Branch: refs/heads/main
Home: https://github.com/WebKit/WebKit
Commit: 71d329770b1579eaa652d2ae023f47001c1f9b4a
https://github.com/WebKit/WebKit/commit/71d329770b1579eaa652d2ae023f47001c1f9b4a
Author: Sergey Rubanov <[email protected]>
Date: 2026-09-30 (Wed, 30 Sep 2026)
Changed paths:
A JSTests/stress/typedarray-constructor-proxy-array-like.js
M Source/JavaScriptCore/runtime/JSGenericTypedArrayViewConstructorInlines.h
Log Message:
-----------
[JSC] Read length when constructing a TypedArray from a Proxy array-like
https://bugs.webkit.org/show_bug.cgi?id=325491
Reviewed by Keith Miller.
A Proxy of a plain object has no @@iterator, so the TypedArray
constructor takes the array-like path. That path asked for "length"
with VMInquiry, which does not run the get trap and stores undefined.
The result was an empty TypedArray.
When the length slot is tainted by an opaque object, Get "length"
for real and apply ToLength. A Proxy of an array still uses its
iterator.
* JSTests/stress/typedarray-constructor-proxy-array-like.js: Added.
* Source/JavaScriptCore/runtime/JSGenericTypedArrayViewConstructorInlines.h:
(JSC::constructGenericTypedArrayViewWithArguments):
Canonical link: https://commits.webkit.org/322260@main
To unsubscribe from these emails, change your notification settings at
https://github.com/WebKit/WebKit/settings/notifications