Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 71d329770b1579eaa652d2ae023f47001c1f9b4a
      
https://github.com/WebKit/WebKit/commit/71d329770b1579eaa652d2ae023f47001c1f9b4a
  Author: Sergey Rubanov <[email protected]>
  Date:   2026-09-30 (Wed, 30 Sep 2026)

  Changed paths:
    A JSTests/stress/typedarray-constructor-proxy-array-like.js
    M Source/JavaScriptCore/runtime/JSGenericTypedArrayViewConstructorInlines.h

  Log Message:
  -----------
  [JSC] Read length when constructing a TypedArray from a Proxy array-like

https://bugs.webkit.org/show_bug.cgi?id=325491

Reviewed by Keith Miller.

A Proxy of a plain object has no @@iterator, so the TypedArray
constructor takes the array-like path. That path asked for "length"
with VMInquiry, which does not run the get trap and stores undefined.
The result was an empty TypedArray.

When the length slot is tainted by an opaque object, Get "length"
for real and apply ToLength. A Proxy of an array still uses its
iterator.

* JSTests/stress/typedarray-constructor-proxy-array-like.js: Added.
* Source/JavaScriptCore/runtime/JSGenericTypedArrayViewConstructorInlines.h:
(JSC::constructGenericTypedArrayViewWithArguments):

Canonical link: https://commits.webkit.org/322260@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to