#define JSCell_h
#include "CallData.h"
-#include "CallFrame.h"
#include "ConstructData.h"
+#include "EnumerationMode.h"
#include "Heap.h"
+#include "IndexingType.h"
#include "JSLock.h"
-#include "JSValueInlineMethods.h"
-#include "MarkStack.h"
+#include "JSTypeInfo.h"
+#include "SlotVisitor.h"
+#include "TypedArrayType.h"
#include "WriteBarrier.h"
#include <wtf/Noncopyable.h>
namespace JSC {
- class JSGlobalObject;
- class Structure;
-
-#if COMPILER(MSVC)
- // If WTF_MAKE_NONCOPYABLE is applied to JSCell we end up with a bunch of
- // undefined references to the JSCell copy constructor and assignment operator
- // when linking JavaScriptCore.
- class MSVCBugWorkaround {
- WTF_MAKE_NONCOPYABLE(MSVCBugWorkaround);
-
- protected:
- MSVCBugWorkaround() { }
- ~MSVCBugWorkaround() { }
- };
-
- class JSCell : MSVCBugWorkaround {
-#else
- class JSCell {
- WTF_MAKE_NONCOPYABLE(JSCell);
-#endif
-
- friend class ExecutableBase;
- friend class GetterSetter;
- friend class Heap;
- friend class JSObject;
- friend class JSPropertyNameIterator;
- friend class JSString;
- friend class JSValue;
- friend class JSAPIValueWrapper;
- friend class JSZombie;
- friend class JSGlobalData;
- friend class MarkedSpace;
- friend class MarkedBlock;
- friend class ScopeChainNode;
- friend class Structure;
- friend class StructureChain;
- friend class RegExp;
- enum CreatingEarlyCellTag { CreatingEarlyCell };
-
- protected:
- enum VPtrStealingHackType { VPtrStealingHack };
-
- private:
- explicit JSCell(VPtrStealingHackType) { }
- JSCell(JSGlobalData&, Structure*);
- JSCell(JSGlobalData&, Structure*, CreatingEarlyCellTag);
- virtual ~JSCell();
- static const ClassInfo s_dummyCellInfo;
-
- public:
- static Structure* createDummyStructure(JSGlobalData&);
-
- // Querying the type.
- bool isString() const;
- bool isObject() const;
- virtual bool isGetterSetter() const;
- bool inherits(const ClassInfo*) const;
- virtual bool isAPIValueWrapper() const { return false; }
- virtual bool isPropertyNameIterator() const { return false; }
-
- Structure* structure() const;
-
- // Extracting the value.
- bool getString(ExecState* exec, UString&) const;
- UString getString(ExecState* exec) const; // null string if not a string
- JSObject* getObject(); // NULL if not an object
- const JSObject* getObject() const; // NULL if not an object
+class CopyVisitor;
+class ExecState;
+class Identifier;
+class JSArrayBufferView;
+class JSDestructibleObject;
+class JSGlobalObject;
+class LLIntOffsetsExtractor;
+class PropertyDescriptor;
+class PropertyNameArray;
+class Structure;
+
+template<typename T> void* allocateCell(Heap&);
+template<typename T> void* allocateCell(Heap&, size_t);
+
+#define DECLARE_EXPORT_INFO \
+ protected: \
+ static JS_EXPORTDATA const ::JSC::ClassInfo s_info; \
+ public: \
+ static const ::JSC::ClassInfo* info() { return &s_info; }
+
+#define DECLARE_INFO \
+ protected: \
+ static const ::JSC::ClassInfo s_info; \
+ public: \
+ static const ::JSC::ClassInfo* info() { return &s_info; }
+
+class JSCell {
+ friend class JSValue;
+ friend class MarkedBlock;
+ template<typename T> friend void* allocateCell(Heap&);
+ template<typename T> friend void* allocateCell(Heap&, size_t);
+
+public:
+ static const unsigned StructureFlags = 0;
+
+ static const bool needsDestruction = false;
+
+ static JSCell* seenMultipleCalleeObjects() { return bitwise_cast<JSCell*>(static_cast<uintptr_t>(1)); }
+
+ enum CreatingEarlyCellTag { CreatingEarlyCell };
+ JSCell(CreatingEarlyCellTag);
+
+protected:
+ JSCell(VM&, Structure*);
+ JS_EXPORT_PRIVATE static void destroy(JSCell*);
+
+public:
+ // Querying the type.
