[JSC] GetterSetter should be JSCell, not JSObject
[WebKit-https.git] / Source / JavaScriptCore / runtime / VM.h
1 /*
2  * Copyright (C) 2008-2019 Apple Inc. All rights reserved.
3  *
4  * Redistribution and use in source and binary forms, with or without
5  * modification, are permitted provided that the following conditions
6  * are met:
7  *
8  * 1.  Redistributions of source code must retain the above copyright
9  *     notice, this list of conditions and the following disclaimer. 
10  * 2.  Redistributions in binary form must reproduce the above copyright
11  *     notice, this list of conditions and the following disclaimer in the
12  *     documentation and/or other materials provided with the distribution. 
13  * 3.  Neither the name of Apple Inc. ("Apple") nor the names of
14  *     its contributors may be used to endorse or promote products derived
15  *     from this software without specific prior written permission. 
16  *
17  * THIS SOFTWARE IS PROVIDED BY APPLE AND ITS CONTRIBUTORS "AS IS" AND ANY
18  * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
19  * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
20  * DISCLAIMED. IN NO EVENT SHALL APPLE OR ITS CONTRIBUTORS BE LIABLE FOR ANY
21  * DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
22  * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
23  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
24  * ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
25  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
26  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
27  */
28
29 #pragma once
30
31 #include "CallData.h"
32 #include "CodeSpecializationKind.h"
33 #include "CompleteSubspace.h"
34 #include "ConcurrentJSLock.h"
35 #include "ControlFlowProfiler.h"
36 #include "DateInstanceCache.h"
37 #include "DeleteAllCodeEffort.h"
38 #include "ExceptionEventLocation.h"
39 #include "ExecutableAllocator.h"
40 #include "FunctionHasExecutedCache.h"
41 #include "FuzzerAgent.h"
42 #include "Heap.h"
43 #include "Integrity.h"
44 #include "Intrinsic.h"
45 #include "IsoCellSet.h"
46 #include "IsoSubspace.h"
47 #include "JITThunks.h"
48 #include "JSCJSValue.h"
49 #include "JSLock.h"
50 #include "MacroAssemblerCodeRef.h"
51 #include "Microtask.h"
52 #include "NumericStrings.h"
53 #include "SmallStrings.h"
54 #include "Strong.h"
55 #include "StructureCache.h"
56 #include "SubspaceAccess.h"
57 #include "VMTraps.h"
58 #include "WasmContext.h"
59 #include "Watchpoint.h"
60 #include <wtf/BumpPointerAllocator.h>
61 #include <wtf/CheckedArithmetic.h>
62 #include <wtf/DateMath.h>
63 #include <wtf/Deque.h>
64 #include <wtf/DoublyLinkedList.h>
65 #include <wtf/Forward.h>
66 #include <wtf/Gigacage.h>
67 #include <wtf/HashMap.h>
68 #include <wtf/HashSet.h>
69 #include <wtf/SetForScope.h>
70 #include <wtf/StackBounds.h>
71 #include <wtf/StackPointer.h>
72 #include <wtf/Stopwatch.h>
73 #include <wtf/ThreadSafeRefCounted.h>
74 #include <wtf/ThreadSpecific.h>
75 #include <wtf/UniqueArray.h>
76 #include <wtf/text/SymbolRegistry.h>
77 #include <wtf/text/WTFString.h>
78 #if ENABLE(REGEXP_TRACING)
79 #include <wtf/ListHashSet.h>
80 #endif
81
82 #if ENABLE(EXCEPTION_SCOPE_VERIFICATION)
83 #include <wtf/StackTrace.h>
84 #endif
85
86 // Enable the Objective-C API for platforms with a modern runtime. This has to match exactly what we
87 // have in JSBase.h.
88 #if !defined(JSC_OBJC_API_ENABLED)
89 #if (defined(__clang__) && defined(__APPLE__) && (defined(__MAC_OS_X_VERSION_MIN_REQUIRED) || (defined(TARGET_OS_IPHONE) && TARGET_OS_IPHONE)))
90 #define JSC_OBJC_API_ENABLED 1
91 #else
92 #define JSC_OBJC_API_ENABLED 0
93 #endif
94 #endif
95
96 namespace WTF {
97 class SimpleStats;
98 } // namespace WTF
99 using WTF::SimpleStats;
100
101 namespace JSC {
102
103 class BuiltinExecutables;
104 class BytecodeIntrinsicRegistry;
105 class CallFrame;
106 class CodeBlock;
107 class CodeCache;
108 class CommonIdentifiers;
109 class CompactVariableMap;
110 class CustomGetterSetter;
111 class DOMAttributeGetterSetter;
112 class Exception;
113 class ExceptionScope;
114 class FastMallocAlignedMemoryAllocator;
115 class GigacageAlignedMemoryAllocator;
116 class HandleStack;
117 class TypeProfiler;
118 class TypeProfilerLog;
119 class HasOwnPropertyCache;
120 class HeapProfiler;
121 class Identifier;
122 class Interpreter;
123 class JSCustomGetterSetterFunction;
124 class JSDestructibleObjectHeapCellType;
125 class JSGlobalObject;
126 class JSObject;
127 class JSPromise;
128 class JSPropertyNameEnumerator;
129 class JSRunLoopTimer;
130 class JSStringHeapCellType;
131 class JSWebAssemblyCodeBlockHeapCellType;
132 class JSWebAssemblyInstance;
133 class LLIntOffsetsExtractor;
134 class NativeExecutable;
135 class PromiseDeferredTimer;
136 class RegExp;
137 class RegExpCache;
138 class Register;
139 class RegisterAtOffsetList;
140 #if ENABLE(SAMPLING_PROFILER)
141 class SamplingProfiler;
142 #endif
143 class ShadowChicken;
144 class ScriptExecutable;
145 class SourceProvider;
146 class SourceProviderCache;
147 class StackFrame;
148 class Structure;
149 #if ENABLE(REGEXP_TRACING)
150 class RegExp;
151 #endif
152 class Symbol;
153 class TypedArrayController;
154 class UnlinkedCodeBlock;
155 class UnlinkedEvalCodeBlock;
156 class UnlinkedFunctionExecutable;
157 class UnlinkedProgramCodeBlock;
158 class UnlinkedModuleProgramCodeBlock;
159 class VirtualRegister;
160 class VMEntryScope;
161 class Watchdog;
162 class Watchpoint;
163 class WatchpointSet;
164 class WebAssemblyFunctionHeapCellType;
165
166 #if ENABLE(FTL_JIT)
167 namespace FTL {
168 class Thunks;
169 }
170 #endif // ENABLE(FTL_JIT)
171 namespace Profiler {
172 class Database;
173 }
174 namespace DOMJIT {
175 class Signature;
176 }
177
178 struct EntryFrame;
179 struct HashTable;
180 struct Instruction;
181 struct ValueProfile;
182
183 using ExecState = CallFrame;
184
185 struct LocalTimeOffsetCache {
186     LocalTimeOffsetCache()
187         : start(0.0)
188         , end(-1.0)
189         , increment(0.0)
190     {
191     }
192
193     void reset()
194     {
195         offset = LocalTimeOffset();
196         start = 0.0;
197         end = -1.0;
198         increment = 0.0;
199     }
200
201     LocalTimeOffset offset;
202     double start;
203     double end;
204     double increment;
205 };
206
207 class QueuedTask {
208     WTF_MAKE_NONCOPYABLE(QueuedTask);
209     WTF_MAKE_FAST_ALLOCATED;
210 public:
211     void run();
212
213     QueuedTask(VM& vm, JSGlobalObject* globalObject, Ref<Microtask>&& microtask)
214         : m_globalObject(vm, globalObject)
215         , m_microtask(WTFMove(microtask))
216     {
217     }
218
219 private:
220     Strong<JSGlobalObject> m_globalObject;
221     Ref<Microtask> m_microtask;
222 };
223
224 class ConservativeRoots;
225
226 #if COMPILER(MSVC)
227 #pragma warning(push)
228 #pragma warning(disable: 4200) // Disable "zero-sized array in struct/union" warning
229 #endif
230 struct ScratchBuffer {
231     ScratchBuffer()
232     {
233         u.m_activeLength = 0;
234     }
235
236     static ScratchBuffer* create(size_t size)
237     {
238         ScratchBuffer* result = new (fastMalloc(ScratchBuffer::allocationSize(size))) ScratchBuffer;
239
240         return result;
241     }
242
243     static size_t allocationSize(Checked<size_t> bufferSize) { return (sizeof(ScratchBuffer) + bufferSize).unsafeGet(); }
244     void setActiveLength(size_t activeLength) { u.m_activeLength = activeLength; }
245     size_t activeLength() const { return u.m_activeLength; };
246     size_t* addressOfActiveLength() { return &u.m_activeLength; };
247     void* dataBuffer() { return m_buffer; }
248
249     union {
250         size_t m_activeLength;
251         double pad; // Make sure m_buffer is double aligned.
252     } u;
253 #if CPU(MIPS) && (defined WTF_MIPS_ARCH_REV && WTF_MIPS_ARCH_REV == 2)
254     alignas(8) void* m_buffer[0];
255 #else
256     void* m_buffer[0];
257 #endif
258 };
259 #if COMPILER(MSVC)
260 #pragma warning(pop)
261 #endif
262
263 class VM : public ThreadSafeRefCounted<VM>, public DoublyLinkedListNode<VM> {
264 public:
265     // WebCore has a one-to-one mapping of threads to VMs;
266     // create() should only be called once
267     // on a thread, this is the 'default' VM (it uses the
268     // thread's default string uniquing table from Thread::current()).
269     // API contexts created using the new context group aware interface
270     // create APIContextGroup objects which require less locking of JSC
271     // than the old singleton APIShared VM created for use by
272     // the original API.
273     enum VMType { Default, APIContextGroup, APIShared };
274
275     struct ClientData {
276         JS_EXPORT_PRIVATE virtual ~ClientData() = 0;
277     };
278
279     bool isSharedInstance() { return vmType == APIShared; }
280     bool usingAPI() { return vmType != Default; }
281     JS_EXPORT_PRIVATE static bool sharedInstanceExists();
282     JS_EXPORT_PRIVATE static VM& sharedInstance();
283
284     JS_EXPORT_PRIVATE static Ref<VM> create(HeapType = SmallHeap);
285     static Ref<VM> createContextGroup(HeapType = SmallHeap);
286     JS_EXPORT_PRIVATE ~VM();
287
288     Watchdog& ensureWatchdog();
289     Watchdog* watchdog() { return m_watchdog.get(); }
290
291     HeapProfiler* heapProfiler() const { return m_heapProfiler.get(); }
292     JS_EXPORT_PRIVATE HeapProfiler& ensureHeapProfiler();
293
294 #if ENABLE(SAMPLING_PROFILER)
295     SamplingProfiler* samplingProfiler() { return m_samplingProfiler.get(); }
296     JS_EXPORT_PRIVATE SamplingProfiler& ensureSamplingProfiler(RefPtr<Stopwatch>&&);
297 #endif
298
299     FuzzerAgent* fuzzerAgent() const { return m_fuzzerAgent.get(); }
300     void setFuzzerAgent(std::unique_ptr<FuzzerAgent>&& fuzzerAgent)
301     {
302         m_fuzzerAgent = WTFMove(fuzzerAgent);
303     }
304
305     static unsigned numberOfIDs() { return s_numberOfIDs.load(); }
306     unsigned id() const { return m_id; }
307     bool isEntered() const { return !!entryScope; }
308
309     inline CallFrame* topJSCallFrame() const;
310
311     // Global object in which execution began.
312     JS_EXPORT_PRIVATE JSGlobalObject* vmEntryGlobalObject(const CallFrame*) const;
313
314     WeakRandom& random() { return m_random; }
315     Integrity::Random& integrityRandom() { return m_integrityRandom; }
316
317 private:
318     unsigned nextID();
319
320     static Atomic<unsigned> s_numberOfIDs;
321
322     unsigned m_id;
323     RefPtr<JSLock> m_apiLock;
324 #if USE(CF)
325     // These need to be initialized before heap below.
