<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[209101] trunk/Source/JavaScriptCore</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta">
<dt>Revision</dt> <dd><a href="http://trac.webkit.org/projects/webkit/changeset/209101">209101</a></dd>
<dt>Author</dt> <dd>mark.lam@apple.com</dd>
<dt>Date</dt> <dd>2016-11-29 16:06:50 -0800 (Tue, 29 Nov 2016)</dd>
</dl>

<h3>Log Message</h3>
<pre>Fix exception scope verification failures in runtime/RegExp* files.
https://bugs.webkit.org/show_bug.cgi?id=165054

Reviewed by Saam Barati.

Also replaced returning JSValue() with returning { }.

* runtime/RegExpConstructor.cpp:
(JSC::toFlags):
(JSC::regExpCreate):
(JSC::constructRegExp):
* runtime/RegExpObject.cpp:
(JSC::RegExpObject::defineOwnProperty):
(JSC::collectMatches):
(JSC::RegExpObject::matchGlobal):
* runtime/RegExpObjectInlines.h:
(JSC::getRegExpObjectLastIndexAsUnsigned):
(JSC::RegExpObject::execInline):
(JSC::RegExpObject::matchInline):
* runtime/RegExpPrototype.cpp:
(JSC::regExpProtoFuncCompile):
(JSC::flagsString):
(JSC::regExpProtoFuncToString):
(JSC::regExpProtoFuncSplitFast):</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#trunkSourceJavaScriptCoreChangeLog">trunk/Source/JavaScriptCore/ChangeLog</a></li>
<li><a href="#trunkSourceJavaScriptCoreruntimeRegExpConstructorcpp">trunk/Source/JavaScriptCore/runtime/RegExpConstructor.cpp</a></li>
<li><a href="#trunkSourceJavaScriptCoreruntimeRegExpObjectcpp">trunk/Source/JavaScriptCore/runtime/RegExpObject.cpp</a></li>
<li><a href="#trunkSourceJavaScriptCoreruntimeRegExpObjectInlinesh">trunk/Source/JavaScriptCore/runtime/RegExpObjectInlines.h</a></li>
<li><a href="#trunkSourceJavaScriptCoreruntimeRegExpPrototypecpp">trunk/Source/JavaScriptCore/runtime/RegExpPrototype.cpp</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunkSourceJavaScriptCoreChangeLog"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/ChangeLog (209100 => 209101)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/ChangeLog        2016-11-30 00:00:33 UTC (rev 209100)
+++ trunk/Source/JavaScriptCore/ChangeLog        2016-11-30 00:06:50 UTC (rev 209101)
</span><span class="lines">@@ -1,3 +1,30 @@
</span><ins>+2016-11-29  Mark Lam  &lt;mark.lam@apple.com&gt;
+
+        Fix exception scope verification failures in runtime/RegExp* files.
+        https://bugs.webkit.org/show_bug.cgi?id=165054
+
+        Reviewed by Saam Barati.
+
+        Also replaced returning JSValue() with returning { }.
+
+        * runtime/RegExpConstructor.cpp:
+        (JSC::toFlags):
+        (JSC::regExpCreate):
+        (JSC::constructRegExp):
+        * runtime/RegExpObject.cpp:
+        (JSC::RegExpObject::defineOwnProperty):
+        (JSC::collectMatches):
+        (JSC::RegExpObject::matchGlobal):
+        * runtime/RegExpObjectInlines.h:
+        (JSC::getRegExpObjectLastIndexAsUnsigned):
+        (JSC::RegExpObject::execInline):
+        (JSC::RegExpObject::matchInline):
+        * runtime/RegExpPrototype.cpp:
+        (JSC::regExpProtoFuncCompile):
+        (JSC::flagsString):
+        (JSC::regExpProtoFuncToString):
+        (JSC::regExpProtoFuncSplitFast):
+
</ins><span class="cx"> 2016-11-29  Andy Estes  &lt;aestes@apple.com&gt;
</span><span class="cx"> 
</span><span class="cx">         [Cocoa] Enable two clang warnings recommended by Xcode
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreruntimeRegExpConstructorcpp"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/runtime/RegExpConstructor.cpp (209100 => 209101)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/runtime/RegExpConstructor.cpp        2016-11-30 00:00:33 UTC (rev 209100)
+++ trunk/Source/JavaScriptCore/runtime/RegExpConstructor.cpp        2016-11-30 00:06:50 UTC (rev 209101)
</span><span class="lines">@@ -214,11 +214,10 @@
</span><span class="cx"> 
</span><span class="cx">     if (flags.isUndefined())
</span><span class="cx">         return NoFlags;
