[csa] Fully initialize elements for large JSArray allocations
This fixes an issue introduced in https://crrev.com/c/1301483. The JSArray allocation could trigger GC and thus elements must be fully initialized. Bug: v8:8429,chromium:890599 Change-Id: I7bfa1728c1dde7fc880063e095413163b13be2d5 Reviewed-on: https://chromium-review.googlesource.com/c/1322955Reviewed-by: Camillo Bruni <cbruni@chromium.org> Commit-Queue: Jakob Gruber <jgruber@chromium.org> Cr-Commit-Position: refs/heads/master@{#57342}
Showing
Please
register
or
sign in
to comment