Commit fe6fc554 authored by yangguo@chromium.org's avatar yangguo@chromium.org

Fix slow path of JSON.stringifier when GC strikes.

FlatContent is not GC-safe.

R=verwaest@chromium.org
BUG=

Review URL: https://chromiumcodereview.appspot.com/13782002

git-svn-id: http://v8.googlecode.com/svn/branches/bleeding_edge@14175 ce2b1a6d-e550-0410-aec6-3dcde31c8c00
parent c569d31f
...@@ -295,19 +295,30 @@ MaybeObject* BasicJsonStringifier::StringifyString(Isolate* isolate, ...@@ -295,19 +295,30 @@ MaybeObject* BasicJsonStringifier::StringifyString(Isolate* isolate,
return stringifier.Stringify(object); return stringifier.Stringify(object);
} }
FlattenString(object); object = FlattenGetString(object);
String::FlatContent flat = object->GetFlatContent(); ASSERT(object->IsFlat());
if (flat.IsAscii()) { if (object->IsOneByteRepresentation()) {
Handle<String> result =
isolate->factory()->NewRawOneByteString(worst_case_length);
AssertNoAllocation no_alloc;
const uint8_t* start = object->IsSeqOneByteString()
? SeqOneByteString::cast(*object)->GetChars()
: ExternalAsciiString::cast(*object)->GetChars();
return StringifyString_<SeqOneByteString>( return StringifyString_<SeqOneByteString>(
isolate, isolate,
flat.ToOneByteVector(), Vector<const uint8_t>(start, object->length()),
isolate->factory()->NewRawOneByteString(worst_case_length)); result);
} else { } else {
ASSERT(flat.IsTwoByte()); Handle<String> result =
isolate->factory()->NewRawTwoByteString(worst_case_length);
AssertNoAllocation no_alloc;
const uc16* start = object->IsSeqTwoByteString()
? SeqTwoByteString::cast(*object)->GetChars()
: ExternalTwoByteString::cast(*object)->GetChars();
return StringifyString_<SeqTwoByteString>( return StringifyString_<SeqTwoByteString>(
isolate, isolate,
flat.ToUC16Vector(), Vector<const uc16>(start, object->length()),
isolate->factory()->NewRawTwoByteString(worst_case_length)); result);
} }
} }
......
...@@ -39,3 +39,13 @@ json1 = JSON.stringify(a); ...@@ -39,3 +39,13 @@ json1 = JSON.stringify(a);
json2 = JSON.stringify(a); json2 = JSON.stringify(a);
assertTrue(json1 == json2, "GC caused JSON.stringify to fail."); assertTrue(json1 == json2, "GC caused JSON.stringify to fail.");
// Check that the slow path of JSON.stringify works correctly wrt GC.
for (var i = 0; i < 100000; i++) {
var s = i.toString();
assertEquals('"' + s + '"', JSON.stringify(s, null, 0));
}
for (var i = 0; i < 100000; i++) {
var s = i.toString() + "\u2603";
assertEquals('"' + s + '"', JSON.stringify(s, null, 0));
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment