[CherryPick] Remove use of JSCell::classInfoOffset() from virtualForThunkGenerator
[Title] Remove use of JSCell::classInfoOffset() from virtualForThunkGenerator
[Issue#] N_SE-49504
[Problem] Crash after accessing property through cached property
[Solution] use structure rather than classinfo
[Cherry-Picker] Lee SangGyu <sg5.lee@samsung.com>
Remove use of JSCell::classInfoOffset() from virtualForThunkGenerator
https://bugs.webkit.org/show_bug.cgi?id=95821
Reviewed by Oliver Hunt.
We can replace the load of the ClassInfo from the object with a load from the Structure.
* dfg/DFGThunks.cpp:
(JSC::DFG::virtualForThunkGenerator):
git-svn-id: http://svn.webkit.org/repository/webkit/trunk@127625
268f45cc-cd09-0410-ab3c-
d52691b4dbfc
Change-Id: Ic649e638d5ef6bb57559423e24caeba9b0745a4c