+ bool isString() const;
+ bool isSymbol() const;
+ bool isObject() const;
+ bool isGetterSetter() const;
+ bool isCustomGetterSetter() const;
+ bool isProxy() const;
+ bool inherits(const ClassInfo*) const;
+ bool isAPIValueWrapper() const;
+
+ JSType type() const;
+ IndexingType indexingType() const;
+ StructureID structureID() const { return m_structureID; }
+ Structure* structure() const;
+ Structure* structure(VM&) const;
+ void setStructure(VM&, Structure*);
+ void clearStructure() { m_structureID = 0; }
+
+ TypeInfo::InlineTypeFlags inlineTypeFlags() const { return m_flags; }
+
+ const char* className() const;
+
+ VM* vm() const;
+
+ // Extracting the value.
+ JS_EXPORT_PRIVATE bool getString(ExecState*, String&) const;
+ JS_EXPORT_PRIVATE String getString(ExecState*) const; // null string if not a string
+ JS_EXPORT_PRIVATE JSObject* getObject(); // NULL if not an object
+ const JSObject* getObject() const; // NULL if not an object
- virtual CallType getCallData(CallData&);
- virtual ConstructType getConstructData(ConstructData&);
-
- // Extracting integer values.
- // FIXME: remove these methods, can check isNumberCell in JSValue && then call asNumberCell::*.
- virtual bool getUInt32(uint32_t&) const;
-
- // Basic conversions.
- virtual JSValue toPrimitive(ExecState*, PreferredPrimitiveType) const;
- virtual bool getPrimitiveNumber(ExecState*, double& number, JSValue&);
- virtual bool toBoolean(ExecState*) const;
- virtual double toNumber(ExecState*) const;
- virtual UString toString(ExecState*) const;
- virtual JSObject* toObject(ExecState*, JSGlobalObject*) const;
-
- // Garbage collection.
- void* operator new(size_t, ExecState*);
- void* operator new(size_t, JSGlobalData*);
- void* operator new(size_t, void* placementNewDestination) { return placementNewDestination; }
-
- virtual void visitChildren(SlotVisitor&);
-#if ENABLE(JSC_ZOMBIES)
- virtual bool isZombie() const { return false; }
-#endif
-
- // Object operations, with the toObject operation included.
- const ClassInfo* classInfo() const;
- virtual void put(ExecState*, const Identifier& propertyName, JSValue, PutPropertySlot&);
- virtual void put(ExecState*, unsigned propertyName, JSValue);
- virtual bool deleteProperty(ExecState*, const Identifier& propertyName);
- virtual bool deleteProperty(ExecState*, unsigned propertyName);
-
- virtual JSObject* toThisObject(ExecState*) const;
- virtual JSValue getJSNumber();
- void* vptr() { return *reinterpret_cast<void**>(this); }
- void setVPtr(void* vptr) { *reinterpret_cast<void**>(this) = vptr; }
-
- // FIXME: Rename getOwnPropertySlot to virtualGetOwnPropertySlot, and
- // fastGetOwnPropertySlot to getOwnPropertySlot. Callers should always
- // call this function, not its slower virtual counterpart. (For integer
- // property names, we want a similar interface with appropriate optimizations.)
