[array] Fix OOB load/stores when underlying FixedArray changed
This CL fixes a bug that allowed OOB read/stores on fastpaths when a comparison function caused the underlying FixedArray to change while keeping the elements kinds and size property on the original JSArray the same. R=jgruber@chromium.org Bug: chromium:852592 Change-Id: I09af357d10e7f41e75241e4c87430fc9aa806f8c Reviewed-on: https://chromium-review.googlesource.com/1104158 Commit-Queue: Simon Zünd <szuend@google.com> Reviewed-by: Jakob Gruber <jgruber@chromium.org> Reviewed-by: Camillo Bruni <cbruni@chromium.org> Cr-Commit-Position: refs/heads/master@{#53811}
Showing
Please
register
or
sign in
to comment