertyNames->parseFloat.string(), globalFuncParseFloat, NoIntrinsic));
715         });
716     
717 #if ENABLE(SHARED_ARRAY_BUFFER)
718     m_sharedArrayBufferPrototype.set(vm, this, JSArrayBufferPrototype::create(vm, this, JSArrayBufferPrototype::createStructure(vm, this, m_objectPrototype.get()), ArrayBufferSharingMode::Shared));
719     m_sharedArrayBufferStructure.set(vm, this, JSArrayBuffer::createStructure(vm, this, m_sharedArrayBufferPrototype.get()));
720 #endif
721
722     m_iteratorPrototype.set(vm, this, IteratorPrototype::create(vm, this, IteratorPrototype::createStructure(vm, this, m_objectPrototype.get())));
723     m_asyncIteratorPrototype.set(vm, this, AsyncIteratorPrototype::create(vm, this, AsyncIteratorPrototype::createStructure(vm, this, m_objectPrototype.get())));
724
725     m_generatorPrototype.set(vm, this, GeneratorPrototype::create(vm, this, GeneratorPrototype::createStructure(vm, this, m_iteratorPrototype.get())));
726     m_asyncGeneratorPrototype.set(vm, this, AsyncGeneratorPrototype::create(vm, this, AsyncGeneratorPrototype::createStructure(vm, this, m_asyncIteratorPrototype.get())));
727
728     m_promiseProtoThenFunction.set(vm, this, JSFunction::create(vm, promisePrototypeThenCodeGenerator(vm), this));
729
730 #define CREATE_PROTOTYPE_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase, featureFlag) if (featureFlag) { \
731         m_ ## lowerName ## Prototype.set(vm, this, capitalName##Prototype::create(vm, this, capitalName##Prototype::createStructure(vm, this, m_ ## prototypeBase ## Prototype.get()))); \
732         m_ ## properName ## Structure.set(vm, this, instanceType::createStructure(vm, this, m_ ## lowerName ## Prototype.get())); \
733     }
734     
735     FOR_EACH_SIMPLE_BUILTIN_TYPE(CREATE_PROTOTYPE_FOR_SIMPLE_TYPE)
736     FOR_EACH_BUILTIN_DERIVED_ITERATOR_TYPE(CREATE_PROTOTYPE_FOR_SIMPLE_TYPE)
737     
738 #undef CREATE_PROTOTYPE_FOR_SIMPLE_TYPE
739
740 #define CREATE_PROTOTYPE_FOR_LAZY_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase, featureFlag) if (featureFlag) {  \
741     m_ ## properName ## Structure.initLater(\
742         [] (LazyClassStructure::Initializer& init) { \
743             init.setPrototype(capitalName##Prototype::create(init.vm, init.global, capitalName##Prototype::createStructure(init.vm, init.global, init.global->m_ ## prototypeBase ## Prototype.get()))); \
744             init.setStructure(instanceType::createStructure(init.vm, init.global, init.prototype)); \
745             init.setConstructor(capitalName ## Constructor::create(init.vm, capitalName ## Constructor::createStructure(init.vm, init.global, init.global->m_functionPrototype.get()), jsCast<capitalName ## Prototype*>(init.prototype), init.global->m_speciesGetterSetter.get())); \
746         }); \
747     }
748     
749     FOR_EACH_LAZY_BUILTIN_TYPE(CREATE_PROTOTYPE_FOR_LAZY_TYPE)
750     
751     // Constructors
752
753     ObjectConstructor* objectConstructor = ObjectConstructor::create(vm, this, ObjectConstructor::createStructure(vm, this, m_functionPrototype.get()), m_objectPrototype.get());
754     m_objectConstructor.set(vm, this, objectConstructor);
755
756     JSFunction* throwTypeErrorFunction = JSFunction::create(vm, this, 0, String(), globalFuncThrowTypeError);
757     m_throwTypeErrorFunction.set(vm, this, throwTypeErrorFunction);
758
759     JSCell* functionConstructor = FunctionConstructor::create(vm, FunctionConstructor::createStructure(vm, this, m_functionPrototype.get()), m_functionPrototype.get());
760
761     ArrayConstructor* arrayConstructor = ArrayConstructor::create(vm, this, ArrayConstructor::createStructure(vm, this, m_functionPrototype.get()), m_arrayPrototype.get(), m_speciesGetterSetter.get());
762     m_arrayConstructor.set(vm, this, arrayConstructor);
763     
764     RegExpConstructor* regExpConstructor = RegExpConstructor::create(vm, RegExpConstructor::createStructure(vm, this, m_functionPrototype.get()), m_regExpPrototype.get(), m_speciesGetterSetter.get());
765     m_regExpGlobalData.cachedResult().record(vm, this, nullptr, jsEmptyString(vm), MatchResult(0, 0));
766     
767 #if ENABLE(SHARED_ARRAY_BUFFER)
768     JSSharedArrayBufferConstructor* sharedArrayBufferConstructor = nullptr;
769     sharedArrayBufferConstructor = JSSharedArrayBufferConstructor::create(vm, JSSharedArrayBufferConstructor::createStructure(vm, this, m_functionPrototype.get()), m_sharedArrayBufferPrototype.get(), m_speciesGetterSetter.get());
770     m_sharedArrayBufferPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, sharedArrayBufferConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
771
772     AtomicsObject* atomicsObject = AtomicsObject::create(vm, this, AtomicsObject::createStructure(vm, this, m_objectPrototype.get()));
773 #endif
774
775 #define CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase, featureFlag) \
776 capitalName ## Constructor* lowerName ## Constructor = featureFlag ? capitalName ## Constructor::create(vm, capitalName ## Constructor::createStructure(vm, this, m_functionPrototype.get()), m_ ## lowerName ## Prototype.get(), m_speciesGetterSetter.get()) : nullptr; \
777     if (featureFlag) \
778         m_ ## lowerName ## Prototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, lowerName ## Constructor, static_cast<unsigned>(PropertyAttribute::DontEnum)); \
779
780     FOR_EACH_SIMPLE_BUILTIN_TYPE(CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE)
781     
782 #undef CREATE_CONSTRUCTOR_FOR_SIMPLE_TYPE
783
784     m_promiseConstructor.set(vm, this, promiseConstructor);
785     m_internalPromiseConstructor.set(vm, this, internalPromiseConstructor);
786     
787     m_evalErrorStructure.initLater(
788         [] (LazyClassStructure::Initializer& init) {
789             init.global->initializeErrorConstructor<ErrorType::EvalError>(init);
790         });
791     m_rangeErrorStructure.initLater(
792         [] (LazyClassStructure::Initializer& init) {
793             init.global->initializeErrorConstructor<ErrorType::RangeError>(init);
794         });
795     m_referenceErrorStructure.initLater(
796         [] (LazyClassStructure::Initializer& init) {
797             init.global->initializeErrorConstructor<ErrorType::ReferenceError>(init);
798         });
799     m_syntaxErrorStructure.initLater(
800         [] (LazyClassStructure::Initializer& init) {
801             init.global->initializeErrorConstructor<ErrorType::SyntaxError>(init);
802         });
803     m_typeErrorStructure.initLater(
804         [] (LazyClassStructure::Initializer& init) {
805             init.global->initializeErrorConstructor<ErrorType::TypeError>(init);
806         });
807     m_URIErrorStructure.initLater(
808         [] (LazyClassStructure::Initializer& init) {
809             init.global->initializeErrorConstructor<ErrorType::URIError>(init);
810         });
811
812     m_generatorFunctionPrototype.set(vm, this, GeneratorFunctionPrototype::create(vm, GeneratorFunctionPrototype::createStructure(vm, this, m_functionPrototype.get())));
813     GeneratorFunctionConstructor* generatorFunctionConstructor = GeneratorFunctionConstructor::create(vm, GeneratorFunctionConstructor::createStructure(vm, this, functionConstructor), m_generatorFunctionPrototype.get());
814     m_generatorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, generatorFunctionConstructor, PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
815     m_generatorFunctionStructure.set(vm, this, JSGeneratorFunction::createStructure(vm, this, m_generatorFunctionPrototype.get()));
816
817     m_generatorPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_generatorFunctionPrototype.get(), PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
818     m_generatorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->prototype, m_generatorPrototype.get(), PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
819     m_generatorStructure.set(vm, this, JSGenerator::createStructure(vm, this, m_generatorPrototype.get()));
820
821     m_asyncFunctionPrototype.set(vm, this, AsyncFunctionPrototype::create(vm, AsyncFunctionPrototype::createStructure(vm, this, m_functionPrototype.get())));
822     AsyncFunctionConstructor* asyncFunctionConstructor = AsyncFunctionConstructor::create(vm, AsyncFunctionConstructor::createStructure(vm, this, functionConstructor), m_asyncFunctionPrototype.get());
823     m_asyncFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, asyncFunctionConstructor, PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
824     m_asyncFunctionStructure.set(vm, this, JSAsyncFunction::createStructure(vm, this, m_asyncFunctionPrototype.get()));
825
826     m_asyncGeneratorFunctionPrototype.set(vm, this, AsyncGeneratorFunctionPrototype::create(vm, AsyncGeneratorFunctionPrototype::createStructure(vm, this, m_functionPrototype.get())));
827     AsyncGeneratorFunctionConstructor* asyncGeneratorFunctionConstructor = AsyncGeneratorFunctionConstructor::create(vm, AsyncGeneratorFunctionConstructor::createStructure(vm, this, functionConstructor), m_asyncGeneratorFunctionPrototype.get());
828     m_asyncGeneratorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, asyncGeneratorFunctionConstructor, PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
829     m_asyncGeneratorFunctionStructure.set(vm, this, JSAsyncGeneratorFunction::createStructure(vm, this, m_asyncGeneratorFunctionPrototype.get()));
830
831     m_asyncGeneratorPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, m_asyncGeneratorFunctionPrototype.get(), PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
832     m_asyncGeneratorFunctionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->prototype, m_asyncGeneratorPrototype.get(), PropertyAttribute::DontEnum | PropertyAttribute::ReadOnly);
833     m_asyncGeneratorStructure.set(vm, this, JSAsyncGenerator::createStructure(vm, this, m_asyncGeneratorPrototype.get()));
834     
835     m_objectPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, objectConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
836     m_functionPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, functionConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
837     m_arrayPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, arrayConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
838     m_regExpPrototype->putDirectWithoutTransition(vm, vm.propertyNames->constructor, regExpConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
839     
840     putDirectWithoutTransition(vm, vm.propertyNames->Object, objectConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
841     putDirectWithoutTransition(vm, vm.propertyNames->Function, functionConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
842     putDirectWithoutTransition(vm, vm.propertyNames->Array, arrayConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
843     putDirectWithoutTransition(vm, vm.propertyNames->RegExp, regExpConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
844
845     putDirectWithoutTransition(vm, vm.propertyNames->builtinNames().ObjectPrivateName(), objectConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly);
846     putDirectWithoutTransition(vm, vm.propertyNames->builtinNames().ArrayPrivateName(), arrayConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly);
847
848 #if ENABLE(SHARED_ARRAY_BUFFER)
849     putDirectWithoutTransition(vm, vm.propertyNames->SharedArrayBuffer, sharedArrayBufferConstructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
850     putDirectWithoutTransition(vm, Identifier::fromString(vm, "Atomics"), atomicsObject, static_cast<unsigned>(PropertyAttribute::DontEnum));
851 #endif
852
853 #define PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase, featureFlag) \
854     if (featureFlag) \
855         putDirectWithoutTransition(vm, vm.propertyNames-> jsName, lowerName ## Constructor, static_cast<unsigned>(PropertyAttribute::DontEnum));
856
857
858     FOR_EACH_SIMPLE_BUILTIN_TYPE_WITH_CONSTRUCTOR(PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE)
859
860 #undef PUT_CONSTRUCTOR_FOR_SIMPLE_TYPE
861     m_iteratorResultObjectStructure.initLater(
862         [] (const Initializer<Structure>& init) {
863             init.set(createIteratorResultObjectStructure(init.vm, *init.owner));
864         });
865     
866     m_evalFunction.initLater(
867         [] (const Initializer<JSFunction>& init) {
868             init.set(JSFunction::create(init.vm, init.owner, 1, init.vm.propertyNames->eval.string(), globalFuncEval, NoIntrinsic));
869         });
870     
871 #if ENABLE(INTL)
872     m_collatorStructure.initLater(
873         [] (const Initializer<Structure>& init) {
874             JSGlobalObject* globalObject = jsCast<JSGlobalObject*>(init.owner);
