v8/test/mjsunit/bugs
sgjesse@chromium.org a74fcf458c Fixed the step in handling for function.apply.
The generic step-in mechanism floods the function called with break points to ensure a break is hit when entering the function. This generic mechanism was also used for function.apply. The code for function.apply contains a keyed load IC which was patched when stepping into function.apply. However function.apply enteres an internal frame not a JavaScript frame. This caused the logic for returning from the break in function.apply to fail as it forced a jump to the IC on the top JavaScript frame. The top JavaScript frame was the frame for the function calling function.apply not the frame for the apply function. Now returning from the break point in the keyed load IC in the apply code caused a jump to the code for the call IC for the function calling function.apply in the first place. Not a pretty sight.

Step-in now handles function.apply as a separate case where the actual JavaScript function called through apply is flodded with breakpoints instead of the function.apply function.

BUG=269
BUG=8210@chromium.org
Review URL: http://codereview.chromium.org/63055

git-svn-id: http://v8.googlecode.com/svn/branches/bleeding_edge@1683 ce2b1a6d-e550-0410-aec6-3dcde31c8c00
2009-04-07 09:54:53 +00:00
..
bug-222.js Added one test case and moved another. 2009-02-09 08:46:26 +00:00
bug-223.js Added one test case and moved another. 2009-02-09 08:46:26 +00:00
bug-900066.js Changed copyright header from google inc. to v8 project authors. 2008-09-09 20:08:45 +00:00
bug-941049.js Changed copyright header from google inc. to v8 project authors. 2008-09-09 20:08:45 +00:00
bug-1344252.js Revert change 1509 that flush ICs when adding setters on an object or 2009-03-19 15:06:00 +00:00