- bool fastGetOwnPropertySlot(ExecState*, const Identifier& propertyName, PropertySlot&);
-
- static ptrdiff_t structureOffset()
- {
- return OBJECT_OFFSETOF(JSCell, m_structure);
- }
-
-#if ENABLE(GC_VALIDATION)
- Structure* unvalidatedStructure() { return m_structure.unvalidatedGet(); }
-#endif
+ // Returns information about how to call/construct this cell as a function/constructor. May tell
+ // you that the cell is not callable or constructor (default is that it's not either). If it
+ // says that the function is callable, and the TypeOfShouldCallGetCallData type flag is set, and
+ // this is an object, then typeof will return "function" instead of "object". These methods
+ // cannot change their minds and must be thread-safe. They are sometimes called from compiler
+ // threads.
+ JS_EXPORT_PRIVATE static CallType getCallData(JSCell*, CallData&);
+ JS_EXPORT_PRIVATE static ConstructType getConstructData(JSCell*, ConstructData&);
+
+ // Basic conversions.
+ JS_EXPORT_PRIVATE JSValue toPrimitive(ExecState*, PreferredPrimitiveType) const;
+ bool getPrimitiveNumber(ExecState*, double& number, JSValue&) const;
+ bool toBoolean(ExecState*) const;
+ TriState pureToBoolean() const;
+ JS_EXPORT_PRIVATE double toNumber(ExecState*) const;
+ JS_EXPORT_PRIVATE JSObject* toObject(ExecState*, JSGlobalObject*) const;
+
+ void dump(PrintStream&) const;
+ JS_EXPORT_PRIVATE static void dumpToStream(const JSCell*, PrintStream&);
+ static void visitChildren(JSCell*, SlotVisitor&);
+ JS_EXPORT_PRIVATE static void copyBackingStore(JSCell*, CopyVisitor&, CopyToken);
+
+ // Object operations, with the toObject operation included.
+ const ClassInfo* classInfo() const;
+ const MethodTable* methodTable() const;
+ const MethodTable* methodTable(VM&) const;
+ static void put(JSCell*, ExecState*, PropertyName, JSValue, PutPropertySlot&);
+ static void putByIndex(JSCell*, ExecState*, unsigned propertyName, JSValue, bool shouldThrow);
- protected:
- static const unsigned AnonymousSlotCount = 0;
-
- private:
- // Base implementation; for non-object classes implements getPropertySlot.
- virtual bool getOwnPropertySlot(ExecState*, const Identifier& propertyName, PropertySlot&);
- virtual bool getOwnPropertySlot(ExecState*, unsigned propertyName, PropertySlot&);
-
- WriteBarrier<Structure> m_structure;
- };
-
- inline JSCell::JSCell(JSGlobalData& globalData, Structure* structure)
- : m_structure(globalData, this, structure)
- {
- ASSERT(m_structure);
- }
+ static bool deleteProperty(JSCell*, ExecState*, PropertyName);
+ static bool deletePropertyByIndex(JSCell*, ExecState*, unsigned propertyName);
- inline JSCell::JSCell(JSGlobalData& globalData, Structure* structure, CreatingEarlyCellTag)
- {
-#if ENABLE(GC_VALIDATION)
- if (structure)
-#endif
- m_structure.setEarlyValue(globalData, this, structure);
- // Very first set of allocations won't have a real structure.
- ASSERT(m_structure || !globalData.dummyMarkableCellStructure);
- }
+ static JSValue toThis(JSCell*, ExecState*, ECMAMode);
- inline JSCell::~JSCell()
- {
-#if ENABLE(GC_VALIDATION)
- m_structure.clear();
-#endif
- }
+ void zap() { *reinterpret_cast<uintptr_t**>(this) = 0; }
+ bool isZapped() const { return !*reinterpret_cast<uintptr_t* const*>(this); }
- inline Structure* JSCell::structure() const
- {
- return m_structure.get();
- }
+ static bool canUseFastGetOwnProperty(const Structure&);
+ JSValue fastGetOwnProperty(VM&, Structure&, PropertyName);
- inline void JSCell::visitChildren(SlotVisitor& visitor)
- {
- visitor.append(&m_structure);
- }
+ enum GCData : uint8_t {
+ Marked = 0, // The object has survived a GC and is in the old gen.