875             IntlCollatorPrototype* collatorPrototype = IntlCollatorPrototype::create(init.vm, globalObject, IntlCollatorPrototype::createStructure(init.vm, globalObject, globalObject->objectPrototype()));
876             init.set(IntlCollator::createStructure(init.vm, globalObject, collatorPrototype));
877         });
878     m_numberFormatStructure.initLater(
879         [] (const Initializer<Structure>& init) {
880             JSGlobalObject* globalObject = jsCast<JSGlobalObject*>(init.owner);
881             IntlNumberFormatPrototype* numberFormatPrototype = IntlNumberFormatPrototype::create(init.vm, globalObject, IntlNumberFormatPrototype::createStructure(init.vm, globalObject, globalObject->objectPrototype()));
882             init.set(IntlNumberFormat::createStructure(init.vm, globalObject, numberFormatPrototype));
883         });
884     m_dateTimeFormatStructure.initLater(
885         [] (const Initializer<Structure>& init) {
886             JSGlobalObject* globalObject = jsCast<JSGlobalObject*>(init.owner);
887             IntlDateTimeFormatPrototype* dateTimeFormatPrototype = IntlDateTimeFormatPrototype::create(init.vm, globalObject, IntlDateTimeFormatPrototype::createStructure(init.vm, globalObject, globalObject->objectPrototype()));
888             init.set(IntlDateTimeFormat::createStructure(init.vm, globalObject, dateTimeFormatPrototype));
889         });
890     m_pluralRulesStructure.initLater(
891         [] (const Initializer<Structure>& init) {
892             JSGlobalObject* globalObject = jsCast<JSGlobalObject*>(init.owner);
893             IntlPluralRulesPrototype* pluralRulesPrototype = IntlPluralRulesPrototype::create(init.vm, globalObject, IntlPluralRulesPrototype::createStructure(init.vm, globalObject, globalObject->objectPrototype()));
894             init.set(IntlPluralRules::createStructure(init.vm, globalObject, pluralRulesPrototype));
895         });
896
897     IntlObject* intl = IntlObject::create(vm, IntlObject::createStructure(vm, this, m_objectPrototype.get()));
898     putDirectWithoutTransition(vm, vm.propertyNames->Intl, intl, static_cast<unsigned>(PropertyAttribute::DontEnum));
899 #endif // ENABLE(INTL)
900
901     m_moduleLoader.initLater(
902         [] (const Initializer<JSModuleLoader>& init) {
903             auto catchScope = DECLARE_CATCH_SCOPE(init.vm);
904             init.set(JSModuleLoader::create(init.owner->globalExec(), init.vm, init.owner, JSModuleLoader::createStructure(init.vm, init.owner, jsNull())));
905             catchScope.releaseAssertNoException();
906         });
907     if (Options::exposeInternalModuleLoader())
908         putDirectWithoutTransition(vm, vm.propertyNames->Loader, moduleLoader(), static_cast<unsigned>(PropertyAttribute::DontEnum));
909
910     JSFunction* builtinLog = JSFunction::create(vm, this, 1, vm.propertyNames->emptyIdentifier.string(), globalFuncBuiltinLog);
911     JSFunction* builtinDescribe = JSFunction::create(vm, this, 1, vm.propertyNames->emptyIdentifier.string(), globalFuncBuiltinDescribe);
912
913     JSFunction* privateFuncTrunc = JSFunction::create(vm, this, 0, String(), mathProtoFuncTrunc, TruncIntrinsic);
914
915     JSFunction* privateFuncPropertyIsEnumerable = JSFunction::create(vm, this, 0, String(), globalFuncPropertyIsEnumerable);
916     JSFunction* privateFuncOwnKeys = JSFunction::create(vm, this, 0, String(), globalFuncOwnKeys);
917     JSFunction* privateFuncImportModule = JSFunction::create(vm, this, 0, String(), globalFuncImportModule);
918     JSFunction* privateFuncMakeTypeError = JSFunction::create(vm, this, 0, String(), globalFuncMakeTypeError);
919     JSFunction* privateFuncTypedArrayLength = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncLength);
920     JSFunction* privateFuncTypedArrayGetOriginalConstructor = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncGetOriginalConstructor);
921     JSFunction* privateFuncTypedArraySort = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncSort);
922     JSFunction* privateFuncIsTypedArrayView = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncIsTypedArrayView, IsTypedArrayViewIntrinsic);
923     JSFunction* privateFuncTypedArraySubarrayCreate = JSFunction::create(vm, this, 0, String(), typedArrayViewPrivateFuncSubarrayCreate);
924     JSFunction* privateFuncIsBoundFunction = JSFunction::create(vm, this, 0, String(), isBoundFunction);
925     JSFunction* privateFuncHasInstanceBoundFunction = JSFunction::create(vm, this, 0, String(), hasInstanceBoundFunction);
926     JSFunction* privateFuncInstanceOf = JSFunction::create(vm, this, 0, String(), objectPrivateFuncInstanceOf);
927     JSFunction* privateFuncThisTimeValue = JSFunction::create(vm, this, 0, String(), dateProtoFuncGetTime);
928 #if ENABLE(INTL)
929     JSFunction* privateFuncDateTimeFormat = JSFunction::create(vm, this, 0, String(), globalFuncDateTimeFormat);
930 #endif
931     JSFunction* privateFuncIsArraySlow = JSFunction::create(vm, this, 0, String(), arrayConstructorPrivateFuncIsArraySlow);
932     JSFunction* privateFuncConcatMemcpy = JSFunction::create(vm, this, 0, String(), arrayProtoPrivateFuncConcatMemcpy);
933     JSFunction* privateFuncAppendMemcpy = JSFunction::create(vm, this, 0, String(), arrayProtoPrivateFuncAppendMemcpy);
934     JSFunction* privateFuncMapBucketHead = JSFunction::create(vm, this, 0, String(), mapPrivateFuncMapBucketHead, JSMapBucketHeadIntrinsic);
935     JSFunction* privateFuncMapBucketNext = JSFunction::create(vm, this, 0, String(), mapPrivateFuncMapBucketNext, JSMapBucketNextIntrinsic);
936     JSFunction* privateFuncMapBucketKey = JSFunction::create(vm, this, 0, String(), mapPrivateFuncMapBucketKey, JSMapBucketKeyIntrinsic);
937     JSFunction* privateFuncMapBucketValue = JSFunction::create(vm, this, 0, String(), mapPrivateFuncMapBucketValue, JSMapBucketValueIntrinsic);
938     JSFunction* privateFuncSetBucketHead = JSFunction::create(vm, this, 0, String(), setPrivateFuncSetBucketHead, JSSetBucketHeadIntrinsic);
939     JSFunction* privateFuncSetBucketNext = JSFunction::create(vm, this, 0, String(), setPrivateFuncSetBucketNext, JSSetBucketNextIntrinsic);
940     JSFunction* privateFuncSetBucketKey = JSFunction::create(vm, this, 0, String(), setPrivateFuncSetBucketKey, JSSetBucketKeyIntrinsic);
941
942     JSObject* regExpProtoFlagsGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->flags);
943     catchScope.assertNoException();
944     JSObject* regExpProtoGlobalGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->global);
945     catchScope.assertNoException();
946     m_regExpProtoGlobalGetter.set(vm, this, regExpProtoGlobalGetterObject);
947     JSObject* regExpProtoIgnoreCaseGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->ignoreCase);
948     catchScope.assertNoException();
949     JSObject* regExpProtoMultilineGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->multiline);
950     catchScope.assertNoException();
951     JSObject* regExpProtoSourceGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->source);
952     catchScope.assertNoException();
953     JSObject* regExpProtoStickyGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->sticky);
954     catchScope.assertNoException();
955     JSObject* regExpProtoUnicodeGetterObject = getGetterById(exec, m_regExpPrototype.get(), vm.propertyNames->unicode);
956     catchScope.assertNoException();
957     m_regExpProtoUnicodeGetter.set(vm, this, regExpProtoUnicodeGetterObject);
958     JSObject* builtinRegExpExec = asObject(m_regExpPrototype->getDirect(vm, vm.propertyNames->exec).asCell());
959     m_regExpProtoExec.set(vm, this, builtinRegExpExec);
960     JSObject* regExpSymbolReplace = asObject(m_regExpPrototype->getDirect(vm, vm.propertyNames->replaceSymbol).asCell());
961     m_regExpProtoSymbolReplace.set(vm, this, regExpSymbolReplace);
962
963 #define CREATE_PRIVATE_GLOBAL_FUNCTION(varName, funcName, code) JSFunction* varName ## PrivateFunction = JSFunction::create(vm, code ## CodeGenerator(vm), this);
964     JSC_FOREACH_BUILTIN_FUNCTION_PRIVATE_GLOBAL_NAME(CREATE_PRIVATE_GLOBAL_FUNCTION)
965 #undef CREATE_PRIVATE_GLOBAL_FUNCTION
966
967     JSObject* arrayIteratorPrototype = ArrayIteratorPrototype::create(vm, this, ArrayIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
968     arrayIteratorConstructorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, arrayIteratorPrototype);
969
970     JSObject* asyncFromSyncIteratorPrototype = AsyncFromSyncIteratorPrototype::create(vm, this, AsyncFromSyncIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
971     asyncFromSyncIteratorConstructorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, asyncFromSyncIteratorPrototype);
972
973     JSObject* mapIteratorPrototype = MapIteratorPrototype::create(vm, this, MapIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
974     mapIteratorConstructorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, mapIteratorPrototype);
975
976     JSObject* regExpStringIteratorPrototype = RegExpStringIteratorPrototype::create(vm, this, RegExpStringIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
977     regExpStringIteratorConstructorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, regExpStringIteratorPrototype);
978
979     JSObject* setIteratorPrototype = SetIteratorPrototype::create(vm, this, SetIteratorPrototype::createStructure(vm, this, m_iteratorPrototype.get()));
980     setIteratorConstructorPrivateFunction->putDirect(vm, vm.propertyNames->prototype, setIteratorPrototype);
981
982     GlobalPropertyInfo staticGlobals[] = {
983 #define INIT_PRIVATE_GLOBAL(varName, funcName, code) GlobalPropertyInfo(vm.propertyNames->builtinNames().funcName ## PrivateName(), varName ## PrivateFunction, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
984         JSC_FOREACH_BUILTIN_FUNCTION_PRIVATE_GLOBAL_NAME(INIT_PRIVATE_GLOBAL)
985 #undef INIT_PRIVATE_GLOBAL
986         GlobalPropertyInfo(vm.propertyNames->NaN, jsNaN(), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
987         GlobalPropertyInfo(vm.propertyNames->Infinity, jsNumber(std::numeric_limits<double>::infinity()), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
988         GlobalPropertyInfo(vm.propertyNames->undefinedKeyword, jsUndefined(), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
989         GlobalPropertyInfo(vm.propertyNames->builtinNames().propertyIsEnumerablePrivateName(), privateFuncPropertyIsEnumerable, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
990         GlobalPropertyInfo(vm.propertyNames->builtinNames().ownKeysPrivateName(), privateFuncOwnKeys, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
991         GlobalPropertyInfo(vm.propertyNames->builtinNames().importModulePrivateName(), privateFuncImportModule, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
992         GlobalPropertyInfo(vm.propertyNames->builtinNames().enqueueJobPrivateName(), JSFunction::create(vm, this, 0, String(), enqueueJob), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
993         GlobalPropertyInfo(vm.propertyNames->builtinNames().makeTypeErrorPrivateName(), privateFuncMakeTypeError, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
994         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArrayLengthPrivateName(), privateFuncTypedArrayLength, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
995         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArrayGetOriginalConstructorPrivateName(), privateFuncTypedArrayGetOriginalConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
996         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArraySortPrivateName(), privateFuncTypedArraySort, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
997         GlobalPropertyInfo(vm.propertyNames->builtinNames().isTypedArrayViewPrivateName(), privateFuncIsTypedArrayView, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
998         GlobalPropertyInfo(vm.propertyNames->builtinNames().typedArraySubarrayCreatePrivateName(), privateFuncTypedArraySubarrayCreate, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