</span><del>-    JSString* flagsString = flags.toString(exec);
-    ASSERT(scope.exception() || flagsString);
-    if (!flagsString) {
</del><ins>+    JSString* flagsString = flags.toStringOrNull(exec);
+    ASSERT(!!scope.exception() == !flagsString);
+    if (UNLIKELY(!flagsString))
</ins><span class="cx">         return InvalidFlags;
</span><del>-    }
</del><span class="cx"> 
</span><span class="cx">     RegExpFlags result = regExpFlags(flagsString-&gt;value(exec));
</span><span class="cx">     RETURN_IF_EXCEPTION(scope, InvalidFlags);
</span><span class="lines">@@ -236,7 +235,8 @@
</span><span class="cx">     RETURN_IF_EXCEPTION(scope, nullptr);
</span><span class="cx"> 
</span><span class="cx">     RegExpFlags flags = toFlags(exec, flagsArg);
</span><del>-    if (flags == InvalidFlags)
</del><ins>+    ASSERT(!!scope.exception() == (flags == InvalidFlags));
+    if (UNLIKELY(flags == InvalidFlags))
</ins><span class="cx">         return nullptr;
</span><span class="cx"> 
</span><span class="cx">     RegExp* regExp = RegExp::create(vm, pattern, flags);
</span><span class="lines">@@ -257,6 +257,7 @@
</span><span class="cx"> 
</span><span class="cx">     bool isPatternRegExp = patternArg.inherits(RegExpObject::info());
</span><span class="cx">     bool constructAsRegexp = isRegExp(vm, exec, patternArg);
</span><ins>+    RETURN_IF_EXCEPTION(scope, nullptr);
</ins><span class="cx"> 
</span><span class="cx">     if (newTarget.isUndefined() &amp;&amp; constructAsRegexp &amp;&amp; flagsArg.isUndefined()) {
</span><span class="cx">         JSValue constructor = patternArg.get(exec, vm.propertyNames-&gt;constructor);
</span><span class="lines">@@ -274,21 +275,26 @@
</span><span class="cx"> 
</span><span class="cx">         if (!flagsArg.isUndefined()) {
</span><span class="cx">             RegExpFlags flags = toFlags(exec, flagsArg);
</span><ins>+            ASSERT(!!scope.exception() == (flags == InvalidFlags));
</ins><span class="cx">             if (flags == InvalidFlags)
</span><span class="cx">                 return nullptr;
</span><span class="cx">             regExp = RegExp::create(vm, regExp-&gt;pattern(), flags);
</span><span class="cx">         }
</span><span class="cx"> 
</span><del>-        return RegExpObject::create(exec-&gt;vm(), structure, regExp);
</del><ins>+        return RegExpObject::create(vm, structure, regExp);
</ins><span class="cx">     }
</span><span class="cx"> 
</span><span class="cx">     if (constructAsRegexp) {
</span><span class="cx">         JSValue pattern = patternArg.get(exec, vm.propertyNames-&gt;source);
</span><del>-        if (flagsArg.isUndefined())
</del><ins>+        RETURN_IF_EXCEPTION(scope, nullptr);
+        if (flagsArg.isUndefined()) {
</ins><span class="cx">             flagsArg = patternArg.get(exec, vm.propertyNames-&gt;flags);
</span><ins>+            RETURN_IF_EXCEPTION(scope, nullptr);
+        }
</ins><span class="cx">         patternArg = pattern;
</span><span class="cx">     }
</span><span class="cx"> 
</span><ins>+    scope.release();
</ins><span class="cx">     return regExpCreate(exec, globalObject, newTarget, patternArg, flagsArg);
</span><span class="cx"> }
</span><span class="cx"> 
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreruntimeRegExpObjectcpp"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/runtime/RegExpObject.cpp (209100 => 209101)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/runtime/RegExpObject.cpp        2016-11-30 00:00:33 UTC (rev 209100)
+++ trunk/Source/JavaScriptCore/runtime/RegExpObject.cpp        2016-11-30 00:06:50 UTC (rev 209101)
</span><span class="lines">@@ -119,13 +119,16 @@
</span><span class="cx">                 return typeError(exec, scope, shouldThrow, ASCIILiteral(ReadonlyPropertyChangeError));
</span><span class="cx">             return true;
</span><span class="cx">         }
</span><del>-        if (descriptor.value())
</del><ins>+        if (descriptor.value()) {
