[api] Canonicalize hole-NaN in DictionaryTemplateInfo::NewInstance When reusing a cached Map with double representation in DictionaryTemplateInfo::NewInstance, ensure that incoming float64 values matching the kHoleNanInt64 bit pattern are canonicalized to quiet NaN before being stored into the fresh HeapNumber. Const double fields in V8 must never contain kHoleNanInt64, as that pattern serves as the uninitialized field sentinel (is_the_hole()). Storing an uncanonicalized hole-NaN value allows subsequent field stores to be mistaken for initializing stores, violating constant tracking and bypassing deoptimization. TAG=agy CONV=df226a09-a1a8-4333-80b4-d95312eb98eb Fixed: 545008200 Change-Id: Ie90c72a71c96e7bcbbddd2608f426ce12eeca370 Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/8261258 Reviewed-by: Leszek Swirski <leszeks@chromium.org> Auto-Submit: Igor Sheludko <ishell@chromium.org> Commit-Queue: Igor Sheludko <ishell@chromium.org> Cr-Commit-Position: refs/heads/main@{#109441}
V8 is Google's open source JavaScript engine.
V8 implements ECMAScript as specified in ECMA-262.
V8 is written in C++ and is used in Chromium, the open source browser from Google.
V8 can run standalone, or can be embedded into any C++ application.
V8 Project page: https://v8.dev/docs
Checkout depot tools, and run
fetch v8
This will checkout V8 into the directory v8 and fetch all of its dependencies. To stay up to date, run
git pull origin
gclient sync
For fetching all branches, add the following into your remote configuration in .git/config:
fetch = +refs/branch-heads/*:refs/remotes/branch-heads/*
fetch = +refs/tags/*:refs/tags/*
Please follow the instructions mentioned at v8.dev/docs/contribute.