1
0
Fork 0
mirror of https://github.com/LadybirdBrowser/ladybird.git synced 2025-06-08 05:27:14 +09:00
ladybird/Libraries/LibJS/Runtime/SetIterator.cpp
Aliaksandr Kalenik 285bc005cb LibJS: Do more comprehensive check if next() fast path is possible
Before this change each built-in iterator object has a boolean
`m_next_method_was_redefined`. If user code later changed the iterator’s
prototype (e.g. `Object.setPrototypeOf()`), we still believed the
built-in fast-path was safe and skipped the user supplied override,
producing wrong results.

With this change
`BuiltinIterator::as_builtin_iterator_if_next_is_not_redefined()` looks
up the current `next` property and verifies that it is still the
built-in native function.
2025-06-02 00:15:36 +02:00

74 lines
2 KiB
C++

/*
* Copyright (c) 2021, Idan Horowitz <idan.horowitz@serenityos.org>
*
* SPDX-License-Identifier: BSD-2-Clause
*/
#include <LibJS/Runtime/Array.h>
#include <LibJS/Runtime/NativeFunction.h>
#include <LibJS/Runtime/SetIterator.h>
namespace JS {
GC_DEFINE_ALLOCATOR(SetIterator);
GC::Ref<SetIterator> SetIterator::create(Realm& realm, Set& set, Object::PropertyKind iteration_kind)
{
return realm.create<SetIterator>(set, iteration_kind, realm.intrinsics().set_iterator_prototype());
}
SetIterator::SetIterator(Set& set, Object::PropertyKind iteration_kind, Object& prototype)
: Object(ConstructWithPrototypeTag::Tag, prototype)
, m_set(set)
, m_iteration_kind(iteration_kind)
, m_iterator(static_cast<Set const&>(set).begin())
{
}
void SetIterator::visit_edges(Cell::Visitor& visitor)
{
Base::visit_edges(visitor);
visitor.visit(m_set);
}
BuiltinIterator* SetIterator::as_builtin_iterator_if_next_is_not_redefined(IteratorRecord const& iterator_record)
{
if (iterator_record.next_method.is_object()) {
auto const& next_function = iterator_record.next_method.as_object();
if (next_function.is_native_function()) {
auto const& native_function = static_cast<NativeFunction const&>(next_function);
if (native_function.is_set_prototype_next_builtin())
return this;
}
}
return nullptr;
}
ThrowCompletionOr<void> SetIterator::next(VM& vm, bool& done, Value& value)
{
if (m_done) {
done = true;
value = js_undefined();
return {};
}
if (m_iterator == m_set->end()) {
m_done = true;
done = true;
value = js_undefined();
return {};
}
VERIFY(m_iteration_kind != Object::PropertyKind::Key);
value = (*m_iterator).key;
++m_iterator;
if (m_iteration_kind == Object::PropertyKind::Value) {
return {};
}
value = Array::create_from(*vm.current_realm(), { value, value });
return {};
}
}