</ins><span class="cx">             regExp-&gt;setLastIndex(exec, descriptor.value(), false);
</span><ins>+            RETURN_IF_EXCEPTION(scope, false);
+        }
</ins><span class="cx">         if (descriptor.writablePresent() &amp;&amp; !descriptor.writable())
</span><span class="cx">             regExp-&gt;m_lastIndexIsWritable = false;
</span><span class="cx">         return true;
</span><span class="cx">     }
</span><span class="cx"> 
</span><ins>+    scope.release();
</ins><span class="cx">     return Base::defineOwnProperty(object, exec, propertyName, descriptor, shouldThrow);
</span><span class="cx"> }
</span><span class="cx"> 
</span><span class="lines">@@ -179,12 +182,17 @@
</span><span class="cx">     static unsigned maxSizeForDirectPath = 100000;
</span><span class="cx">     
</span><span class="cx">     JSArray* array = constructEmptyArray(exec, nullptr);
</span><del>-    RETURN_IF_EXCEPTION(scope, JSValue());
</del><ins>+    RETURN_IF_EXCEPTION(scope, { });
</ins><span class="cx"> 
</span><ins>+    bool hasException = false;
</ins><span class="cx">     auto iterate = [&amp;] () {
</span><span class="cx">         size_t end = result.end;
</span><span class="cx">         size_t length = end - result.start;
</span><span class="cx">         array-&gt;push(exec, JSRopeString::createSubstringOfResolved(vm, string, result.start, length));
</span><ins>+        if (UNLIKELY(scope.exception())) {
+            hasException = true;
+            return;
+        }
</ins><span class="cx">         if (!length)
</span><span class="cx">             end = fixEnd(end);
</span><span class="cx">         result = constructor-&gt;performMatch(vm, regExp, string, s, end);
</span><span class="lines">@@ -216,9 +224,12 @@
</span><span class="cx">             
</span><span class="cx">             // OK, we have a sensible number of matches. Now we can create them for reals.
</span><span class="cx">             result = savedResult;
</span><del>-            do
</del><ins>+            do {
</ins><span class="cx">                 iterate();
</span><del>-            while (result);
</del><ins>+                ASSERT(!!scope.exception() == hasException);
+                if (UNLIKELY(hasException))
+                    return { };
+            } while (result);
</ins><span class="cx">             
</span><span class="cx">             return array;
</span><span class="cx">         }
</span><span class="lines">@@ -238,7 +249,7 @@
</span><span class="cx">     ASSERT(regExp-&gt;global());
</span><span class="cx"> 
</span><span class="cx">     setLastIndex(exec, 0);
</span><del>-    RETURN_IF_EXCEPTION(scope, JSValue());
</del><ins>+    RETURN_IF_EXCEPTION(scope, { });
</ins><span class="cx"> 
</span><span class="cx">     String s = string-&gt;value(exec);
</span><span class="cx">     RegExpConstructor* regExpConstructor = globalObject-&gt;regExpConstructor();
</span><span class="lines">@@ -245,6 +256,7 @@
</span><span class="cx">     
</span><span class="cx">     if (regExp-&gt;unicode()) {
</span><span class="cx">         unsigned stringLength = s.length();
</span><ins>+        scope.release();
</ins><span class="cx">         return collectMatches(
</span><span class="cx">             vm, exec, string, s, regExpConstructor, regExp,
</span><span class="cx">             [&amp;] (size_t end) -&gt; size_t {
</span><span class="lines">@@ -251,7 +263,8 @@
</span><span class="cx">                 return advanceStringUnicode(s, stringLength, end);
</span><span class="cx">             });
</span><span class="cx">     }
</span><del>-    
</del><ins>+
+    scope.release();
</ins><span class="cx">     return collectMatches(
</span><span class="cx">         vm, exec, string, s, regExpConstructor, regExp,
</span><span class="cx">         [&amp;] (size_t end) -&gt; size_t {
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreruntimeRegExpObjectInlinesh"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/runtime/RegExpObjectInlines.h (209100 => 209101)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/runtime/RegExpObjectInlines.h        2016-11-30 00:00:33 UTC (rev 209100)
+++ trunk/Source/JavaScriptCore/runtime/RegExpObjectInlines.h        2016-11-30 00:06:50 UTC (rev 209101)
</span><span class="lines">@@ -36,17 +36,22 @@
</span><span class="cx"> ALWAYS_INLINE unsigned getRegExpObjectLastIndexAsUnsigned(
</span><span class="cx">     ExecState* exec, RegExpObject* regExpObject, const String&amp; input)
</span><span class="cx"> {
</span><ins>+    VM&amp; vm = exec-&gt;vm();
+    auto scope = DECLARE_THROW_SCOPE(vm);
</ins><span class="cx">     JSValue jsLastIndex = regExpObject-&gt;getLastIndex();
</span><span class="cx">     unsigned lastIndex;
</span><span class="cx">     if (LIKELY(jsLastIndex.isUInt32())) {
</span><span class="cx">         lastIndex = jsLastIndex.asUInt32();
</span><span class="cx">         if (lastIndex &gt; input.length()) {
</span><ins>+            scope.release();
</ins><span class="cx">             regExpObject-&gt;setLastIndex(exec, 0);
</span><span class="cx">             return UINT_MAX;
</span><span class="cx">         }
</span><span class="cx">     } else {
</span><span class="cx">         double doubleLastIndex = jsLastIndex.toInteger(exec);
</span><ins>+        RETURN_IF_EXCEPTION(scope, UINT_MAX);
</ins><span class="cx">         if (doubleLastIndex &lt; 0 || doubleLastIndex &gt; input.length()) {
</span><ins>+            scope.release();
</ins><span class="cx">             regExpObject-&gt;setLastIndex(exec, 0);
</span><span class="cx">             return UINT_MAX;
</span><span class="cx">         }
</span><span class="lines">@@ -63,7 +68,7 @@
</span><span class="cx">     RegExp* regExp = this-&gt;regExp();
</span><span class="cx">     RegExpConstructor* regExpConstructor = globalObject-&gt;regExpConstructor();
</span><span class="cx">     String input = string-&gt;value(exec);
</span><del>-    RETURN_IF_EXCEPTION(scope, JSValue());
</del><ins>+    RETURN_IF_EXCEPTION(scope, { });
</ins><span class="cx"> 
</span><span class="cx">     bool globalOrSticky = regExp-&gt;globalOrSticky();
</span><span class="cx"> 
</span><span class="lines">@@ -70,6 +75,7 @@
</span><span class="cx">     unsigned lastIndex;
</span><span class="cx">     if (globalOrSticky) {
</span><span class="cx">         lastIndex = getRegExpObjectLastIndexAsUnsigned(exec, this, input);
</span><ins>+        ASSERT(!scope.exception() || lastIndex == UINT_MAX);
</ins><span class="cx">         if (lastIndex == UINT_MAX)
</span><span class="cx">             return jsNull();
</span><span class="cx">     } else
</span><span class="lines">@@ -79,6 +85,7 @@
</span><span class="cx">     JSArray* array =
</span><span class="cx">         createRegExpMatchesArray(vm, globalObject, string, input, regExp, lastIndex, result);
</span><span class="cx">     if (!array) {
</span><ins>+        scope.release();
</ins><span class="cx">         if (globalOrSticky)
</span><span class="cx">             setLastIndex(exec, 0);
</span><span class="cx">         return jsNull();
</span><span class="lines">@@ -86,6 +93,7 @@
</span><span class="cx"> 
</span><span class="cx">     if (globalOrSticky)
</span><span class="cx">         setLastIndex(exec, result.end);
</span><ins>+    RETURN_IF_EXCEPTION(scope, { });
</ins><span class="cx">     regExpConstructor-&gt;recordMatch(vm, regExp, string, result);
</span><span class="cx">     return array;
</span><span class="cx"> }
</span><span class="lines">@@ -100,16 +108,18 @@
</span><span class="cx">     RegExp* regExp = this-&gt;regExp();
</span><span class="cx">     RegExpConstructor* regExpConstructor = globalObject-&gt;regExpConstructor();
</span><span class="cx">     String input = string-&gt;value(exec);
</span><del>-    RETURN_IF_EXCEPTION(scope, MatchResult());
</del><ins>+    RETURN_IF_EXCEPTION(scope, { });