+ NotMarked = 1, // The object is new and in the eden gen.
+ MarkedAndRemembered = 2, // The object is in the GC's remembered set.
- // --- JSValue inlines ----------------------------
-
- inline bool JSValue::isString() const
- {
- return isCell() && asCell()->isString();
- }
-
- inline bool JSValue::isGetterSetter() const
- {
- return isCell() && asCell()->isGetterSetter();
- }
-
- inline bool JSValue::isObject() const
- {
- return isCell() && asCell()->isObject();
- }
-
- inline bool JSValue::getString(ExecState* exec, UString& s) const
- {
- return isCell() && asCell()->getString(exec, s);
- }
-
- inline UString JSValue::getString(ExecState* exec) const
- {
- return isCell() ? asCell()->getString(exec) : UString();
- }
-
- template <typename Base> UString HandleConverter<Base, Unknown>::getString(ExecState* exec) const
- {
- return jsValue().getString(exec);
- }
-
- inline JSObject* JSValue::getObject() const
- {
- return isCell() ? asCell()->getObject() : 0;
- }
-
- inline CallType getCallData(JSValue value, CallData& callData)
- {
- CallType result = value.isCell() ? value.asCell()->getCallData(callData) : CallTypeNone;
- ASSERT(result == CallTypeNone || value.isValidCallee());
- return result;
- }
+ // The object being in the GC's remembered set implies that it is also
+ // Marked. This is because objects are only added to the remembered sets
+ // by write barriers, and write barriers are only interested in old gen
+ // objects that point to potential eden gen objects.
+ };
- inline ConstructType getConstructData(JSValue value, ConstructData& constructData)
+ void setMarked() { m_gcData = Marked; }
+ void setRemembered(bool remembered)
{
- ConstructType result = value.isCell() ? value.asCell()->getConstructData(constructData) : ConstructTypeNone;
- ASSERT(result == ConstructTypeNone || value.isValidCallee());
- return result;
+ ASSERT(m_gcData == (remembered ? Marked : MarkedAndRemembered));
+ m_gcData = remembered ? MarkedAndRemembered : Marked;
}
-
- ALWAYS_INLINE bool JSValue::getUInt32(uint32_t& v) const
+ bool isMarked() const
{
- if (isInt32()) {
- int32_t i = asInt32();
- v = static_cast<uint32_t>(i);
- return i >= 0;
- }
- if (isDouble()) {
- double d = asDouble();
- v = static_cast<uint32_t>(d);
- return v == d;
+ switch (m_gcData) {
+ case Marked:
+ case MarkedAndRemembered:
+ return true;
+ case NotMarked:
+ return false;
}
+ RELEASE_ASSERT_NOT_REACHED();
return false;
}
+ bool isRemembered() const { return m_gcData == MarkedAndRemembered; }
- inline JSValue JSValue::toPrimitive(ExecState* exec, PreferredPrimitiveType preferredType) const
+ static ptrdiff_t structureIDOffset()
{
- return isCell() ? asCell()->toPrimitive(exec, preferredType) : asValue();
+ return OBJECT_OFFSETOF(JSCell, m_structureID);
}
- inline bool JSValue::getPrimitiveNumber(ExecState* exec, double& number, JSValue& value)
+ static ptrdiff_t typeInfoFlagsOffset()
{
- if (isInt32()) {
- number = asInt32();
- value = *this;
- return true;
- }
- if (isDouble()) {
- number = asDouble();
- value = *this;
- return true;
- }
- if (isCell())
- return asCell()->getPrimitiveNumber(exec, number, value);
- if (isTrue()) {
- number = 1.0;
- value = *this;
- return true;
- }
- if (isFalse() || isNull()) {
- number = 0.0;
- value = *this;
- return true;
- }
- ASSERT(isUndefined());
- number = nonInlineNaN();
- value = *this;
- return true;
+ return OBJECT_OFFSETOF(JSCell, m_flags);
}
- inline bool JSValue::toBoolean(ExecState* exec) const
+ static ptrdiff_t typeInfoTypeOffset()
{
- if (isInt32())
- return asInt32() != 0;
- if (isDouble())
- return asDouble() > 0.0 || asDouble() < 0.0; // false for NaN
- if (isCell())
- return asCell()->toBoolean(exec);
- return isTrue(); // false, null, and undefined all convert to false.
