deps: cherry-pick 88f8fe1 from upstream V8
Original commit message:
Fix collection iterator preview with deleted entries
We used to assume that we know the remaining entries returned by the
iterator based on the current index. However, that is not accurate,
since entries skipped by the current index could be deleted.
In the new approach, we allocate conservatively and shrink the result.
R=neis@chromium.org
Bug: v8:8433
Change-Id: I38a3004dc3af292daabb454bb76f38d65ef437e8
Reviewed-on: https://chromium-review.googlesource.com/c/1325966
Commit-Queue: Yang Guo <yangguo@chromium.org>
Reviewed-by:
Georg Neis <neis@chromium.org>
Cr-Commit-Position: refs/heads/master@{#57360}
[The backport to v10.x resolves merge conflicts due to a different way
of accessing the “hole” value in V8, different signatures of the
`Handle` constructor and the `Shrink()` method, and neighbouring-line
conflicts in the test file.]
Refs: https://github.com/v8/v8/commit/88f8fe19a863c6392bd296faf86c06eff2a41bc1
Fixes: https://github.com/nodejs/node/issues/27882
Backport-PR-URL: https://github.com/nodejs/node/pull/27894
PR-URL: https://github.com/nodejs/node/pull/24514
Refs: https://github.com/nodejs/node/issues/24053
Reviewed-By:
Michaël Zasso <targos@protonmail.com>
Reviewed-By:
Anna Henningsen <anna@addaleax.net>
Reviewed-By:
Gus Caplan <me@gus.host>
Reviewed-By:
Joyee Cheung <joyeec9h3@gmail.com>
parent
cc3ca080
Please register or sign in to comment