326     RetainPtr<CFRunLoopRef> m_runLoop;
327 #endif
328
329     WeakRandom m_random;
330     Integrity::Random m_integrityRandom;
331
332 public:
333     Heap heap;
334     
335     std::unique_ptr<FastMallocAlignedMemoryAllocator> fastMallocAllocator;
336     std::unique_ptr<GigacageAlignedMemoryAllocator> primitiveGigacageAllocator;
337     std::unique_ptr<GigacageAlignedMemoryAllocator> jsValueGigacageAllocator;
338
339     std::unique_ptr<HeapCellType> auxiliaryHeapCellType;
340     std::unique_ptr<HeapCellType> immutableButterflyHeapCellType;
341     std::unique_ptr<HeapCellType> cellHeapCellType;
342     std::unique_ptr<HeapCellType> destructibleCellHeapCellType;
343     std::unique_ptr<JSStringHeapCellType> stringHeapCellType;
344     std::unique_ptr<JSDestructibleObjectHeapCellType> destructibleObjectHeapCellType;
345 #if ENABLE(WEBASSEMBLY)
346     std::unique_ptr<JSWebAssemblyCodeBlockHeapCellType> webAssemblyCodeBlockHeapCellType;
347     std::unique_ptr<WebAssemblyFunctionHeapCellType> webAssemblyFunctionHeapCellType;
348 #endif
349     
350     CompleteSubspace primitiveGigacageAuxiliarySpace; // Typed arrays, strings, bitvectors, etc go here.
351     CompleteSubspace jsValueGigacageAuxiliarySpace; // Butterflies, arrays of JSValues, etc go here.
352     CompleteSubspace immutableButterflyJSValueGigacageAuxiliarySpace; // JSImmutableButterfly goes here.
353
354     // We make cross-cutting assumptions about typed arrays being in the primitive Gigacage and butterflies
355     // being in the JSValue gigacage. For some types, it's super obvious where they should go, and so we
356     // can hardcode that fact. But sometimes it's not clear, so we abstract it by having a Gigacage::Kind
357     // constant somewhere.
358     // FIXME: Maybe it would be better if everyone abstracted this?
359     // https://bugs.webkit.org/show_bug.cgi?id=175248
360     ALWAYS_INLINE CompleteSubspace& gigacageAuxiliarySpace(Gigacage::Kind kind)
361     {
362         switch (kind) {
363         case Gigacage::Primitive:
364             return primitiveGigacageAuxiliarySpace;
365         case Gigacage::JSValue:
366             return jsValueGigacageAuxiliarySpace;
367         case Gigacage::NumberOfKinds:
368             break;
369         }
370         RELEASE_ASSERT_NOT_REACHED();
371         return primitiveGigacageAuxiliarySpace;
372     }
373     
374     // Whenever possible, use subspaceFor<CellType>(vm) to get one of these subspaces.
375     CompleteSubspace cellSpace;
376     CompleteSubspace variableSizedCellSpace; // FIXME: This space is problematic because we have things in here like DirectArguments and ScopedArguments; those should be split into JSValueOOB cells and JSValueStrict auxiliaries. https://bugs.webkit.org/show_bug.cgi?id=182858
377     CompleteSubspace destructibleCellSpace;
378     CompleteSubspace stringSpace;
379     CompleteSubspace destructibleObjectSpace;
380     CompleteSubspace eagerlySweptDestructibleObjectSpace;
381     
382     IsoSubspace executableToCodeBlockEdgeSpace;
383     IsoSubspace functionSpace;
384     IsoSubspace internalFunctionSpace;
385     IsoSubspace nativeExecutableSpace;
386     IsoSubspace propertyTableSpace;
387     IsoSubspace structureRareDataSpace;
388     IsoSubspace structureSpace;
389     IsoSubspace symbolTableSpace;
390
391 #define DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(name) \
392     template<SubspaceAccess mode> \
393     IsoSubspace* name() \
394     { \
395         if (m_##name || mode == SubspaceAccess::Concurrently) \
396             return m_##name.get(); \
397         return name##Slow(); \
398     } \
399     IsoSubspace* name##Slow(); \
400     std::unique_ptr<IsoSubspace> m_##name;
401
402
403 #if JSC_OBJC_API_ENABLED
404     DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(objCCallbackFunctionSpace)
405 #endif
406     DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(boundFunctionSpace)
407     DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(callbackFunctionSpace)
408     DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(customGetterSetterFunctionSpace)
409     DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(errorInstanceSpace)
410     DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(nativeStdFunctionSpace)
411     DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(proxyRevokeSpace)
412     DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(weakObjectRefSpace)
413     DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(weakSetSpace)
414     DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(weakMapSpace)
415 #if ENABLE(WEBASSEMBLY)
416     DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(webAssemblyCodeBlockSpace)
417     DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(webAssemblyFunctionSpace)
418     DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER(webAssemblyWrapperFunctionSpace)
419 #endif
420
421 #undef DYNAMIC_ISO_SUBSPACE_DEFINE_MEMBER
422     
423     IsoCellSet executableToCodeBlockEdgesWithConstraints;
424     IsoCellSet executableToCodeBlockEdgesWithFinalizers;
425
426 #define DYNAMIC_SPACE_AND_SET_DEFINE_MEMBER(name) \
427     template<SubspaceAccess mode> \
428     IsoSubspace* name() \
429     { \
430         if (auto* spaceAndSet = m_##name.get()) \
431             return &spaceAndSet->space; \
432         if (mode == SubspaceAccess::Concurrently) \
433             return nullptr; \
434         return name##Slow(); \
435     } \
436     IsoSubspace* name##Slow(); \
437     std::unique_ptr<SpaceAndSet> m_##name;
438     
439     struct SpaceAndSet {
440         WTF_MAKE_STRUCT_FAST_ALLOCATED;
441
442         IsoSubspace space;
443         IsoCellSet set;
444         
445         template<typename... Arguments>
446         SpaceAndSet(Arguments&&... arguments)
447             : space(std::forward<Arguments>(arguments)...)
448             , set(space)
449         {
450         }
451         
452         static IsoCellSet& setFor(Subspace& space)
453         {
454             return *bitwise_cast<IsoCellSet*>(
455                 bitwise_cast<char*>(&space) -
456                 OBJECT_OFFSETOF(SpaceAndSet, space) +
457                 OBJECT_OFFSETOF(SpaceAndSet, set));
458         }
459     };
460     
461     SpaceAndSet codeBlockSpace;
462
463     template<typename Func>
464     void forEachCodeBlockSpace(const Func& func)
465     {
466         // This should not include webAssemblyCodeBlockSpace because this is about subsclasses of
467         // JSC::CodeBlock.
468         func(codeBlockSpace);
469     }
470
471     DYNAMIC_SPACE_AND_SET_DEFINE_MEMBER(evalExecutableSpace)
472     DYNAMIC_SPACE_AND_SET_DEFINE_MEMBER(moduleProgramExecutableSpace)
473     SpaceAndSet functionExecutableSpace;
474     SpaceAndSet programExecutableSpace;
475
476     template<typename Func>
477     void forEachScriptExecutableSpace(const Func& func)
478     {
479         if (m_evalExecutableSpace)
480             func(*m_evalExecutableSpace);
481         func(functionExecutableSpace);
482         if (m_moduleProgramExecutableSpace)
483             func(*m_moduleProgramExecutableSpace);
484         func(programExecutableSpace);
485     }
486
487     SpaceAndSet unlinkedFunctionExecutableSpace;
488
489 #undef DYNAMIC_SPACE_AND_SET_DEFINE_MEMBER
490
491     VMType vmType;
492     ClientData* clientData;
493     EntryFrame* topEntryFrame;
494     // NOTE: When throwing an exception while rolling back the call frame, this may be equal to
495     // topEntryFrame.
496     // FIXME: This should be a void*, because it might not point to a CallFrame.
497     // https://bugs.webkit.org/show_bug.cgi?id=160441
498     ExecState* topCallFrame { nullptr };
499 #if ENABLE(WEBASSEMBLY)
500     Wasm::Context wasmContext;
501 #endif
502     Strong<Structure> structureStructure;
503     Strong<Structure> structureRareDataStructure;
504     Strong<Structure> terminatedExecutionErrorStructure;
505     Strong<Structure> stringStructure;
506     Strong<Structure> propertyNameEnumeratorStructure;
507     Strong<Structure> getterSetterStructure;
508     Strong<Structure> customGetterSetterStructure;
509     Strong<Structure> domAttributeGetterSetterStructure;
510     Strong<Structure> scopedArgumentsTableStructure;
511     Strong<Structure> apiWrapperStructure;
512     Strong<Structure> nativeExecutableStructure;
513     Strong<Structure> evalExecutableStructure;
514     Strong<Structure> programExecutableStructure;
515     Strong<Structure> functionExecutableStructure;
516 #if ENABLE(WEBASSEMBLY)
517     Strong<Structure> webAssemblyCodeBlockStructure;
518 #endif
519     Strong<Structure> moduleProgramExecutableStructure;
520     Strong<Structure> regExpStructure;
521     Strong<Structure> symbolStructure;
522     Strong<Structure> symbolTableStructure;
523     Strong<Structure> fixedArrayStructure;
524     Strong<Structure> immutableButterflyStructures[NumberOfCopyOnWriteIndexingModes];
525     Strong<Structure> sourceCodeStructure;
526     Strong<Structure> scriptFetcherStructure;
527     Strong<Structure> scriptFetchParametersStructure;
528     Strong<Structure> structureChainStructure;
529     Strong<Structure> sparseArrayValueMapStructure;
530     Strong<Structure> templateObjectDescriptorStructure;
531     Strong<Structure> arrayBufferNeuteringWatchpointStructure;
532     Strong<Structure> unlinkedFunctionExecutableStructure;
533     Strong<Structure> unlinkedProgramCodeBlockStructure;
534     Strong<Structure> unlinkedEvalCodeBlockStructure;
535     Strong<Structure> unlinkedFunctionCodeBlockStructure;
536     Strong<Structure> unlinkedModuleProgramCodeBlockStructure;
537     Strong<Structure> propertyTableStructure;
538     Strong<Structure> functionRareDataStructure;
539     Strong<Structure> exceptionStructure;
540     Strong<Structure> promiseDeferredStructure;
541     Strong<Structure> internalPromiseDeferredStructure;
542     Strong<Structure> nativeStdFunctionCellStructure;
543     Strong<Structure> programCodeBlockStructure;
544     Strong<Structure> moduleProgramCodeBlockStructure;
545     Strong<Structure> evalCodeBlockStructure;
546     Strong<Structure> functionCodeBlockStructure;
547     Strong<Structure> hashMapBucketSetStructure;
548     Strong<Structure> hashMapBucketMapStructure;
549     Strong<Structure> bigIntStructure;
550     Strong<Structure> executableToCodeBlockEdgeStructure;
551
552     Strong<Structure> m_setIteratorStructure;
553     Strong<Structure> m_mapIteratorStructure;
554
555     Strong<JSPropertyNameEnumerator> m_emptyPropertyNameEnumerator;
556
557     Strong<JSCell> m_sentinelSetBucket;
558     Strong<JSCell> m_sentinelMapBucket;
559
560     Ref<PromiseDeferredTimer> promiseDeferredTimer;
561     
562     JSCell* currentlyDestructingCallbackObject;
563     const ClassInfo* currentlyDestructingCallbackObjectClassInfo { nullptr };
564
565     AtomStringTable* m_atomStringTable;
566     WTF::SymbolRegistry m_symbolRegistry;
567     CommonIdentifiers* propertyNames;
568     const ArgList* emptyList;
569     SmallStrings smallStrings;
570     NumericStrings numericStrings;
571     DateInstanceCache dateInstanceCache;
572     std::unique_ptr<SimpleStats> machineCodeBytesPerBytecodeWordForBaselineJIT;
573     WeakGCMap<std::pair<CustomGetterSetter*, int>, JSCustomGetterSetterFunction> customGetterSetterFunctionMap;
574     WeakGCMap<StringImpl*, JSString, PtrHash<StringImpl*>> stringCache;
575     Strong<JSString> lastCachedString;
576
577     AtomStringTable* atomStringTable() const { return m_atomStringTable; }
578     WTF::SymbolRegistry& symbolRegistry() { return m_symbolRegistry; }
579
580     Structure* setIteratorStructure()
581     {
582         if (LIKELY(m_setIteratorStructure))
583             return m_setIteratorStructure.get();
584         return setIteratorStructureSlow();
585     }
586
587     Structure* mapIteratorStructure()
588     {
589         if (LIKELY(m_mapIteratorStructure))
590             return m_mapIteratorStructure.get();
591         return mapIteratorStructureSlow();
592     }
593
594     JSCell* sentinelSetBucket()
595     {
596         if (LIKELY(m_sentinelSetBucket))
597             return m_sentinelSetBucket.get();
598         return sentinelSetBucketSlow();
599     }
600
601     JSCell* sentinelMapBucket()
602     {
603         if (LIKELY(m_sentinelMapBucket))
604             return m_sentinelMapBucket.get();
605         return sentinelMapBucketSlow();
606     }
607
608     JSPropertyNameEnumerator* emptyPropertyNameEnumerator()
609     {
610         if (LIKELY(m_emptyPropertyNameEnumerator))
611             return m_emptyPropertyNameEnumerator.get();
612         return emptyPropertyNameEnumeratorSlow();
613     }
614
615     WeakGCMap<SymbolImpl*, Symbol, PtrHash<SymbolImpl*>> symbolImplToSymbolMap;
616
617     enum class DeletePropertyMode {
618         // Default behaviour of deleteProperty, matching the spec.