+ return OBJECT_OFFSETOF(JSCell, m_type);
}
- ALWAYS_INLINE double JSValue::toNumber(ExecState* exec) const
+ static ptrdiff_t indexingTypeOffset()
{
- if (isInt32())
- return asInt32();
- if (isDouble())
- return asDouble();
- if (isCell())
- return asCell()->toNumber(exec);
- if (isTrue())
- return 1.0;
- return isUndefined() ? nonInlineNaN() : 0; // null and false both convert to 0.
+ return OBJECT_OFFSETOF(JSCell, m_indexingType);
}
- inline JSValue JSValue::getJSNumber()
+ static ptrdiff_t gcDataOffset()
{
- if (isInt32() || isDouble())
- return *this;
- if (isCell())
- return asCell()->getJSNumber();
- return JSValue();
+ return OBJECT_OFFSETOF(JSCell, m_gcData);
}
- inline JSObject* JSValue::toObject(ExecState* exec) const
- {
- return isCell() ? asCell()->toObject(exec, exec->lexicalGlobalObject()) : toObjectSlowCase(exec, exec->lexicalGlobalObject());
- }
+ static const TypedArrayType TypedArrayStorageType = NotTypedArray;
+protected:
- inline JSObject* JSValue::toObject(ExecState* exec, JSGlobalObject* globalObject) const
- {
- return isCell() ? asCell()->toObject(exec, globalObject) : toObjectSlowCase(exec, globalObject);
- }
+ void finishCreation(VM&);
+ void finishCreation(VM&, Structure*, CreatingEarlyCellTag);
- inline JSObject* JSValue::toThisObject(ExecState* exec) const
- {
- return isCell() ? asCell()->toThisObject(exec) : toThisObjectSlowCase(exec);
- }
+ // Dummy implementations of override-able static functions for classes to put in their MethodTable
+ static JSValue defaultValue(const JSObject*, ExecState*, PreferredPrimitiveType);
+ static NO_RETURN_DUE_TO_CRASH void getOwnPropertyNames(JSObject*, ExecState*, PropertyNameArray&, EnumerationMode);
+ static NO_RETURN_DUE_TO_CRASH void getOwnNonIndexPropertyNames(JSObject*, ExecState*, PropertyNameArray&, EnumerationMode);
+ static NO_RETURN_DUE_TO_CRASH void getPropertyNames(JSObject*, ExecState*, PropertyNameArray&, EnumerationMode);
- inline Heap* Heap::heap(JSValue v)
- {
- if (!v.isCell())
- return 0;
- return heap(v.asCell());
- }
+ static uint32_t getEnumerableLength(ExecState*, JSObject*);
+ static NO_RETURN_DUE_TO_CRASH void getStructurePropertyNames(JSObject*, ExecState*, PropertyNameArray&, EnumerationMode);
+ static NO_RETURN_DUE_TO_CRASH void getGenericPropertyNames(JSObject*, ExecState*, PropertyNameArray&, EnumerationMode);
- inline Heap* Heap::heap(JSCell* c)
- {
- return MarkedSpace::heap(c);
- }
-
-#if ENABLE(JSC_ZOMBIES)
- inline bool JSValue::isZombie() const
- {
- return isCell() && asCell() > (JSCell*)0x1ffffffffL && asCell()->isZombie();
- }
-#endif
+ static String className(const JSObject*);
+ JS_EXPORT_PRIVATE static bool customHasInstance(JSObject*, ExecState*, JSValue);
+ static bool defineOwnProperty(JSObject*, ExecState*, PropertyName, const PropertyDescriptor&, bool shouldThrow);
+ static bool getOwnPropertySlot(JSObject*, ExecState*, PropertyName, PropertySlot&);
