Merged r19024, r19026 into trunk branch.
Make memento checks more stable. Add filler at the end of new space and check if object and memento are on the same new space page.
Elements field of newly allocated JSArray could be left uninitialized in some cases (fast literal case).
BUG=340124
LOG=N
R=jkummerow@chromium.org, machenbach@chromium.org
Review URL: https://codereview.chromium.org/139133004
git-svn-id: http://v8.googlecode.com/svn/trunk@19029 ce2b1a6d-e550-0410-aec6-3dcde31c8c00
7 files changed