999         GlobalPropertyInfo(vm.propertyNames->builtinNames().isBoundFunctionPrivateName(), privateFuncIsBoundFunction, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1000         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasInstanceBoundFunctionPrivateName(), privateFuncHasInstanceBoundFunction, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1001         GlobalPropertyInfo(vm.propertyNames->builtinNames().instanceOfPrivateName(), privateFuncInstanceOf, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1002         GlobalPropertyInfo(vm.propertyNames->builtinNames().BuiltinLogPrivateName(), builtinLog, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1003         GlobalPropertyInfo(vm.propertyNames->builtinNames().BuiltinDescribePrivateName(), builtinDescribe, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1004         GlobalPropertyInfo(vm.propertyNames->builtinNames().RegExpPrivateName(), regExpConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1005         GlobalPropertyInfo(vm.propertyNames->builtinNames().truncPrivateName(), privateFuncTrunc, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1006         GlobalPropertyInfo(vm.propertyNames->builtinNames().PromisePrivateName(), promiseConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1007         GlobalPropertyInfo(vm.propertyNames->builtinNames().InternalPromisePrivateName(), internalPromiseConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1008         GlobalPropertyInfo(vm.propertyNames->builtinNames().defaultPromiseThenPrivateName(), promiseProtoThenFunction(), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1009
1010         GlobalPropertyInfo(vm.propertyNames->builtinNames().repeatCharacterPrivateName(), JSFunction::create(vm, this, 2, String(), stringProtoFuncRepeatCharacter), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1011         GlobalPropertyInfo(vm.propertyNames->builtinNames().arraySpeciesCreatePrivateName(), JSFunction::create(vm, this, 2, String(), arrayProtoFuncSpeciesCreate), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1012         GlobalPropertyInfo(vm.propertyNames->builtinNames().isArrayPrivateName(), arrayConstructor->getDirect(vm, vm.propertyNames->isArray), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1013         GlobalPropertyInfo(vm.propertyNames->builtinNames().isArraySlowPrivateName(), privateFuncIsArraySlow, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1014         GlobalPropertyInfo(vm.propertyNames->builtinNames().concatMemcpyPrivateName(), privateFuncConcatMemcpy, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1015         GlobalPropertyInfo(vm.propertyNames->builtinNames().appendMemcpyPrivateName(), privateFuncAppendMemcpy, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1016
1017         GlobalPropertyInfo(vm.propertyNames->builtinNames().hostPromiseRejectionTrackerPrivateName(), JSFunction::create(vm, this, 2, String(), globalFuncHostPromiseRejectionTracker), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1018         GlobalPropertyInfo(vm.propertyNames->builtinNames().InspectorInstrumentationPrivateName(), InspectorInstrumentationObject::create(vm, this, InspectorInstrumentationObject::createStructure(vm, this, m_objectPrototype.get())), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1019         GlobalPropertyInfo(vm.propertyNames->builtinNames().SetPrivateName(), setConstructor, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1020         GlobalPropertyInfo(vm.propertyNames->builtinNames().thisTimeValuePrivateName(), privateFuncThisTimeValue, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1021 #if ENABLE(INTL)
1022         GlobalPropertyInfo(vm.propertyNames->builtinNames().dateTimeFormatPrivateName(), privateFuncDateTimeFormat, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1023 #endif // ENABLE(INTL)
1024
1025         GlobalPropertyInfo(vm.propertyNames->builtinNames().isConstructorPrivateName(), JSFunction::create(vm, this, 1, String(), esSpecIsConstructor, NoIntrinsic), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1026
1027         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoFlagsGetterPrivateName(), regExpProtoFlagsGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1028         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoGlobalGetterPrivateName(), regExpProtoGlobalGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1029         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoIgnoreCaseGetterPrivateName(), regExpProtoIgnoreCaseGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1030         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoMultilineGetterPrivateName(), regExpProtoMultilineGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1031         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoSourceGetterPrivateName(), regExpProtoSourceGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1032         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoStickyGetterPrivateName(), regExpProtoStickyGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1033         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpProtoUnicodeGetterPrivateName(), regExpProtoUnicodeGetterObject, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1034
1035         // RegExp.prototype helpers.
1036         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpBuiltinExecPrivateName(), builtinRegExpExec, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1037         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpCreatePrivateName(), JSFunction::create(vm, this, 2, String(), esSpecRegExpCreate, NoIntrinsic), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1038         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpMatchFastPrivateName(), JSFunction::create(vm, this, 1, String(), regExpProtoFuncMatchFast, RegExpMatchFastIntrinsic), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1039         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpSearchFastPrivateName(), JSFunction::create(vm, this, 1, String(), regExpProtoFuncSearchFast), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1040         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpSplitFastPrivateName(), JSFunction::create(vm, this, 2, String(), regExpProtoFuncSplitFast), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1041         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpPrototypeSymbolReplacePrivateName(), m_regExpPrototype->getDirect(vm, vm.propertyNames->replaceSymbol), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1042         GlobalPropertyInfo(vm.propertyNames->builtinNames().regExpTestFastPrivateName(), JSFunction::create(vm, this, 1, String(), regExpProtoFuncTestFast, RegExpTestFastIntrinsic), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1043
1044         // String.prototype helpers.
1045         GlobalPropertyInfo(vm.propertyNames->builtinNames().stringIncludesInternalPrivateName(), JSFunction::create(vm, this, 1, String(), builtinStringIncludesInternal), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1046         GlobalPropertyInfo(vm.propertyNames->builtinNames().stringSplitFastPrivateName(), JSFunction::create(vm, this, 2, String(), stringProtoFuncSplitFast), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1047         GlobalPropertyInfo(vm.propertyNames->builtinNames().stringSubstrInternalPrivateName(), JSFunction::create(vm, this, 2, String(), builtinStringSubstrInternal), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1048
1049         // Function prototype helpers.
1050         GlobalPropertyInfo(vm.propertyNames->builtinNames().makeBoundFunctionPrivateName(), JSFunction::create(vm, this, 5, String(), makeBoundFunction), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1051         GlobalPropertyInfo(vm.propertyNames->builtinNames().hasOwnLengthPropertyPrivateName(), JSFunction::create(vm, this, 1, String(), hasOwnLengthProperty), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1052
1053         // Map and Set helpers.
1054         GlobalPropertyInfo(vm.propertyNames->builtinNames().mapBucketHeadPrivateName(), privateFuncMapBucketHead, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1055         GlobalPropertyInfo(vm.propertyNames->builtinNames().mapBucketNextPrivateName(), privateFuncMapBucketNext, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1056         GlobalPropertyInfo(vm.propertyNames->builtinNames().mapBucketKeyPrivateName(), privateFuncMapBucketKey, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1057         GlobalPropertyInfo(vm.propertyNames->builtinNames().mapBucketValuePrivateName(), privateFuncMapBucketValue, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1058         GlobalPropertyInfo(vm.propertyNames->builtinNames().setBucketHeadPrivateName(), privateFuncSetBucketHead, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1059         GlobalPropertyInfo(vm.propertyNames->builtinNames().setBucketNextPrivateName(), privateFuncSetBucketNext, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1060         GlobalPropertyInfo(vm.propertyNames->builtinNames().setBucketKeyPrivateName(), privateFuncSetBucketKey, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1061 #if ENABLE(WEBASSEMBLY) && ENABLE(WEBASSEMBLY_STREAMING_API)
1062         // WebAssembly Streaming API
1063         GlobalPropertyInfo(vm.propertyNames->builtinNames().webAssemblyCompileStreamingInternalPrivateName(), JSFunction::create(vm, this, 1, String(), webAssemblyCompileStreamingInternal), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1064         GlobalPropertyInfo(vm.propertyNames->builtinNames().webAssemblyInstantiateStreamingInternalPrivateName(), JSFunction::create(vm, this, 1, String(), webAssemblyInstantiateStreamingInternal), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1065 #endif
1066 #if !ASSERT_DISABLED
1067         GlobalPropertyInfo(vm.propertyNames->builtinNames().assertPrivateName(), JSFunction::create(vm, this, 1, String(), assertCall), PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1068 #endif
1069     };
1070     addStaticGlobals(staticGlobals, WTF_ARRAY_LENGTH(staticGlobals));
1071     
1072     m_specialPointers[Special::CallFunction] = m_callFunction.get();
1073     m_specialPointers[Special::ApplyFunction] = m_applyFunction.get();
1074     m_specialPointers[Special::ObjectConstructor] = objectConstructor;
1075     m_specialPointers[Special::ArrayConstructor] = arrayConstructor;
1076
1077     m_linkTimeConstants[static_cast<unsigned>(LinkTimeConstant::ThrowTypeErrorFunction)] = m_throwTypeErrorFunction.get();
1078
1079     if (UNLIKELY(Options::useDollarVM()))
1080         exposeDollarVM(vm);
1081
1082 #if ENABLE(WEBASSEMBLY)
1083     if (Wasm::isSupported()) {
1084         m_webAssemblyModuleRecordStructure.initLater(
1085             [] (const Initializer<Structure>& init) {
1086                 init.set(WebAssemblyModuleRecord::createStructure(init.vm, init.owner, init.owner->m_objectPrototype.get()));
1087             });
1088         m_webAssemblyFunctionStructure.initLater(
1089             [] (const Initializer<Structure>& init) {
1090                 init.set(WebAssemblyFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
1091             });
1092         m_jsToWasmICCalleeStructure.initLater(
1093             [] (const Initializer<Structure>& init) {
1094                 init.set(JSToWasmICCallee::createStructure(init.vm, init.owner, jsNull()));
1095             });
1096         m_webAssemblyWrapperFunctionStructure.initLater(
1097             [] (const Initializer<Structure>& init) {
1098                 init.set(WebAssemblyWrapperFunction::createStructure(init.vm, init.owner, init.owner->m_functionPrototype.get()));
1099             });
1100         m_webAssemblyToJSCalleeStructure.initLater(
1101             [] (const Initializer<Structure>& init) {
1102                 init.set(WebAssemblyToJSCallee::createStructure(init.vm, init.owner, jsNull()));
1103             });
1104         auto* webAssembly = JSWebAssembly::create(vm, this, JSWebAssembly::createStructure(vm, this, m_objectPrototype.get()));
1105         putDirectWithoutTransition(vm, Identifier::fromString(vm, "WebAssembly"), webAssembly, static_cast<unsigned>(PropertyAttribute::DontEnum));
1106
1107 #define CREATE_WEBASSEMBLY_PROTOTYPE(capitalName, lowerName, properName, instanceType, jsName, prototypeBase, featureFlag) \
1108     if (featureFlag) {\
1109         m_ ## properName ## Structure.initLater(\
1110             [] (LazyClassStructure::Initializer& init) { \
1111                 init.setPrototype(capitalName##Prototype::create(init.vm, init.global, capitalName##Prototype::createStructure(init.vm, init.global, init.global->prototypeBase ## Prototype()))); \
1112                 init.setStructure(instanceType::createStructure(init.vm, init.global, init.prototype)); \
1113                 init.setConstructor(capitalName ## Constructor::create(init.vm, capitalName ## Constructor::createStructure(init.vm, init.global, init.global->functionPrototype()), jsCast<capitalName ## Prototype*>(init.prototype))); \
1114             }); \
1115     }
1116
1117         FOR_EACH_WEBASSEMBLY_CONSTRUCTOR_TYPE(CREATE_WEBASSEMBLY_PROTOTYPE)
1118
1119 #undef CREATE_WEBASSEMBLY_CONSTRUCTOR
1120     }
1121 #endif // ENABLE(WEBASSEMBLY)
1122
1123 #undef CREATE_PROTOTYPE_FOR_LAZY_TYPE
1124
1125     auto setupAdaptiveWatchpoint = [&] (JSObject* base, const Identifier& ident) -> ObjectPropertyCondition {
1126         // Performing these gets should not throw.