619         Default,
620         // This setting causes deleteProperty to force deletion of all
621         // properties including those that are non-configurable (DontDelete).
622         IgnoreConfigurable
623     };
624
625     DeletePropertyMode deletePropertyMode()
626     {
627         return m_deletePropertyMode;
628     }
629
630     class DeletePropertyModeScope {
631     public:
632         DeletePropertyModeScope(VM& vm, DeletePropertyMode mode)
633             : m_vm(vm)
634             , m_previousMode(vm.m_deletePropertyMode)
635         {
636             m_vm.m_deletePropertyMode = mode;
637         }
638
639         ~DeletePropertyModeScope()
640         {
641             m_vm.m_deletePropertyMode = m_previousMode;
642         }
643
644     private:
645         VM& m_vm;
646         DeletePropertyMode m_previousMode;
647     };
648
649     static JS_EXPORT_PRIVATE bool canUseAssembler();
650     static bool isInMiniMode()
651     {
652         return !canUseJIT() || Options::forceMiniVMMode();
653     }
654
655     static bool useUnlinkedCodeBlockJettisoning()
656     {
657         return Options::useUnlinkedCodeBlockJettisoning() || isInMiniMode();
658     }
659
660     static void computeCanUseJIT();
661     ALWAYS_INLINE static bool canUseJIT()
662     {
663 #if ENABLE(JIT)
664 #if !ASSERT_DISABLED
665         RELEASE_ASSERT(s_canUseJITIsSet);
666 #endif
667         return s_canUseJIT;
668 #else
669         return false;
670 #endif
671     }
672
673     SourceProviderCache* addSourceProviderCache(SourceProvider*);
674     void clearSourceProviderCaches();
675
676     StructureCache structureCache;
677
678     typedef HashMap<RefPtr<SourceProvider>, RefPtr<SourceProviderCache>> SourceProviderCacheMap;
679     SourceProviderCacheMap sourceProviderCacheMap;
680     Interpreter* interpreter;
681 #if ENABLE(JIT)
682     std::unique_ptr<JITThunks> jitStubs;
683     MacroAssemblerCodeRef<JITThunkPtrTag> getCTIStub(ThunkGenerator generator)
684     {
685         return jitStubs->ctiStub(*this, generator);
686     }
687
688 #endif // ENABLE(JIT)
689 #if ENABLE(FTL_JIT)
690     std::unique_ptr<FTL::Thunks> ftlThunks;
691 #endif
692     NativeExecutable* getHostFunction(NativeFunction, NativeFunction constructor, const String& name);
693     NativeExecutable* getHostFunction(NativeFunction, Intrinsic, NativeFunction constructor, const DOMJIT::Signature*, const String& name);
694
695     MacroAssemblerCodePtr<JSEntryPtrTag> getCTIInternalFunctionTrampolineFor(CodeSpecializationKind);
696
697     static ptrdiff_t exceptionOffset()
698     {
699         return OBJECT_OFFSETOF(VM, m_exception);
700     }
701
702     static ptrdiff_t callFrameForCatchOffset()
703     {
704         return OBJECT_OFFSETOF(VM, callFrameForCatch);
705     }
706
707     static ptrdiff_t topEntryFrameOffset()
708     {
709         return OBJECT_OFFSETOF(VM, topEntryFrame);
710     }
711
712     static ptrdiff_t offsetOfHeapBarrierThreshold()
713     {
714         return OBJECT_OFFSETOF(VM, heap) + OBJECT_OFFSETOF(Heap, m_barrierThreshold);
715     }
716
717     static ptrdiff_t offsetOfHeapMutatorShouldBeFenced()
718     {
719         return OBJECT_OFFSETOF(VM, heap) + OBJECT_OFFSETOF(Heap, m_mutatorShouldBeFenced);
720     }
721
722     void restorePreviousException(Exception* exception) { setException(exception); }
723
724     void clearLastException() { m_lastException = nullptr; }
725
726     ExecState** addressOfCallFrameForCatch() { return &callFrameForCatch; }
727
728     JSCell** addressOfException() { return reinterpret_cast<JSCell**>(&m_exception); }
729
730     Exception* lastException() const { return m_lastException; }
731     JSCell** addressOfLastException() { return reinterpret_cast<JSCell**>(&m_lastException); }
732
733     // This should only be used for test or assertion code that wants to inspect
734     // the pending exception without interfering with Throw/CatchScopes.
735     Exception* exceptionForInspection() const { return m_exception; }
736
737     void setFailNextNewCodeBlock() { m_failNextNewCodeBlock = true; }
738     bool getAndClearFailNextNewCodeBlock()
739     {
740         bool result = m_failNextNewCodeBlock;
741         m_failNextNewCodeBlock = false;
742         return result;
743     }
744     
745     ALWAYS_INLINE Structure* getStructure(StructureID id)
746     {
747         return heap.structureIDTable().get(decontaminate(id));
748     }
749     
750     void* stackPointerAtVMEntry() const { return m_stackPointerAtVMEntry; }
751     void setStackPointerAtVMEntry(void*);
752
753     size_t softReservedZoneSize() const { return m_currentSoftReservedZoneSize; }
754     size_t updateSoftReservedZoneSize(size_t softReservedZoneSize);
755     
756     static size_t committedStackByteCount();
757     inline bool ensureStackCapacityFor(Register* newTopOfStack);
758
759     void* stackLimit() { return m_stackLimit; }
760     void* softStackLimit() { return m_softStackLimit; }
761     void** addressOfSoftStackLimit() { return &m_softStackLimit; }
762 #if ENABLE(C_LOOP)
763     void* cloopStackLimit() { return m_cloopStackLimit; }
764     void setCLoopStackLimit(void* limit) { m_cloopStackLimit = limit; }
765     JS_EXPORT_PRIVATE void* currentCLoopStackPointer() const;
766 #endif
767
768     inline bool isSafeToRecurseSoft() const;
769     bool isSafeToRecurse() const
770     {
771         return isSafeToRecurse(m_stackLimit);
772     }
773
774     void** addressOfLastStackTop() { return &m_lastStackTop; }
775     void* lastStackTop() { return m_lastStackTop; }
776     void setLastStackTop(void*);
777     
778     void firePrimitiveGigacageEnabledIfNecessary()
779     {
780         if (m_needToFirePrimitiveGigacageEnabled) {
781             m_needToFirePrimitiveGigacageEnabled = false;
782             m_primitiveGigacageEnabled.fireAll(*this, "Primitive gigacage disabled asynchronously");
783         }
784     }
785
786     JSValue hostCallReturnValue;
787     unsigned varargsLength;
788     ExecState* newCallFrameReturnValue;
789     ExecState* callFrameForCatch;
790     void* targetMachinePCForThrow;
791     const Instruction* targetInterpreterPCForThrow;
792     uint32_t osrExitIndex;
793     void* osrExitJumpDestination;
794     bool isExecutingInRegExpJIT { false };
795
796     // The threading protocol here is as follows:
797     // - You can call scratchBufferForSize from any thread.
798     // - You can only set the ScratchBuffer's activeLength from the main thread.
799     // - You can only write to entries in the ScratchBuffer from the main thread.
800     ScratchBuffer* scratchBufferForSize(size_t size);
801     void clearScratchBuffers();
802
803     EncodedJSValue* exceptionFuzzingBuffer(size_t size)
804     {
805         ASSERT(Options::useExceptionFuzz());
806         if (!m_exceptionFuzzBuffer)
807             m_exceptionFuzzBuffer = MallocPtr<EncodedJSValue>::malloc(size);
808         return m_exceptionFuzzBuffer.get();
809     }
810
811     void gatherScratchBufferRoots(ConservativeRoots&);
812
813     VMEntryScope* entryScope;
814
815     JSObject* stringRecursionCheckFirstObject { nullptr };
816     HashSet<JSObject*> stringRecursionCheckVisitedObjects;
817     
818     LocalTimeOffsetCache utcTimeOffsetCache;
819     LocalTimeOffsetCache localTimeOffsetCache;
820
821     String cachedDateString;
822     double cachedDateStringValue;
823
824     std::unique_ptr<Profiler::Database> m_perBytecodeProfiler;
825     RefPtr<TypedArrayController> m_typedArrayController;
826     RegExpCache* m_regExpCache;
827     BumpPointerAllocator m_regExpAllocator;
828     ConcurrentJSLock m_regExpAllocatorLock;
829
830 #if ENABLE(YARR_JIT_ALL_PARENS_EXPRESSIONS)
831     static constexpr size_t patternContextBufferSize = 8192; // Space allocated to save nested parenthesis context
832     UniqueArray<char> m_regExpPatternContexBuffer;
833     Lock m_regExpPatternContextLock;
834     char* acquireRegExpPatternContexBuffer();
835     void releaseRegExpPatternContexBuffer();
836 #else
837     static constexpr size_t patternContextBufferSize = 0; // Space allocated to save nested parenthesis context
838 #endif
839
840     Ref<CompactVariableMap> m_compactVariableMap;
841
842     std::unique_ptr<HasOwnPropertyCache> m_hasOwnPropertyCache;
843     ALWAYS_INLINE HasOwnPropertyCache* hasOwnPropertyCache() { return m_hasOwnPropertyCache.get(); }
844     HasOwnPropertyCache* ensureHasOwnPropertyCache();
845
846 #if ENABLE(REGEXP_TRACING)
847     typedef ListHashSet<RegExp*> RTTraceList;
848     RTTraceList* m_rtTraceList;
849 #endif
850
851     JS_EXPORT_PRIVATE void resetDateCache();
852
853     RegExpCache* regExpCache() { return m_regExpCache; }
854 #if ENABLE(REGEXP_TRACING)
855     void addRegExpToTrace(RegExp*);
856 #endif
857     JS_EXPORT_PRIVATE void dumpRegExpTrace();
858
859     bool isCollectorBusyOnCurrentThread() { return heap.isCurrentThreadBusy(); }
860
861 #if ENABLE(GC_VALIDATION)
862     bool isInitializingObject() const; 
863     void setInitializingObjectClass(const ClassInfo*);
864 #endif
865
866     bool currentThreadIsHoldingAPILock() const { return m_apiLock->currentThreadIsHoldingLock(); }
867
868     JSLock& apiLock() { return *m_apiLock; }
869     CodeCache* codeCache() { return m_codeCache.get(); }
870
871     JS_EXPORT_PRIVATE void whenIdle(Function<void()>&&);
872
873     JS_EXPORT_PRIVATE void deleteAllCode(DeleteAllCodeEffort);
874     JS_EXPORT_PRIVATE void deleteAllLinkedCode(DeleteAllCodeEffort);
875
876     void shrinkFootprintWhenIdle();
877
878     WatchpointSet* ensureWatchpointSetForImpureProperty(const Identifier&);
879     void registerWatchpointForImpureProperty(const Identifier&, Watchpoint*);
880     
881     // FIXME: Use AtomString once it got merged with Identifier.
