Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 9ef3e2eb29bf68df3e3072ec6431fd6e7d61f99f
      
https://github.com/WebKit/WebKit/commit/9ef3e2eb29bf68df3e3072ec6431fd6e7d61f99f
  Author: Charlie Wolfe <[email protected]>
  Date:   2026-09-29 (Tue, 29 Sep 2026)

  Changed paths:
    A LayoutTests/js/dom/window-proxy-prototype-navigation-expected.txt
    A LayoutTests/js/dom/window-proxy-prototype-navigation.html
    M Source/JavaScriptCore/runtime/JSObject.cpp

  Log Message:
  -----------
  Avoid `haveABadTime()` when a prototype's chain already intercepts indexed 
accesses
https://bugs.webkit.org/show_bug.cgi?id=325587
rdar://188662224

Reviewed by Yusuke Suzuki.

JSObject::setPrototypeDirect() calls haveABadTime() whenever a prototype gets a 
chain that may
intercept indexed accesses. If the old chain already could, this is 
unnecessary, since nothing
inheriting from it has fast indexed storage. That's the case for every 
JSGlobalProxy retargeted on
navigation, since the proxy itself intercepts indexed accesses.

Now we only call it if the old chain could not intercept indexed accesses.

Test: js/dom/window-proxy-prototype-navigation.html

* LayoutTests/js/dom/window-proxy-prototype-navigation-expected.txt: Added.
* LayoutTests/js/dom/window-proxy-prototype-navigation.html: Added.
* Source/JavaScriptCore/runtime/JSObject.cpp:
(JSC::JSObject::setPrototypeDirect):

Canonical link: https://commits.webkit.org/322162@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to