1127         ExecState* exec = globalExec();
1128         PropertySlot slot(base, PropertySlot::InternalMethodType::Get);
1129         bool result = base->getOwnPropertySlot(base, exec, ident, slot);
1130         ASSERT_UNUSED(result, result);
1131         catchScope.assertNoException();
1132         RELEASE_ASSERT(slot.isCacheableValue());
1133         JSValue functionValue = slot.getValue(exec, ident);
1134         catchScope.assertNoException();
1135         ASSERT(jsDynamicCast<JSFunction*>(vm, functionValue));
1136
1137         ObjectPropertyCondition condition = generateConditionForSelfEquivalence(m_vm, nullptr, base, ident.impl());
1138         RELEASE_ASSERT(condition.requiredValue() == functionValue);
1139
1140         bool isWatchable = condition.isWatchable(PropertyCondition::EnsureWatchability);
1141         RELEASE_ASSERT(isWatchable); // We allow this to install the necessary watchpoints.
1142
1143         return condition;
1144     };
1145
1146     {
1147         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(arrayIteratorPrototype, m_vm.propertyNames->next);
1148         m_arrayIteratorPrototypeNext = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_arrayIteratorProtocolWatchpointSet);
1149         m_arrayIteratorPrototypeNext->install(vm);
1150     }
1151     {
1152         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(this->arrayPrototype(), m_vm.propertyNames->iteratorSymbol);
1153         m_arrayPrototypeSymbolIteratorWatchpoint = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_arrayIteratorProtocolWatchpointSet);
1154         m_arrayPrototypeSymbolIteratorWatchpoint->install(vm);
1155     }
1156     {
1157         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(this->arrayPrototype(), m_vm.propertyNames->join);
1158         m_arrayPrototypeJoinWatchpoint = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_arrayJoinWatchpointSet);
1159         m_arrayPrototypeJoinWatchpoint->install(vm);
1160     }
1161
1162     {
1163         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(mapIteratorPrototype, m_vm.propertyNames->next);
1164         m_mapIteratorPrototypeNextWatchpoint = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_mapIteratorProtocolWatchpointSet);
1165         m_mapIteratorPrototypeNextWatchpoint->install(vm);
1166     }
1167     {
1168         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_mapPrototype.get(), m_vm.propertyNames->iteratorSymbol);
1169         m_mapPrototypeSymbolIteratorWatchpoint = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_mapIteratorProtocolWatchpointSet);
1170         m_mapPrototypeSymbolIteratorWatchpoint->install(vm);
1171     }
1172
1173     {
1174         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(setIteratorPrototype, m_vm.propertyNames->next);
1175         m_setIteratorPrototypeNextWatchpoint = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_setIteratorProtocolWatchpointSet);
1176         m_setIteratorPrototypeNextWatchpoint->install(vm);
1177     }
1178     {
1179         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_setPrototype.get(), m_vm.propertyNames->iteratorSymbol);
1180         m_setPrototypeSymbolIteratorWatchpoint = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_setIteratorProtocolWatchpointSet);
1181         m_setPrototypeSymbolIteratorWatchpoint->install(vm);
1182     }
1183
1184     {
1185         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_stringIteratorPrototype.get(), m_vm.propertyNames->next);
1186         m_stringIteratorPrototypeNextWatchpoint = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_stringIteratorProtocolWatchpointSet);
1187         m_stringIteratorPrototypeNextWatchpoint->install(vm);
1188     }
1189     {
1190         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_stringPrototype.get(), m_vm.propertyNames->iteratorSymbol);
1191         m_stringPrototypeSymbolIteratorWatchpoint = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_stringIteratorProtocolWatchpointSet);
1192         m_stringPrototypeSymbolIteratorWatchpoint->install(vm);
1193     }
1194
1195     {
1196         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_mapPrototype.get(), m_vm.propertyNames->set);
1197         m_mapPrototypeSetWatchpoint = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_mapSetWatchpointSet);
1198         m_mapPrototypeSetWatchpoint->install(vm);
1199     }
1200
1201     {
1202         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(m_setPrototype.get(), m_vm.propertyNames->add);
1203         m_setPrototypeAddWatchpoint = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_setAddWatchpointSet);
1204         m_setPrototypeAddWatchpoint->install(vm);
1205     }
1206
1207     // Unfortunately, the prototype objects of the builtin objects can be touched from concurrent compilers. So eagerly initialize them only if we use JIT.
1208     if (VM::canUseJIT()) {
1209         this->booleanPrototype();
1210         auto* numberPrototype = this->numberPrototype();
1211         this->symbolPrototype();
1212
1213         ObjectPropertyCondition condition = setupAdaptiveWatchpoint(numberPrototype, m_vm.propertyNames->toString);
1214         m_numberPrototypeToStringWatchpoint = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, condition, m_numberToStringWatchpointSet);
1215         m_numberPrototypeToStringWatchpoint->install(vm);
1216         m_numberProtoToStringFunction.set(vm, this, jsCast<JSFunction*>(numberPrototype->getDirect(vm, vm.propertyNames->toString)));
1217     }
1218
1219     fixupPrototypeChainWithObjectPrototype(vm);
1220 }
1221
1222 bool JSGlobalObject::put(JSCell* cell, ExecState* exec, PropertyName propertyName, JSValue value, PutPropertySlot& slot)
1223 {
1224     VM& vm = exec->vm();
1225     auto scope = DECLARE_THROW_SCOPE(vm);
1226     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(cell);
1227     ASSERT(!Heap::heap(value) || Heap::heap(value) == Heap::heap(thisObject));
1228
1229     if (UNLIKELY(isThisValueAltered(slot, thisObject)))
1230         RELEASE_AND_RETURN(scope, ordinarySetSlow(exec, thisObject, propertyName, value, slot.thisValue(), slot.isStrictMode()));
1231
1232     bool shouldThrowReadOnlyError = slot.isStrictMode();
1233     bool ignoreReadOnlyErrors = false;
1234     bool putResult = false;
1235     bool done = symbolTablePutTouchWatchpointSet(thisObject, exec, propertyName, value, shouldThrowReadOnlyError, ignoreReadOnlyErrors, putResult);
1236     EXCEPTION_ASSERT((!!scope.exception() == (done && !putResult)) || !shouldThrowReadOnlyError);
1237     if (done)
1238         return putResult;
1239     RELEASE_AND_RETURN(scope, Base::put(thisObject, exec, propertyName, value, slot));
1240 }
1241
1242 bool JSGlobalObject::defineOwnProperty(JSObject* object, ExecState* exec, PropertyName propertyName, const PropertyDescriptor& descriptor, bool shouldThrow)
1243 {
1244     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(object);
1245     PropertySlot slot(thisObject, PropertySlot::InternalMethodType::VMInquiry);
1246     // silently ignore attempts to add accessors aliasing vars.