</ins><span class="cx"> 
</span><span class="cx">     if (!regExp-&gt;global() &amp;&amp; !regExp-&gt;sticky())
</span><span class="cx">         return regExpConstructor-&gt;performMatch(vm, regExp, string, input, 0);
</span><span class="cx"> 
</span><span class="cx">     unsigned lastIndex = getRegExpObjectLastIndexAsUnsigned(exec, this, input);
</span><ins>+    ASSERT(!scope.exception() || (lastIndex == UINT_MAX));
</ins><span class="cx">     if (lastIndex == UINT_MAX)
</span><span class="cx">         return MatchResult::failed();
</span><span class="cx">     
</span><span class="cx">     MatchResult result = regExpConstructor-&gt;performMatch(vm, regExp, string, input, lastIndex);
</span><ins>+    scope.release();
</ins><span class="cx">     setLastIndex(exec, result.end);
</span><span class="cx">     return result;
</span><span class="cx"> }
</span></span></pre></div>
<a id="trunkSourceJavaScriptCoreruntimeRegExpPrototypecpp"></a>
<div class="modfile"><h4>Modified: trunk/Source/JavaScriptCore/runtime/RegExpPrototype.cpp (209100 => 209101)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/Source/JavaScriptCore/runtime/RegExpPrototype.cpp        2016-11-30 00:00:33 UTC (rev 209100)
+++ trunk/Source/JavaScriptCore/runtime/RegExpPrototype.cpp        2016-11-30 00:06:50 UTC (rev 209101)
</span><span class="lines">@@ -183,6 +183,7 @@
</span><span class="cx">         return throwVMError(exec, scope, createSyntaxError(exec, regExp-&gt;errorMessage()));
</span><span class="cx"> 
</span><span class="cx">     asRegExpObject(thisValue)-&gt;setRegExp(vm, regExp);
</span><ins>+    scope.release();
</ins><span class="cx">     asRegExpObject(thisValue)-&gt;setLastIndex(exec, 0);
</span><span class="cx">     return JSValue::encode(thisValue);
</span><span class="cx"> }
</span><span class="lines">@@ -197,15 +198,15 @@
</span><span class="cx">     VM&amp; vm = exec-&gt;vm();
</span><span class="cx">     auto scope = DECLARE_THROW_SCOPE(vm);
</span><span class="cx"> 
</span><del>-    JSValue globalValue = regexp-&gt;get(exec, exec-&gt;propertyNames().global);
</del><ins>+    JSValue globalValue = regexp-&gt;get(exec, vm.propertyNames-&gt;global);
</ins><span class="cx">     RETURN_IF_EXCEPTION(scope, string);
</span><del>-    JSValue ignoreCaseValue = regexp-&gt;get(exec, exec-&gt;propertyNames().ignoreCase);
</del><ins>+    JSValue ignoreCaseValue = regexp-&gt;get(exec, vm.propertyNames-&gt;ignoreCase);
</ins><span class="cx">     RETURN_IF_EXCEPTION(scope, string);
</span><del>-    JSValue multilineValue = regexp-&gt;get(exec, exec-&gt;propertyNames().multiline);
</del><ins>+    JSValue multilineValue = regexp-&gt;get(exec, vm.propertyNames-&gt;multiline);
</ins><span class="cx">     RETURN_IF_EXCEPTION(scope, string);
</span><del>-    JSValue unicodeValue = regexp-&gt;get(exec, exec-&gt;propertyNames().unicode);
</del><ins>+    JSValue unicodeValue = regexp-&gt;get(exec, vm.propertyNames-&gt;unicode);
</ins><span class="cx">     RETURN_IF_EXCEPTION(scope, string);
</span><del>-    JSValue stickyValue = regexp-&gt;get(exec, exec-&gt;propertyNames().sticky);
</del><ins>+    JSValue stickyValue = regexp-&gt;get(exec, vm.propertyNames-&gt;sticky);
</ins><span class="cx">     RETURN_IF_EXCEPTION(scope, string);
</span><span class="cx"> 
</span><span class="cx">     unsigned index = 0;
</span><span class="lines">@@ -236,6 +237,7 @@
</span><span class="cx">     JSObject* thisObject = asObject(thisValue);
</span><span class="cx"> 
</span><span class="cx">     StringRecursionChecker checker(exec, thisObject);
</span><ins>+    ASSERT(!scope.exception() || checker.earlyReturnValue());
</ins><span class="cx">     if (JSValue earlyReturnValue = checker.earlyReturnValue())
</span><span class="cx">         return JSValue::encode(earlyReturnValue);
</span><span class="cx"> 
</span><span class="lines">@@ -621,8 +623,10 @@
</span><span class="cx">         // b. If z is not null, return A.
</span><span class="cx">         // c. Perform ! CreateDataProperty(A, &quot;0&quot;, S).
</span><span class="cx">         // d. Return A.
</span><del>-        if (!regexp-&gt;match(vm, input, 0))
</del><ins>+        if (!regexp-&gt;match(vm, input, 0)) {
</ins><span class="cx">             result-&gt;putDirectIndex(exec, 0, inputString);
</span><ins>+            RETURN_IF_EXCEPTION(scope, encodedJSValue());
+        }
</ins><span class="cx">         return JSValue::encode(result);
</span><span class="cx">     }
</span><span class="cx"> 
</span><span class="lines">@@ -643,16 +647,19 @@
</span><span class="cx">         },
</span><span class="cx">         [&amp;] (bool isDefined, unsigned start, unsigned length) -&gt; SplitControl {
</span><span class="cx">             result-&gt;putDirectIndex(exec, resultLength++, isDefined ? JSRopeString::createSubstringOfResolved(vm, inputString, start, length) : jsUndefined());
</span><ins>+            RETURN_IF_EXCEPTION(scope, AbortSplit);
</ins><span class="cx">             if (resultLength &gt;= limit)
</span><span class="cx">                 return AbortSplit;
</span><span class="cx">             return ContinueSplit;
</span><span class="cx">         });
</span><del>-    
</del><ins>+    RETURN_IF_EXCEPTION(scope, encodedJSValue());
+
</ins><span class="cx">     if (resultLength &gt;= limit)
</span><span class="cx">         return JSValue::encode(result);
</span><span class="cx">     if (resultLength &lt; maxSizeForDirectPath) {
</span><span class="cx">         // 20. Let T be a String value equal to the substring of S consisting of the elements at indices p (inclusive) through size (exclusive).
</span><span class="cx">         // 21. Perform ! CreateDataProperty(A, ! ToString(lengthA), T).
</span><ins>+        scope.release();
</ins><span class="cx">         result-&gt;putDirectIndex(exec, resultLength, JSRopeString::createSubstringOfResolved(vm, inputString, position, inputSize - position));
</span><span class="cx">         
</span><span class="cx">         // 22. Return A.
</span><span class="lines">@@ -679,7 +686,7 @@
</span><span class="cx">     
</span><span class="cx">     if (resultLength + dryRunCount &gt;= MAX_STORAGE_VECTOR_LENGTH) {
</span><span class="cx">         throwOutOfMemoryError(exec, scope);
</span><del>-        return JSValue::encode(jsUndefined());
</del><ins>+        return encodedJSValue();
</ins><span class="cx">     }
</span><span class="cx">     
</span><span class="cx">     // OK, we know that if we finish the split, we won't have to OOM.
</span><span class="lines">@@ -693,16 +700,19 @@
</span><span class="cx">         },
</span><span class="cx">         [&amp;] (bool isDefined, unsigned start, unsigned length) -&gt; SplitControl {
</span><span class="cx">             result-&gt;putDirectIndex(exec, resultLength++, isDefined ? JSRopeString::createSubstringOfResolved(vm, inputString, start, length) : jsUndefined());
</span><ins>+            RETURN_IF_EXCEPTION(scope, AbortSplit);
</ins><span class="cx">             if (resultLength &gt;= limit)
</span><span class="cx">                 return AbortSplit;
</span><span class="cx">             return ContinueSplit;
</span><span class="cx">         });
</span><del>-    
</del><ins>+    RETURN_IF_EXCEPTION(scope, encodedJSValue());
+
</ins><span class="cx">     if (resultLength &gt;= limit)
</span><span class="cx">         return JSValue::encode(result);
</span><span class="cx">     
</span><span class="cx">     // 20. Let T be a String value equal to the substring of S consisting of the elements at indices p (inclusive) through size (exclusive).
</span><span class="cx">     // 21. Perform ! CreateDataProperty(A, ! ToString(lengthA), T).
</span><ins>+    scope.release();
</ins><span class="cx">     result-&gt;putDirectIndex(exec, resultLength, JSRopeString::createSubstringOfResolved(vm, inputString, position, inputSize - position));
</span><span class="cx">     // 22. Return A.
</span><span class="cx">     return JSValue::encode(result);
</span></span></pre>
</div>
</div>

</body>
</html>