882     JS_EXPORT_PRIVATE void addImpureProperty(const String&);
883     
884     InlineWatchpointSet& primitiveGigacageEnabled() { return m_primitiveGigacageEnabled; }
885
886     BuiltinExecutables* builtinExecutables() { return m_builtinExecutables.get(); }
887
888     bool enableTypeProfiler();
889     bool disableTypeProfiler();
890     TypeProfilerLog* typeProfilerLog() { return m_typeProfilerLog.get(); }
891     TypeProfiler* typeProfiler() { return m_typeProfiler.get(); }
892     JS_EXPORT_PRIVATE void dumpTypeProfilerData();
893
894     FunctionHasExecutedCache* functionHasExecutedCache() { return &m_functionHasExecutedCache; }
895
896     ControlFlowProfiler* controlFlowProfiler() { return m_controlFlowProfiler.get(); }
897     bool enableControlFlowProfiler();
898     bool disableControlFlowProfiler();
899
900     void queueMicrotask(JSGlobalObject&, Ref<Microtask>&&);
901     JS_EXPORT_PRIVATE void drainMicrotasks();
902     void setOnEachMicrotaskTick(WTF::Function<void(VM&)>&& func) { m_onEachMicrotaskTick = WTFMove(func); }
903     void finalizeSynchronousJSExecution() { ASSERT(currentThreadIsHoldingAPILock()); m_currentWeakRefVersion++; }
904     uintptr_t currentWeakRefVersion() const { return m_currentWeakRefVersion; }
905
906     void setGlobalConstRedeclarationShouldThrow(bool globalConstRedeclarationThrow) { m_globalConstRedeclarationShouldThrow = globalConstRedeclarationThrow; }
907     ALWAYS_INLINE bool globalConstRedeclarationShouldThrow() const { return m_globalConstRedeclarationShouldThrow; }
908
909     void setShouldBuildPCToCodeOriginMapping() { m_shouldBuildPCToCodeOriginMapping = true; }
910     bool shouldBuilderPCToCodeOriginMapping() const { return m_shouldBuildPCToCodeOriginMapping; }
911
912     BytecodeIntrinsicRegistry& bytecodeIntrinsicRegistry() { return *m_bytecodeIntrinsicRegistry; }
913     
914     ShadowChicken* shadowChicken() { return m_shadowChicken.get(); }
915     void ensureShadowChicken();
916     
917     template<typename Func>
918     void logEvent(CodeBlock*, const char* summary, const Func& func);
919
920     Optional<RefPtr<Thread>> ownerThread() const { return m_apiLock->ownerThread(); }
921
922     VMTraps& traps() { return m_traps; }
923
924     void handleTraps(ExecState* exec, VMTraps::Mask mask = VMTraps::Mask::allEventTypes()) { m_traps.handleTraps(exec, mask); }
925
926     bool needTrapHandling() { return m_traps.needTrapHandling(); }
927     bool needTrapHandling(VMTraps::Mask mask) { return m_traps.needTrapHandling(mask); }
928     void* needTrapHandlingAddress() { return m_traps.needTrapHandlingAddress(); }
929
930     void notifyNeedDebuggerBreak() { m_traps.fireTrap(VMTraps::NeedDebuggerBreak); }
931     void notifyNeedTermination() { m_traps.fireTrap(VMTraps::NeedTermination); }
932     void notifyNeedWatchdogCheck() { m_traps.fireTrap(VMTraps::NeedWatchdogCheck); }
933
934     void promiseRejected(JSPromise*);
935
936 #if ENABLE(EXCEPTION_SCOPE_VERIFICATION)
937     StackTrace* nativeStackTraceOfLastThrow() const { return m_nativeStackTraceOfLastThrow.get(); }
938     Thread* throwingThread() const { return m_throwingThread.get(); }
939     bool needExceptionCheck() const { return m_needExceptionCheck; }
940 #endif
941
942 #if USE(CF)
943     CFRunLoopRef runLoop() const { return m_runLoop.get(); }
944     JS_EXPORT_PRIVATE void setRunLoop(CFRunLoopRef);
945 #endif // USE(CF)
946
947     static void setCrashOnVMCreation(bool);
948
949     class DeferExceptionScope {
950     public:
951         DeferExceptionScope(VM& vm)
952             : m_savedException(vm.m_exception, nullptr)
953             , m_savedLastException(vm.m_lastException, nullptr)
954         {
955         }
956
957     private:
958         SetForScope<Exception*> m_savedException;
959         SetForScope<Exception*> m_savedLastException;
960     };
961
962 private:
963     friend class LLIntOffsetsExtractor;
964
965     VM(VMType, HeapType);
966     static VM*& sharedInstanceInternal();
967     void createNativeThunk();
968
969     JS_EXPORT_PRIVATE Structure* setIteratorStructureSlow();
970     JS_EXPORT_PRIVATE Structure* mapIteratorStructureSlow();
971     JSCell* sentinelSetBucketSlow();
972     JSCell* sentinelMapBucketSlow();
973     JSPropertyNameEnumerator* emptyPropertyNameEnumeratorSlow();
974
975     void updateStackLimits();
976
977     bool isSafeToRecurse(void* stackLimit) const
978     {
979         ASSERT(Thread::current().stack().isGrowingDownward());
980         void* curr = currentStackPointer();
981         return curr >= stackLimit;
982     }
983
984     void setException(Exception* exception)
985     {
986         m_exception = exception;
987         m_lastException = exception;
988     }
989     Exception* exception() const
990     {
991 #if ENABLE(EXCEPTION_SCOPE_VERIFICATION)
992         m_needExceptionCheck = false;
993 #endif
994         return m_exception;
995     }
996     void clearException()
997     {
998 #if ENABLE(EXCEPTION_SCOPE_VERIFICATION)
999         m_needExceptionCheck = false;