1247     if (descriptor.isAccessorDescriptor() && symbolTableGet(thisObject, propertyName, slot))
1248         return false;
1249     return Base::defineOwnProperty(thisObject, exec, propertyName, descriptor, shouldThrow);
1250 }
1251
1252 void JSGlobalObject::addGlobalVar(const Identifier& ident)
1253 {
1254     ConcurrentJSLocker locker(symbolTable()->m_lock);
1255     SymbolTableEntry entry = symbolTable()->get(locker, ident.impl());
1256     if (!entry.isNull())
1257         return;
1258     
1259     ScopeOffset offset = symbolTable()->takeNextScopeOffset(locker);
1260     SymbolTableEntry newEntry(VarOffset(offset), 0);
1261     newEntry.prepareToWatch();
1262     symbolTable()->add(locker, ident.impl(), WTFMove(newEntry));
1263     
1264     ScopeOffset offsetForAssert = addVariables(1, jsUndefined());
1265     RELEASE_ASSERT(offsetForAssert == offset);
1266 }
1267
1268 void JSGlobalObject::addFunction(ExecState* exec, const Identifier& propertyName)
1269 {
1270     VM& vm = exec->vm();
1271     VM::DeletePropertyModeScope scope(vm, VM::DeletePropertyMode::IgnoreConfigurable);
1272     methodTable(vm)->deleteProperty(this, exec, propertyName);
1273     addGlobalVar(propertyName);
1274 }
1275
1276 void JSGlobalObject::setGlobalScopeExtension(JSScope* scope)
1277 {
1278     m_globalScopeExtension.set(vm(), this, scope);
1279 }
1280
1281 void JSGlobalObject::clearGlobalScopeExtension()
1282 {
1283     m_globalScopeExtension.clear();
1284 }
1285
1286 static inline JSObject* lastInPrototypeChain(VM& vm, JSObject* object)
1287 {
1288     JSObject* o = object;
1289     while (o->getPrototypeDirect(vm).isObject())
1290         o = asObject(o->getPrototypeDirect(vm));
1291     return o;
1292 }
1293
1294 // Private namespace for helpers for JSGlobalObject::haveABadTime()
1295 namespace {
1296
1297 class GlobalObjectDependencyFinder : public MarkedBlock::VoidFunctor {
1298 public:
1299     GlobalObjectDependencyFinder(VM& vm)
1300         : m_vm(vm)
1301     { }
1302
1303     IterationStatus operator()(HeapCell*, HeapCell::Kind) const;
1304
1305     void addDependency(JSGlobalObject* key, JSGlobalObject* dependent);
1306     HashSet<JSGlobalObject*>* dependentsFor(JSGlobalObject* key);
1307
1308 private:
1309     void visit(JSObject*);
1310
1311     VM& m_vm;
1312     HashMap<JSGlobalObject*, HashSet<JSGlobalObject*>> m_dependencies;
1313 };
1314
1315 inline void GlobalObjectDependencyFinder::addDependency(JSGlobalObject* key, JSGlobalObject* dependent)
1316 {
1317     auto keyResult = m_dependencies.add(key, HashSet<JSGlobalObject*>());
1318     keyResult.iterator->value.add(dependent);
1319 }
1320
1321 inline HashSet<JSGlobalObject*>* GlobalObjectDependencyFinder::dependentsFor(JSGlobalObject* key)
1322 {
1323     auto iterator = m_dependencies.find(key);
1324     if (iterator == m_dependencies.end())
1325         return nullptr;
1326     return &iterator->value;
1327 }
1328
1329 inline void GlobalObjectDependencyFinder::visit(JSObject* object)
1330 {
1331     VM& vm = m_vm;
1332
1333     if (!object->mayBePrototype())
1334         return;
1335
1336     JSObject* current = object;
1337     JSGlobalObject* objectGlobalObject = object->globalObject(vm);
1338     do {
1339         JSValue prototypeValue = current->getPrototypeDirect(vm);
1340         if (prototypeValue.isNull())
1341             return;
1342         current = asObject(prototypeValue);
1343
1344         JSGlobalObject* protoGlobalObject = current->globalObject(vm);
1345         if (protoGlobalObject != objectGlobalObject)
1346             addDependency(protoGlobalObject, objectGlobalObject);
1347     } while (true);
1348 }
1349
1350 IterationStatus GlobalObjectDependencyFinder::operator()(HeapCell* cell, HeapCell::Kind kind) const
1351 {
1352     if (isJSCellKind(kind) && static_cast<JSCell*>(cell)->isObject()) {
1353         // FIXME: This const_cast exists because this isn't a C++ lambda.
1354         // https://bugs.webkit.org/show_bug.cgi?id=159644
1355         const_cast<GlobalObjectDependencyFinder*>(this)->visit(jsCast<JSObject*>(static_cast<JSCell*>(cell)));
1356     }
1357     return IterationStatus::Continue;
1358 }
1359
1360 enum class BadTimeFinderMode {
1361     SingleGlobal,
1362     MultipleGlobals
1363 };
1364
1365 template<BadTimeFinderMode mode>
1366 class ObjectsWithBrokenIndexingFinder : public MarkedBlock::VoidFunctor {
1367 public:
1368     ObjectsWithBrokenIndexingFinder(VM&, Vector<JSObject*>&, JSGlobalObject*);
1369     ObjectsWithBrokenIndexingFinder(VM&, Vector<JSObject*>&, HashSet<JSGlobalObject*>&);
1370
1371     bool needsMultiGlobalsScan() const { return m_needsMultiGlobalsScan; }
1372     IterationStatus operator()(HeapCell*, HeapCell::Kind) const;
1373
1374 private:
1375     IterationStatus visit(JSObject*);
1376
1377     VM& m_vm;
1378     Vector<JSObject*>& m_foundObjects;
1379     JSGlobalObject* m_globalObject { nullptr }; // Only used for SingleBadTimeGlobal mode.
1380     HashSet<JSGlobalObject*>* m_globalObjects { nullptr }; // Only used for BadTimeGlobalGraph mode;
1381     bool m_needsMultiGlobalsScan { false };
1382 };
1383
1384 template<>
1385 ObjectsWithBrokenIndexingFinder<BadTimeFinderMode::SingleGlobal>::ObjectsWithBrokenIndexingFinder(
1386     VM& vm, Vector<JSObject*>& foundObjects, JSGlobalObject* globalObject)
1387     : m_vm(vm)
1388     , m_foundObjects(foundObjects)
1389     , m_globalObject(globalObject)
1390 {
1391 }
1392
1393 template<>
1394 ObjectsWithBrokenIndexingFinder<BadTimeFinderMode::MultipleGlobals>::ObjectsWithBrokenIndexingFinder(
1395     VM& vm, Vector<JSObject*>& foundObjects, HashSet<JSGlobalObject*>& globalObjects)
1396     : m_vm(vm)
1397     , m_foundObjects(foundObjects)
1398     , m_globalObjects(&globalObjects)
1399 {
1400 }
1401
1402 inline bool hasBrokenIndexing(IndexingType type)
1403 {
1404     return type && !hasSlowPutArrayStorage(type);
1405 }
1406
1407 inline bool hasBrokenIndexing(JSObject* object)
1408 {
1409     IndexingType type = object->indexingType();
1410     return hasBrokenIndexing(type);
1411 }
1412
1413 template<BadTimeFinderMode mode>
1414 inline IterationStatus ObjectsWithBrokenIndexingFinder<mode>::visit(JSObject* object)
1415 {
1416     VM& vm = m_vm;
1417
1418     // We only want to have a bad time in the affected global object, not in the entire
1419     // VM. But we have to be careful, since there may be objects that claim to belong to
1420     // a different global object that have prototypes from our global object.
1421     auto isInAffectedGlobalObject = [&] (JSObject* object) {
1422         JSGlobalObject* objectGlobalObject { nullptr };
1423         bool objectMayBePrototype { false };
1424
1425         if (mode == BadTimeFinderMode::SingleGlobal) {
1426             objectGlobalObject = object->globalObject(vm);
1427             if (objectGlobalObject == m_globalObject)
1428                 return true;
1429
1430             objectMayBePrototype = object->mayBePrototype();
1431         }
1432
1433         for (JSObject* current = object; ;) {
1434             JSGlobalObject* currentGlobalObject = current->globalObject(vm);
1435             if (mode == BadTimeFinderMode::SingleGlobal) {
1436                 if (objectMayBePrototype && currentGlobalObject != objectGlobalObject)
1437                     m_needsMultiGlobalsScan = true;
1438                 if (currentGlobalObject == m_globalObject)
1439                     return true;
1440             } else {
1441                 if (m_globalObjects->contains(currentGlobalObject))
1442                     return true;
1443             }
1444
1445             JSValue prototypeValue = current->getPrototypeDirect(vm);
1446             if (prototypeValue.isNull())
1447                 return false;
1448             current = asObject(prototypeValue);
1449         }
1450         RELEASE_ASSERT_NOT_REACHED();
1451     };
1452
1453     if (JSFunction* function = jsDynamicCast<JSFunction*>(vm, object)) {
1454         if (FunctionRareData* rareData = function->rareData()) {
1455             // We only use this to cache JSFinalObjects. They do not start off with a broken indexing type.
1456             ASSERT(!(rareData->objectAllocationStructure() && hasBrokenIndexing(rareData->objectAllocationStructure()->indexingType())));
1457
1458             if (Structure* structure = rareData->internalFunctionAllocationStructure()) {
1459                 if (hasBrokenIndexing(structure->indexingType())) {
1460                     bool isRelevantGlobalObject =
1461                         (mode == BadTimeFinderMode::SingleGlobal
1462                             ? m_globalObject == structure->globalObject()
1463                             : m_globalObjects->contains(structure->globalObject()))
1464                         || (structure->hasMonoProto() && !structure->storedPrototype().isNull() && isInAffectedGlobalObject(asObject(structure->storedPrototype())));
1465                     if (mode == BadTimeFinderMode::SingleGlobal && m_needsMultiGlobalsScan)
1466                         return IterationStatus::Done; // Bailing early and let the MultipleGlobals path handle everything.
1467                     if (isRelevantGlobalObject)
1468                         rareData->clearInternalFunctionAllocationProfile("have a bad time breaking internal function allocation");
1469                 }
1470             }
1471         }
1472     }
1473
1474     // Run this filter first, since it's cheap, and ought to filter out a lot of objects.
1475     if (!hasBrokenIndexing(object))
1476         return IterationStatus::Continue;
1477
1478     if (isInAffectedGlobalObject(object))
1479         m_foundObjects.append(object);
1480
1481     if (mode == BadTimeFinderMode::SingleGlobal && m_needsMultiGlobalsScan)
1482         return IterationStatus::Done; // Bailing early and let the MultipleGlobals path handle everything.
1483
1484     return IterationStatus::Continue;
1485 }
1486
1487 template<BadTimeFinderMode mode>
1488 IterationStatus ObjectsWithBrokenIndexingFinder<mode>::operator()(HeapCell* cell, HeapCell::Kind kind) const
1489 {
1490     if (isJSCellKind(kind) && static_cast<JSCell*>(cell)->isObject()) {
1491         // FIXME: This const_cast exists because this isn't a C++ lambda.
1492         // https://bugs.webkit.org/show_bug.cgi?id=159644
1493         return const_cast<ObjectsWithBrokenIndexingFinder*>(this)->visit(jsCast<JSObject*>(static_cast<JSCell*>(cell)));
1494     }
1495     return IterationStatus::Continue;
1496 }
1497
1498 } // end private namespace for helpers for JSGlobalObject::haveABadTime()
1499
1500 void JSGlobalObject::fireWatchpointAndMakeAllArrayStructuresSlowPut(VM& vm)
1501 {
1502     if (isHavingABadTime())
1503         return;
1504
1505     // Make sure that all allocations or indexed storage transitions that are inlining
1506     // the assumption that it's safe to transition to a non-SlowPut array storage don't
1507     // do so anymore.
1508     m_havingABadTimeWatchpoint->fireAll(vm, "Having a bad time");
1509     ASSERT(isHavingABadTime()); // The watchpoint is what tells us that we're having a bad time.
1510     
1511     // Make sure that all JSArray allocations that load the appropriate structure from
1512     // this object now load a structure that uses SlowPut.
1513     for (unsigned i = 0; i < NumberOfArrayIndexingModes; ++i)
1514         m_arrayStructureForIndexingShapeDuringAllocation[i].set(vm, this, originalArrayStructureForIndexingType(ArrayWithSlowPutArrayStorage));
1515
1516     // Same for any special array structures.
1517     Structure* slowPutStructure;
1518     slowPutStructure = createRegExpMatchesArraySlowPutStructure(vm, this);
1519     m_regExpMatchesArrayStructure.set(vm, this, slowPutStructure);
1520     slowPutStructure = createRegExpMatchesArrayWithGroupsSlowPutStructure(vm, this);
1521     m_regExpMatchesArrayWithGroupsStructure.set(vm, this, slowPutStructure);
1522     slowPutStructure = ClonedArguments::createSlowPutStructure(vm, this, m_objectPrototype.get());
1523     m_clonedArgumentsStructure.set(vm, this, slowPutStructure);
1524 };
1525
1526 void JSGlobalObject::haveABadTime(VM& vm)
1527 {
1528     ASSERT(&vm == &this->vm());
1529     
1530     if (isHavingABadTime())
1531         return;
1532
1533     vm.structureCache.clear(); // We may be caching array structures in here.