+ static bool getOwnPropertySlotByIndex(JSObject*, ExecState*, unsigned propertyName, PropertySlot&);
+ JS_EXPORT_PRIVATE static ArrayBuffer* slowDownAndWasteMemory(JSArrayBufferView*);
+ JS_EXPORT_PRIVATE static PassRefPtr<ArrayBufferView> getTypedArrayImpl(JSArrayBufferView*);
- inline void* MarkedBlock::allocate()
- {
- while (m_nextAtom < m_endAtom) {
- if (!m_marks.testAndSet(m_nextAtom)) {
- JSCell* cell = reinterpret_cast<JSCell*>(&atoms()[m_nextAtom]);
- m_nextAtom += m_atomsPerCell;
- cell->~JSCell();
- return cell;
- }
- m_nextAtom += m_atomsPerCell;
- }
+private:
+ friend class LLIntOffsetsExtractor;
- return 0;
- }
-
- inline MarkedSpace::SizeClass& MarkedSpace::sizeClassFor(size_t bytes)
- {
- ASSERT(bytes && bytes < maxCellSize);
- if (bytes < preciseCutoff)
- return m_preciseSizeClasses[(bytes - 1) / preciseStep];
- return m_impreciseSizeClasses[(bytes - 1) / impreciseStep];
- }
+ StructureID m_structureID;
+ IndexingType m_indexingType;
+ JSType m_type;
+ TypeInfo::InlineTypeFlags m_flags;
+ uint8_t m_gcData;
+};
- inline void* MarkedSpace::allocate(size_t bytes)
- {
- SizeClass& sizeClass = sizeClassFor(bytes);
- return allocateFromSizeClass(sizeClass);
- }
+template<typename To, typename From>
+inline To jsCast(From* from)
+{
+ ASSERT_WITH_SECURITY_IMPLICATION(!from || from->JSCell::inherits(std::remove_pointer<To>::type::info()));
+ return static_cast<To>(from);
+}
- inline void* Heap::allocate(size_t bytes)
- {
- ASSERT(globalData()->identifierTable == wtfThreadData().currentIdentifierTable());
- ASSERT(JSLock::lockCount() > 0);
- ASSERT(JSLock::currentThreadIsHoldingLock());
- ASSERT(bytes <= MarkedSpace::maxCellSize);
- ASSERT(m_operationInProgress == NoOperation);
-
- m_operationInProgress = Allocation;
- void* result = m_markedSpace.allocate(bytes);
- m_operationInProgress = NoOperation;
- if (result)
- return result;
-
- return allocateSlowCase(bytes);
- }
-
- inline void* JSCell::operator new(size_t size, JSGlobalData* globalData)
- {
- JSCell* result = static_cast<JSCell*>(globalData->heap.allocate(size));
- result->m_structure.clear();
- return result;
- }
-
- inline void* JSCell::operator new(size_t size, ExecState* exec)
- {
- JSCell* result = static_cast<JSCell*>(exec->heap()->allocate(size));
- result->m_structure.clear();
- return result;
- }
+template<typename To>
+inline To jsCast(JSValue from)
+{
+ ASSERT_WITH_SECURITY_IMPLICATION(from.isCell() && from.asCell()->JSCell::inherits(std::remove_pointer<To>::type::info()));
+ return static_cast<To>(from.asCell());
+}
+
+template<typename To, typename From>
+inline To jsDynamicCast(From* from)
+{
+ if (LIKELY(from->inherits(std::remove_pointer<To>::type::info())))
+ return static_cast<To>(from);
+ return nullptr;
+}
+
+template<typename To>
+inline To jsDynamicCast(JSValue from)
+{
+ if (LIKELY(from.isCell() && from.asCell()->inherits(std::remove_pointer<To>::type::info())))
+ return static_cast<To>(from.asCell());
+ return nullptr;
+}
} // namespace JSC