1000         m_nativeStackTraceOfLastThrow = nullptr;
1001         m_throwingThread = nullptr;
1002 #endif
1003         m_exception = nullptr;
1004     }
1005
1006 #if ENABLE(C_LOOP)
1007     bool ensureStackCapacityForCLoop(Register* newTopOfStack);
1008     bool isSafeToRecurseSoftCLoop() const;
1009 #endif // ENABLE(C_LOOP)
1010
1011     JS_EXPORT_PRIVATE Exception* throwException(ExecState*, Exception*);
1012     JS_EXPORT_PRIVATE Exception* throwException(ExecState*, JSValue);
1013     JS_EXPORT_PRIVATE Exception* throwException(ExecState*, JSObject*);
1014
1015 #if ENABLE(EXCEPTION_SCOPE_VERIFICATION)
1016     void verifyExceptionCheckNeedIsSatisfied(unsigned depth, ExceptionEventLocation&);
1017 #endif
1018     
1019     static void primitiveGigacageDisabledCallback(void*);
1020     void primitiveGigacageDisabled();
1021
1022     void callPromiseRejectionCallback(Strong<JSPromise>&);
1023     void didExhaustMicrotaskQueue();
1024
1025 #if ENABLE(GC_VALIDATION)
1026     const ClassInfo* m_initializingObjectClass;
1027 #endif
1028
1029     void* m_stackPointerAtVMEntry;
1030     size_t m_currentSoftReservedZoneSize;
1031     void* m_stackLimit { nullptr };
1032     void* m_softStackLimit { nullptr };
1033 #if ENABLE(C_LOOP)
1034     void* m_cloopStackLimit { nullptr };
1035 #endif
1036     void* m_lastStackTop { nullptr };
1037
1038     Exception* m_exception { nullptr };
1039     Exception* m_lastException { nullptr };
1040 #if ENABLE(EXCEPTION_SCOPE_VERIFICATION)
1041     ExceptionScope* m_topExceptionScope { nullptr };
1042     ExceptionEventLocation m_simulatedThrowPointLocation;
1043     unsigned m_simulatedThrowPointRecursionDepth { 0 };
1044     mutable bool m_needExceptionCheck { false };
1045     std::unique_ptr<StackTrace> m_nativeStackTraceOfLastThrow;
1046     std::unique_ptr<StackTrace> m_nativeStackTraceOfLastSimulatedThrow;
1047     RefPtr<Thread> m_throwingThread;
1048 #endif
1049
1050     bool m_failNextNewCodeBlock { false };
1051     DeletePropertyMode m_deletePropertyMode { DeletePropertyMode::Default };
1052     bool m_globalConstRedeclarationShouldThrow { true };
1053     bool m_shouldBuildPCToCodeOriginMapping { false };
1054     std::unique_ptr<CodeCache> m_codeCache;
1055     std::unique_ptr<BuiltinExecutables> m_builtinExecutables;
1056     HashMap<String, RefPtr<WatchpointSet>> m_impurePropertyWatchpointSets;
1057     std::unique_ptr<TypeProfiler> m_typeProfiler;
1058     std::unique_ptr<TypeProfilerLog> m_typeProfilerLog;
1059     unsigned m_typeProfilerEnabledCount;
1060     bool m_needToFirePrimitiveGigacageEnabled { false };
1061     Lock m_scratchBufferLock;
1062     Vector<ScratchBuffer*> m_scratchBuffers;
1063     size_t m_sizeOfLastScratchBuffer { 0 };
1064     InlineWatchpointSet m_primitiveGigacageEnabled;
1065     FunctionHasExecutedCache m_functionHasExecutedCache;
1066     std::unique_ptr<ControlFlowProfiler> m_controlFlowProfiler;
1067     unsigned m_controlFlowProfilerEnabledCount;
1068     Deque<std::unique_ptr<QueuedTask>> m_microtaskQueue;
1069     MallocPtr<EncodedJSValue> m_exceptionFuzzBuffer;
1070     VMTraps m_traps;
1071     RefPtr<Watchdog> m_watchdog;
1072     std::unique_ptr<HeapProfiler> m_heapProfiler;
1073 #if ENABLE(SAMPLING_PROFILER)
1074     RefPtr<SamplingProfiler> m_samplingProfiler;
1075 #endif
1076     std::unique_ptr<FuzzerAgent> m_fuzzerAgent;
1077     std::unique_ptr<ShadowChicken> m_shadowChicken;
1078     std::unique_ptr<BytecodeIntrinsicRegistry> m_bytecodeIntrinsicRegistry;
1079
1080     // FIXME: We should remove handled promises from this list at GC flip. <https://webkit.org/b/201005>
1081     Vector<Strong<JSPromise>> m_aboutToBeNotifiedRejectedPromises;
1082
1083     WTF::Function<void(VM&)> m_onEachMicrotaskTick;
1084     uintptr_t m_currentWeakRefVersion { 0 };
1085
1086 #if ENABLE(JIT)
1087 #if !ASSERT_DISABLED
1088     JS_EXPORT_PRIVATE static bool s_canUseJITIsSet;
1089 #endif
1090     JS_EXPORT_PRIVATE static bool s_canUseJIT;
1091 #endif
1092
1093     VM* m_prev; // Required by DoublyLinkedListNode.
1094     VM* m_next; // Required by DoublyLinkedListNode.
1095
1096     // Friends for exception checking purpose only.
1097     friend class Heap;
1098     friend class CatchScope;
1099     friend class ExceptionScope;
1100     friend class ThrowScope;
1101     friend class VMTraps;
1102     friend class WTF::DoublyLinkedListNode<VM>;
1103 };
1104
1105 #if ENABLE(GC_VALIDATION)
1106 inline bool VM::isInitializingObject() const
1107 {
1108     return !!m_initializingObjectClass;
1109 }
1110
1111 inline void VM::setInitializingObjectClass(const ClassInfo* initializingObjectClass)
1112 {
1113     m_initializingObjectClass = initializingObjectClass;
1114 }
1115 #endif
1116
1117 inline Heap* WeakSet::heap() const
1118 {
1119     return &m_vm.heap;
1120 }
1121
1122 #if !ENABLE(C_LOOP)
1123 extern "C" void sanitizeStackForVMImpl(VM*);
1124 #endif
1125
1126 JS_EXPORT_PRIVATE void sanitizeStackForVM(VM&);
1127 void logSanitizeStack(VM&);
1128
1129 } // namespace JSC