1534
1535     DeferGC deferGC(vm.heap);
1536
1537     // Consider the following objects and prototype chains:
1538     //    O (of global G1) -> A (of global G1)
1539     //    B (of global G2) where G2 has a bad time
1540     //
1541     // If we set B as the prototype of A, G1 will need to have a bad time.
1542     // See comments in Structure::mayInterceptIndexedAccesses() for why.
1543     //
1544     // Now, consider the following objects and prototype chains:
1545     //    O1 (of global G1) -> A1 (of global G1) -> B1 (of global G2)
1546     //    O2 (of global G2) -> A2 (of global G2)
1547     //    B2 (of global G3) where G3 has a bad time.
1548     //
1549     // G1 and G2 does not have a bad time, but G3 already has a bad time.
1550     // If we set B2 as the prototype of A2, then G2 needs to have a bad time.
1551     // Note that by induction, G1 also now needs to have a bad time because of
1552     // O1 -> A1 -> B1.
1553     //
1554     // We describe this as global G1 being affected by global G2, and G2 by G3.
1555     // Similarly, we say that G1 is dependent on G2, and G2 on G3.
1556     // Hence, when G3 has a bad time, we need to ensure that all globals that
1557     // are transitively dependent on it also have a bad time (G2 and G1 in this
1558     // example).
1559     //
1560     // Apart from clearing the VM structure cache above, there are 2 more things
1561     // that we have to do when globals have a bad time:
1562     // 1. For each affected global:
1563     //    a. Fire its HaveABadTime watchpoint.
1564     //    b. Convert all of its array structures to SlowPutArrayStorage.
1565     // 2. Make sure that all affected objects  switch to the slow kind of
1566     //    indexed storage. An object is considered to be affected if it has
1567     //    indexed storage and has a prototype object which may have indexed
1568     //    accessors. If the prototype object belongs to a global having a bad
1569     //    time, then the prototype object is considered to possibly have indexed
1570     //    accessors. See comments in Structure::mayInterceptIndexedAccesses()
1571     //    for details.
1572     //
1573     // Note: step 1 must be completed before step 2 because step 2 relies on
1574     // the HaveABadTime watchpoint having already been fired on all affected
1575     // globals.
1576     //
1577     // In the common case, only this global will start having a bad time here,
1578     // and no other globals are affected by it. So, we first proceed on this assumption
1579     // with a simpler ObjectsWithBrokenIndexingFinder scan to find heap objects
1580     // affected by this global that need to be converted to SlowPutArrayStorage.
1581     // We'll also have the finder check for the presence of other global objects
1582     // depending on this one.
1583     //
1584     // If we do discover other globals depending on this one, we'll abort this
1585     // first ObjectsWithBrokenIndexingFinder scan because it will be insufficient
1586     // to find all affected objects that need to be converted to SlowPutArrayStorage.
1587     // It also does not make dependent globals have a bad time. Instead, we'll
1588     // take a more comprehensive approach of first creating a dependency graph
1589     // between globals, and then using that graph to determine all affected
1590     // globals and objects. With that, we can make all affected globals have a
1591     // bad time, and convert all affected objects to SlowPutArrayStorage.
1592
1593     fireWatchpointAndMakeAllArrayStructuresSlowPut(vm); // Step 1 above.
1594     
1595     Vector<JSObject*> foundObjects;
1596     ObjectsWithBrokenIndexingFinder<BadTimeFinderMode::SingleGlobal> finder(vm, foundObjects, this);
1597     {
1598         HeapIterationScope iterationScope(vm.heap);
1599         vm.heap.objectSpace().forEachLiveCell(iterationScope, finder); // Attempt step 2 above.
1600     }
1601
1602     if (finder.needsMultiGlobalsScan()) {
1603         foundObjects.clear();
1604
1605         // Find all globals that will also have a bad time as a side effect of
1606         // this global having a bad time.
1607         GlobalObjectDependencyFinder dependencies(vm);
1608         {
1609             HeapIterationScope iterationScope(vm.heap);
1610             vm.heap.objectSpace().forEachLiveCell(iterationScope, dependencies);
1611         }
1612
1613         HashSet<JSGlobalObject*> globalsHavingABadTime;
1614         Deque<JSGlobalObject*> globals;
1615
1616         globals.append(this);
1617         while (!globals.isEmpty()) {
1618             JSGlobalObject* global = globals.takeFirst();
1619             global->fireWatchpointAndMakeAllArrayStructuresSlowPut(vm); // Step 1 above.
1620             auto result = globalsHavingABadTime.add(global);
1621             if (result.isNewEntry) {
1622                 if (HashSet<JSGlobalObject*>* dependents = dependencies.dependentsFor(global)) {
1623                     for (JSGlobalObject* dependentGlobal : *dependents)
1624                         globals.append(dependentGlobal);
1625                 }
1626             }
1627         }
1628
1629         ObjectsWithBrokenIndexingFinder<BadTimeFinderMode::MultipleGlobals> finder(vm, foundObjects, globalsHavingABadTime);
1630         {
1631             HeapIterationScope iterationScope(vm.heap);
1632             vm.heap.objectSpace().forEachLiveCell(iterationScope, finder); // Step 2 above.
1633         }
1634     }
1635
1636     while (!foundObjects.isEmpty()) {
1637         JSObject* object = asObject(foundObjects.last());
1638         foundObjects.removeLast();
1639         ASSERT(hasBrokenIndexing(object));
1640         object->switchToSlowPutArrayStorage(vm);
1641     }
1642 }
1643
1644 void JSGlobalObject::fixupPrototypeChainWithObjectPrototype(VM& vm)
1645 {
1646     JSObject* oldLastInPrototypeChain = lastInPrototypeChain(vm, this);
1647     JSObject* objectPrototype = m_objectPrototype.get();
1648     if (oldLastInPrototypeChain != objectPrototype)
1649         oldLastInPrototypeChain->setPrototypeDirect(vm, objectPrototype);
1650 }
1651
1652 // Set prototype, and also insert the object prototype at the end of the chain.
1653 void JSGlobalObject::resetPrototype(VM& vm, JSValue prototype)
1654 {
1655     if (getPrototypeDirect(vm) == prototype)
1656         return;
1657     setPrototypeDirect(vm, prototype);
1658     fixupPrototypeChainWithObjectPrototype(vm);
1659     // Whenever we change the prototype of the global object, we need to create a new JSProxy with the correct prototype.
1660     setGlobalThis(vm, JSNonDestructibleProxy::create(vm, JSNonDestructibleProxy::createStructure(vm, this, prototype, PureForwardingProxyType), this));
1661 }
1662
1663 void JSGlobalObject::visitChildren(JSCell* cell, SlotVisitor& visitor)
1664
1665     JSGlobalObject* thisObject = jsCast<JSGlobalObject*>(cell);
1666     ASSERT_GC_OBJECT_INHERITS(thisObject, info());
1667     Base::visitChildren(thisObject, visitor);
1668
1669     visitor.append(thisObject->m_globalThis);
1670
1671     visitor.append(thisObject->m_globalLexicalEnvironment);
1672     visitor.append(thisObject->m_globalScopeExtension);
1673     visitor.append(thisObject->m_globalCallee);
1674     visitor.append(thisObject->m_stackOverflowFrameCallee);
1675     thisObject->m_evalErrorStructure.visit(visitor);
1676     thisObject->m_rangeErrorStructure.visit(visitor);
1677     thisObject->m_referenceErrorStructure.visit(visitor);
1678     thisObject->m_syntaxErrorStructure.visit(visitor);
1679     thisObject->m_typeErrorStructure.visit(visitor);
1680     thisObject->m_URIErrorStructure.visit(visitor);
1681     visitor.append(thisObject->m_objectConstructor);
1682     visitor.append(thisObject->m_promiseConstructor);
1683     visitor.append(thisObject->m_internalPromiseConstructor);
1684
1685 #if ENABLE(INTL)
1686     visitor.append(thisObject->m_defaultCollator);
1687     thisObject->m_collatorStructure.visit(visitor);
1688     thisObject->m_numberFormatStructure.visit(visitor);
1689     thisObject->m_dateTimeFormatStructure.visit(visitor);
1690     thisObject->m_pluralRulesStructure.visit(visitor);
1691 #endif
1692     visitor.append(thisObject->m_nullGetterFunction);
1693     visitor.append(thisObject->m_nullSetterFunction);
1694
1695     thisObject->m_parseIntFunction.visit(visitor);
1696     thisObject->m_parseFloatFunction.visit(visitor);
1697     visitor.append(thisObject->m_callFunction);
1698     visitor.append(thisObject->m_applyFunction);
1699     visitor.append(thisObject->m_throwTypeErrorFunction);
1700     thisObject->m_arrayProtoToStringFunction.visit(visitor);
1701     thisObject->m_arrayProtoValuesFunction.visit(visitor);
1702     thisObject->m_evalFunction.visit(visitor);
1703     thisObject->m_iteratorProtocolFunction.visit(visitor);
1704     thisObject->m_promiseResolveFunction.visit(visitor);
1705     visitor.append(thisObject->m_promiseProtoThenFunction);
1706     visitor.append(thisObject->m_objectProtoValueOfFunction);
1707     visitor.append(thisObject->m_numberProtoToStringFunction);
1708     visitor.append(thisObject->m_newPromiseCapabilityFunction);
1709     visitor.append(thisObject->m_functionProtoHasInstanceSymbolFunction);
1710     thisObject->m_throwTypeErrorGetterSetter.visit(visitor);
1711     visitor.append(thisObject->m_throwTypeErrorArgumentsCalleeAndCallerGetterSetter);
1712     thisObject->m_moduleLoader.visit(visitor);
1713
1714     visitor.append(thisObject->m_objectPrototype);
1715     visitor.append(thisObject->m_functionPrototype);
1716     visitor.append(thisObject->m_arrayPrototype);
1717     visitor.append(thisObject->m_iteratorPrototype);
1718     visitor.append(thisObject->m_generatorFunctionPrototype);
1719     visitor.append(thisObject->m_generatorPrototype);
1720     visitor.append(thisObject->m_asyncFunctionPrototype);
1721     visitor.append(thisObject->m_asyncGeneratorPrototype);
1722     visitor.append(thisObject->m_asyncIteratorPrototype);
1723     visitor.append(thisObject->m_asyncGeneratorFunctionPrototype);
1724
1725     thisObject->m_debuggerScopeStructure.visit(visitor);
1726     thisObject->m_withScopeStructure.visit(visitor);
1727     thisObject->m_strictEvalActivationStructure.visit(visitor);
1728     visitor.append(thisObject->m_lexicalEnvironmentStructure);
