• jbroman's avatar
    Initialize internal fields in Factory::NewJSTypedArray and NewJSDataView. · 879f6599
    jbroman authored
    This was causing array buffer views created by ValueDeserializer to have
    uninitialized internal fields, which lead to crashes in layout tests when
    Blink tried to read those fields.
    
    For array buffers, JSArrayBuffer::Setup is responsible for this logic
    (as well as initializing the V8 fields); this is similar to that.
    
    The runtime already seems to correctly initialize these for script-created
    array buffer views as well, which is why this issue was not detected sooner.
    
    Review-Url: https://codereview.chromium.org/2498413002
    Cr-Commit-Position: refs/heads/master@{#41014}
    879f6599
factory.cc 100 KB