File: internalClassParentGc.js

package info (click to toggle)
qt6-declarative 6.9.1%2Bdfsg-1
  • links: PTS, VCS
  • area: main
  • in suites: experimental
  • size: 308,920 kB
  • sloc: cpp: 775,911; javascript: 514,247; xml: 10,855; python: 2,806; ansic: 2,253; java: 810; sh: 262; makefile: 41; php: 27
file content (29 lines) | stat: -rw-r--r-- 856 bytes parent folder | download | duplicates (7)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
function init() {
    Array.prototype.doPush = Array.prototype.push
}

function nasty() {
    var sc_Vector = Array;
    var push = sc_Vector.prototype.doPush;

    // Change the memberData to hold something nasty on the current internalClass
    sc_Vector.prototype.doPush = 5;

    // Trigger a re-allocation of memberData
    for (var i = 0; i < 256; ++i)
        sc_Vector.prototype[i + "string"] = function() { return 98; }

    // Change the (new) memberData back, to hold our doPush function again.
    // This should propagate a protoId change all the way up to the lookup.
    sc_Vector.prototype.doPush = push;
}

function func() {
    var b = [];

    // This becomes a lookup internally, which stores protoId and a pointer
    // into the memberData. It should get invalidated when memberData is re-allocated.
    b.doPush(3);

    return b;
}