1729     thisObject->m_moduleEnvironmentStructure.visit(visitor);
1730     visitor.append(thisObject->m_directArgumentsStructure);
1731     visitor.append(thisObject->m_scopedArgumentsStructure);
1732     visitor.append(thisObject->m_clonedArgumentsStructure);
1733     visitor.append(thisObject->m_objectStructureForObjectConstructor);
1734     for (unsigned i = 0; i < NumberOfArrayIndexingModes; ++i)
1735         visitor.append(thisObject->m_originalArrayStructureForIndexingShape[i]);
1736     for (unsigned i = 0; i < NumberOfArrayIndexingModes; ++i)
1737         visitor.append(thisObject->m_arrayStructureForIndexingShapeDuringAllocation[i]);
1738     thisObject->m_callbackConstructorStructure.visit(visitor);
1739     thisObject->m_callbackFunctionStructure.visit(visitor);
1740     thisObject->m_callbackObjectStructure.visit(visitor);
1741 #if JSC_OBJC_API_ENABLED
1742     thisObject->m_objcCallbackFunctionStructure.visit(visitor);
1743     thisObject->m_objcWrapperObjectStructure.visit(visitor);
1744 #endif
1745 #ifdef JSC_GLIB_API_ENABLED
1746     thisObject->m_glibCallbackFunctionStructure.visit(visitor);
1747     thisObject->m_glibWrapperObjectStructure.visit(visitor);
1748 #endif
1749     visitor.append(thisObject->m_nullPrototypeObjectStructure);
1750     visitor.append(thisObject->m_calleeStructure);
1751
1752     visitor.append(thisObject->m_hostFunctionStructure);
1753     auto visitFunctionStructures = [&] (FunctionStructures& structures) {
1754         visitor.append(structures.arrowFunctionStructure);
1755         visitor.append(structures.sloppyFunctionStructure);
1756         visitor.append(structures.strictFunctionStructure);
1757     };
1758     visitFunctionStructures(thisObject->m_builtinFunctions);
1759     visitFunctionStructures(thisObject->m_ordinaryFunctions);
1760
1761     thisObject->m_customGetterSetterFunctionStructure.visit(visitor);
1762     thisObject->m_boundFunctionStructure.visit(visitor);
1763     visitor.append(thisObject->m_getterSetterStructure);
1764     thisObject->m_nativeStdFunctionStructure.visit(visitor);
1765     visitor.append(thisObject->m_regExpStructure);
1766     visitor.append(thisObject->m_generatorFunctionStructure);
1767     visitor.append(thisObject->m_asyncFunctionStructure);
1768     visitor.append(thisObject->m_asyncGeneratorFunctionStructure);
1769     visitor.append(thisObject->m_generatorStructure);
1770     visitor.append(thisObject->m_asyncGeneratorStructure);
1771     thisObject->m_iteratorResultObjectStructure.visit(visitor);
1772     visitor.append(thisObject->m_regExpMatchesArrayStructure);
1773     visitor.append(thisObject->m_regExpMatchesArrayWithGroupsStructure);
1774     thisObject->m_moduleRecordStructure.visit(visitor);
1775     thisObject->m_moduleNamespaceObjectStructure.visit(visitor);
1776     thisObject->m_proxyObjectStructure.visit(visitor);
1777     thisObject->m_callableProxyObjectStructure.visit(visitor);
1778     thisObject->m_proxyRevokeStructure.visit(visitor);
1779     
1780 #if ENABLE(SHARED_ARRAY_BUFFER)
1781     visitor.append(thisObject->m_sharedArrayBufferPrototype);
1782     visitor.append(thisObject->m_sharedArrayBufferStructure);
1783 #endif
1784
1785 #define VISIT_SIMPLE_TYPE(CapitalName, lowerName, properName, instanceType, jsName, prototypeBase, featureFlag) if (featureFlag) { \
1786         visitor.append(thisObject->m_ ## lowerName ## Prototype); \
1787         visitor.append(thisObject->m_ ## properName ## Structure); \
1788     }
1789
1790     FOR_EACH_SIMPLE_BUILTIN_TYPE(VISIT_SIMPLE_TYPE)
1791     FOR_EACH_BUILTIN_DERIVED_ITERATOR_TYPE(VISIT_SIMPLE_TYPE)
1792
1793 #define VISIT_LAZY_TYPE(CapitalName, lowerName, properName, instanceType, jsName, prototypeBase, featureFlag) if (featureFlag) \
1794         thisObject->m_ ## properName ## Structure.visit(visitor);
1795
1796     FOR_EACH_LAZY_BUILTIN_TYPE(VISIT_LAZY_TYPE)
1797
1798 #if ENABLE(WEBASSEMBLY)
1799     thisObject->m_webAssemblyModuleRecordStructure.visit(visitor);
1800     thisObject->m_webAssemblyFunctionStructure.visit(visitor);
1801     thisObject->m_jsToWasmICCalleeStructure.visit(visitor);
1802     thisObject->m_webAssemblyWrapperFunctionStructure.visit(visitor);
1803     thisObject->m_webAssemblyToJSCalleeStructure.visit(visitor);
1804     FOR_EACH_WEBASSEMBLY_CONSTRUCTOR_TYPE(VISIT_LAZY_TYPE)
1805 #endif // ENABLE(WEBASSEMBLY)
1806
1807 #undef VISIT_SIMPLE_TYPE
1808 #undef VISIT_LAZY_TYPE
1809
1810     for (unsigned i = NumberOfTypedArrayTypes; i--;)
1811         thisObject->lazyTypedArrayStructure(indexToTypedArrayType(i)).visit(visitor);
1812     
1813     visitor.append(thisObject->m_speciesGetterSetter);
1814     thisObject->m_typedArrayProto.visit(visitor);
1815     thisObject->m_typedArraySuperConstructor.visit(visitor);
1816     thisObject->m_regExpGlobalData.visitAggregate(visitor);
1817 }
1818
1819 ExecState* JSGlobalObject::globalExec()
1820 {
1821     return CallFrame::create(m_globalCallFrame);
1822 }
1823
1824 void JSGlobalObject::exposeDollarVM(VM& vm)
1825 {
1826     RELEASE_ASSERT(g_jscConfig.restrictedOptionsEnabled && Options::useDollarVM());
1827     if (hasOwnProperty(globalExec(), vm.propertyNames->builtinNames().dollarVMPrivateName()))
1828         return;
1829
1830     JSDollarVM* dollarVM = JSDollarVM::create(vm, JSDollarVM::createStructure(vm, this, m_objectPrototype.get()));
1831
1832     GlobalPropertyInfo extraStaticGlobals[] = {
1833         GlobalPropertyInfo(vm.propertyNames->builtinNames().dollarVMPrivateName(), dollarVM, PropertyAttribute::DontEnum | PropertyAttribute::DontDelete | PropertyAttribute::ReadOnly),
1834     };
1835     addStaticGlobals(extraStaticGlobals, WTF_ARRAY_LENGTH(extraStaticGlobals));
1836
1837     putDirect(vm, Identifier::fromString(vm, "$vm"), dollarVM, static_cast<unsigned>(PropertyAttribute::DontEnum));
1838 }
1839
1840 void JSGlobalObject::addStaticGlobals(GlobalPropertyInfo* globals, int count)
1841 {
1842     ScopeOffset startOffset = addVariables(count, jsUndefined());
1843
1844     for (int i = 0; i < count; ++i) {
1845         GlobalPropertyInfo& global = globals[i];
1846         // This `configurable = false` is necessary condition for static globals,
1847         // otherwise lexical bindings can change the result of GlobalVar queries too.
1848         // We won't be able to declare a global lexical variable with the sanem name to
1849         // the static globals because configurable = false.
1850         ASSERT(global.attributes & PropertyAttribute::DontDelete);
1851         
1852         WatchpointSet* watchpointSet = nullptr;
1853         WriteBarrierBase<Unknown>* variable = nullptr;
1854         {
1855             ConcurrentJSLocker locker(symbolTable()->m_lock);
1856             ScopeOffset offset = symbolTable()->takeNextScopeOffset(locker);
1857             RELEASE_ASSERT(offset == startOffset + i);
1858             SymbolTableEntry newEntry(VarOffset(offset), global.attributes);
1859             newEntry.prepareToWatch();
1860             watchpointSet = newEntry.watchpointSet();
1861             symbolTable()->add(locker, global.identifier.impl(), WTFMove(newEntry));
1862             variable = &variableAt(offset);
1863         }
1864         symbolTablePutTouchWatchpointSet(vm(), this, global.identifier, global.value, variable, watchpointSet);
1865     }
1866 }
1867
1868 bool JSGlobalObject::getOwnPropertySlot(JSObject* object, ExecState* exec, PropertyName propertyName, PropertySlot& slot)
1869 {
1870     if (Base::getOwnPropertySlot(object, exec, propertyName, slot))
1871         return true;
1872     return symbolTableGet(jsCast<JSGlobalObject*>(object), propertyName, slot);
1873 }
1874
1875 void JSGlobalObject::clearRareData(JSCell* cell)
1876 {
1877     jsCast<JSGlobalObject*>(cell)->m_rareData = nullptr;
1878 }
1879
1880 void JSGlobalObject::tryInstallArraySpeciesWatchpoint(ExecState* exec)
1881 {
1882     RELEASE_ASSERT(!m_arrayPrototypeConstructorWatchpoint);
1883     RELEASE_ASSERT(!m_arrayConstructorSpeciesWatchpoint);
1884
1885     VM& vm = exec->vm();
1886     auto scope = DECLARE_THROW_SCOPE(vm);
1887
1888     // First we need to make sure that the Array.prototype.constructor property points to Array
1889     // and that Array[Symbol.species] is the primordial GetterSetter.
1890     ArrayPrototype* arrayPrototype = this->arrayPrototype();
1891
1892     // We only initialize once so flattening the structures does not have any real cost.
1893     Structure* prototypeStructure = arrayPrototype->structure(vm);
1894     if (prototypeStructure->isDictionary())
1895         prototypeStructure = prototypeStructure->flattenDictionaryStructure(vm, arrayPrototype);
1896     RELEASE_ASSERT(!prototypeStructure->isDictionary());
1897
1898     ArrayConstructor* arrayConstructor = this->arrayConstructor();
1899
1900     auto invalidateWatchpoint = [&] {
1901         m_arraySpeciesWatchpointSet.invalidate(vm, StringFireDetail("Was not able to set up array species watchpoint."));
1902     };
1903
1904     PropertySlot constructorSlot(arrayPrototype, PropertySlot::InternalMethodType::VMInquiry);
1905     arrayPrototype->getOwnPropertySlot(arrayPrototype, exec, vm.propertyNames->constructor, constructorSlot);
1906     scope.assertNoException();
1907     if (constructorSlot.slotBase() != arrayPrototype
1908         || !constructorSlot.isCacheableValue()
1909         || constructorSlot.getValue(exec, vm.propertyNames->constructor) != arrayConstructor) {
1910         invalidateWatchpoint();
1911         return;
1912     }
1913
1914     Structure* constructorStructure = arrayConstructor->structure(vm);
1915     if (constructorStructure->isDictionary())
1916         constructorStructure = constructorStructure->flattenDictionaryStructure(vm, arrayConstructor);
1917
1918     PropertySlot speciesSlot(arrayConstructor, PropertySlot::InternalMethodType::VMInquiry);
1919     arrayConstructor->getOwnPropertySlot(arrayConstructor, exec, vm.propertyNames->speciesSymbol, speciesSlot);
1920     scope.assertNoException();
1921     if (speciesSlot.slotBase() != arrayConstructor
1922         || !speciesSlot.isCacheableGetter()
1923         || speciesSlot.getterSetter() != speciesGetterSetter()) {
1924         invalidateWatchpoint();
1925         return;
1926     }
1927
1928     // Now we need to setup the watchpoints to make sure these conditions remain valid.
1929     prototypeStructure->startWatchingPropertyForReplacements(vm, constructorSlot.cachedOffset());
1930     constructorStructure->startWatchingPropertyForReplacements(vm, speciesSlot.cachedOffset());
1931
1932     ObjectPropertyCondition constructorCondition = ObjectPropertyCondition::equivalence(vm, arrayPrototype, arrayPrototype, vm.propertyNames->constructor.impl(), arrayConstructor);
1933     ObjectPropertyCondition speciesCondition = ObjectPropertyCondition::equivalence(vm, arrayPrototype, arrayConstructor, vm.propertyNames->speciesSymbol.impl(), speciesGetterSetter());
1934
1935     if (!constructorCondition.isWatchable() || !speciesCondition.isWatchable()) {
1936         invalidateWatchpoint();
1937         return;
1938     }
1939
1940     // We only watch this from the DFG, and the DFG makes sure to only start watching if the watchpoint is in the IsWatched state.
1941     RELEASE_ASSERT(!m_arraySpeciesWatchpointSet.isBeingWatched());
1942     m_arraySpeciesWatchpointSet.touch(vm, "Set up array species watchpoint.");
1943
1944     m_arrayPrototypeConstructorWatchpoint = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, constructorCondition, m_arraySpeciesWatchpointSet);
1945     m_arrayPrototypeConstructorWatchpoint->install(vm);
1946
1947     m_arrayConstructorSpeciesWatchpoint = makeUnique<ObjectPropertyChangeAdaptiveWatchpoint<InlineWatchpointSet>>(this, speciesCondition, m_arraySpeciesWatchpointSet);
1948     m_arrayConstructorSpeciesWatchpoint->install(vm);
1949 }
1950
1951 void slowValidateCell(JSGlobalObject* globalObject)
1952 {
1953     RELEASE_ASSERT(globalObject->isGlobalObject());
1954     ASSERT_GC_OBJECT_INHERITS(globalObject, JSGlobalObject::info());
1955 }
1956
1957 void JSGlobalObject::setRemoteDebuggingEnabled(bool enabled)
1958 {
1959 #if ENABLE(REMOTE_INSPECTOR)
1960     m_inspectorDebuggable->setRemoteDebuggingAllowed(enabled);
1961 #else
1962     UNUSED_PARAM(enabled);
1963 #endif
1964 }
1965
1966 bool JSGlobalObject::remoteDebuggingEnabled() const
1967 {
1968 #if ENABLE(REMOTE_INSPECTOR)
1969     return m_inspectorDebuggable->remoteDebuggingAllowed();
1970 #else
1971     return false;
1972 #endif
1973 }
1974
1975 void JSGlobalObject::setName(const String& name)
1976 {
1977     m_name = name;
1978
1979 #if ENABLE(REMOTE_INSPECTOR)
1980     m_inspectorDebuggable->update();
1981 #endif
1982 }
1983
1984 # if ENABLE(INTL)
1985 static void addMissingScriptLocales(HashSet<String>& availableLocales)
1986 {
1987     if (availableLocales.contains("pa-Arab-PK"))
1988         availableLocales.add("pa-PK"_s);
1989     if (availableLocales.contains("zh-Hans-CN"))
1990         availableLocales.add("zh-CN"_s);
1991     if (availableLocales.contains("zh-Hant-HK"))
1992         availableLocales.add("zh-HK"_s);
1993     if (availableLocales.contains("zh-Hans-SG"))
1994         availableLocales.add("zh-SG"_s);
1995     if (availableLocales.contains("zh-Hant-TW"))
1996         availableLocales.add("zh-TW"_s);
1997 }
1998
1999 const HashSet<String>& JSGlobalObject::intlCollatorAvailableLocales()
2000 {
2001     if (m_intlCollatorAvailableLocales.isEmpty()) {
2002         int32_t count = ucol_countAvailable();
2003         for (int32_t i = 0; i < count; ++i) {
2004             String locale = convertICULocaleToBCP47LanguageTag(ucol_getAvailable(i));
2005             if (!locale.isEmpty())
2006                 m_intlCollatorAvailableLocales.add(locale);
2007         }
2008         addMissingScriptLocales(m_intlCollatorAvailableLocales);
2009     }
2010     return m_intlCollatorAvailableLocales;
2011 }
2012
2013 const HashSet<String>& JSGlobalObject::intlDateTimeFormatAvailableLocales()
2014 {
2015     if (m_intlDateTimeFormatAvailableLocales.isEmpty()) {
2016         int32_t count = udat_countAvailable();
2017         for (int32_t i = 0; i < count; ++i) {
2018             String locale = convertICULocaleToBCP47LanguageTag(udat_getAvailable(i));
2019             if (!locale.isEmpty())
2020                 m_intlDateTimeFormatAvailableLocales.add(locale);
2021         }
2022         addMissingScriptLocales(m_intlDateTimeFormatAvailableLocales);
2023     }
2024     return m_intlDateTimeFormatAvailableLocales;
2025 }
2026
2027 const HashSet<String>& JSGlobalObject::intlNumberFormatAvailableLocales()
2028 {
2029     if (m_intlNumberFormatAvailableLocales.isEmpty()) {
2030         int32_t count = unum_countAvailable();
2031         for (int32_t i = 0; i < count; ++i) {
2032             String locale = convertICULocaleToBCP47LanguageTag(unum_getAvailable(i));
2033             if (!locale.isEmpty())
2034                 m_intlNumberFormatAvailableLocales.add(locale);
2035         }
2036         addMissingScriptLocales(m_intlNumberFormatAvailableLocales);
2037     }
2038     return m_intlNumberFormatAvailableLocales;
2039 }
2040
2041 const HashSet<String>& JSGlobalObject::intlPluralRulesAvailableLocales()
2042 {
2043     if (m_intlPluralRulesAvailableLocales.isEmpty()) {
2044         int32_t count = uloc_countAvailable();
2045         for (int32_t i = 0; i < count; ++i) {
2046             String locale = convertICULocaleToBCP47LanguageTag(uloc_getAvailable(i));
2047             if (!locale.isEmpty())
2048                 m_intlPluralRulesAvailableLocales.add(locale);
2049         }
2050         addMissingScriptLocales(m_intlPluralRulesAvailableLocales);
2051     }
2052     return m_intlPluralRulesAvailableLocales;
2053 }
2054
2055 IntlCollator* JSGlobalObject::defaultCollator(ExecState* exec)
2056 {
2057     VM& vm = exec->vm();
2058     auto scope = DECLARE_THROW_SCOPE(vm);
2059
2060     if (m_defaultCollator)
2061         return m_defaultCollator.get();
2062
2063     IntlCollator* collator = IntlCollator::create(vm, collatorStructure());
2064     collator->initializeCollator(*exec, jsUndefined(), jsUndefined());
2065     RETURN_IF_EXCEPTION(scope, nullptr);
2066     m_defaultCollator.set(vm, this, collator);
2067     return collator;
2068 }
2069
2070 #endif // ENABLE(INTL)
2071
2072 void JSGlobalObject::bumpGlobalLexicalBindingEpoch(VM& vm)
2073 {
2074     if (++m_globalLexicalBindingEpoch == Options::thresholdForGlobalLexicalBindingEpoch()) {
2075         // Since the epoch overflows, we should rewrite all the CodeBlock to adjust to the newly started generation.
2076         m_globalLexicalBindingEpoch = 1;
2077         vm.heap.codeBlockSet().iterate([&] (CodeBlock* codeBlock) {
2078             if (codeBlock->globalObject() != this)
2079                 return;
2080             codeBlock->notifyLexicalBindingUpdate();
2081         });
2082     }
2083 }
2084
2085 void JSGlobalObject::queueMicrotask(Ref<Microtask>&& task)
2086 {
2087     if (globalObjectMethodTable()->queueTaskToEventLoop) {
2088         globalObjectMethodTable()->queueTaskToEventLoop(*this, WTFMove(task));
2089         return;
2090     }
2091
2092     vm().queueMicrotask(*this, WTFMove(task));
2093 }
2094
2095 void JSGlobalObject::setDebugger(Debugger* debugger)
2096 {
2097     m_debugger = debugger;
2098     if (debugger)
2099         vm().ensureShadowChicken();
2100 }
2101
2102 bool JSGlobalObject::hasDebugger() const
2103
2104     return m_debugger;
2105 }
2106
2107 bool JSGlobalObject::hasInteractiveDebugger() const 
2108
2109     return m_debugger && m_debugger->isInteractivelyDebugging();
2110 }
2111
2112 #if ENABLE(DFG_JIT)
2113 WatchpointSet* JSGlobalObject::getReferencedPropertyWatchpointSet(UniquedStringImpl* uid)
2114 {
2115     ConcurrentJSLocker locker(m_referencedGlobalPropertyWatchpointSetsLock);
2116     return m_referencedGlobalPropertyWatchpointSets.get(uid);
2117 }
2118
2119 WatchpointSet& JSGlobalObject::ensureReferencedPropertyWatchpointSet(UniquedStringImpl* uid)
2120 {
2121     ConcurrentJSLocker locker(m_referencedGlobalPropertyWatchpointSetsLock);
2122     return m_referencedGlobalPropertyWatchpointSets.ensure(uid, [] {
2123         return WatchpointSet::create(IsWatched);
2124     }).iterator->value.get();
2125 }
2126 #endif
2127
2128 JSGlobalObject* JSGlobalObject::create(VM& vm, Structure* structure)
2129 {
2130     JSGlobalObject* globalObject = new (NotNull, allocateCell<JSGlobalObject>(vm.heap)) JSGlobalObject(vm, structure);
2131     globalObject->finishCreation(vm);
2132     return globalObject;
2133 }
2134
2135 void JSGlobalObject::finishCreation(VM& vm)
2136 {
2137     Base::finishCreation(vm);
2138     structure(vm)->setGlobalObject(vm, this);
2139     m_runtimeFlags = m_globalObjectMethodTable->javaScriptRuntimeFlags(this);
2140     init(vm);
2141     setGlobalThis(vm, JSNonDestructibleProxy::create(vm, JSNonDestructibleProxy::createStructure(vm, this, getPrototypeDirect(vm), PureForwardingProxyType), this));
2142     ASSERT(type() == GlobalObjectType);
2143 }
2144
2145 void JSGlobalObject::finishCreation(VM& vm, JSObject* thisValue)
2146 {
2147     Base::finishCreation(vm);
2148     structure(vm)->setGlobalObject(vm, this);
2149     m_runtimeFlags = m_globalObjectMethodTable->javaScriptRuntimeFlags(this);
2150     init(vm);
2151     setGlobalThis(vm, thisValue);
2152     ASSERT(type() == GlobalObjectType);
2153 }
2154
2155 #ifdef JSC_GLIB_API_ENABLED
2156 void JSGlobalObject::setWrapperMap(std::unique_ptr<WrapperMap>&& map)
2157 {
2158     m_wrapperMap = WTFMove(map);
2159 }
2160 #endif
2161
2162 } // namespace JSC