68beef53c3
This fixes a corner-case where arrow functions that require a context allocate none, because there are no additional slots allocated. Note that this didn't happen with true function scopes because they always had at least the receiver slot. The outcome was a context chain that no longer was in sync with the scope chain, hence context slot loads were bogus. This is observable using the DYNAMIC_LOCAL optimization in all compilers. R=rossberg@chromium.org,wingo@igalia.com TEST=mjsunit/harmony/regress/regress-4160 BUG=v8:4160 LOG=N Review URL: https://codereview.chromium.org/1146063006 Cr-Commit-Position: refs/heads/master@{#28788} |
||
---|---|---|
.. | ||
regress-2219.js | ||
regress-2225.js | ||
regress-3501.js | ||
regress-3750.js | ||
regress-4056.js | ||
regress-4160.js | ||
regress-173361.js | ||
regress-343928.js | ||
regress-405844.js | ||
regress-455141.js | ||
regress-crbug-347528.js | ||
regress-crbug-448730.js | ||
regress-crbug-451770.js | ||
regress-crbug-461520.js | ||
regress-crbug-465671-null.js | ||
regress-crbug-465671.js | ||
regress-lookup-transition.js | ||
regress-observe-empty-double-array.js | ||
regress-typedarray-out-of-bounds.js |