зеркало из https://github.com/mozilla/pjs.git
Bug 636079 - Refactor JSON.stringify code to more closely conform to the specification, fixing a bunch of known problems in the process. r=pbiggar
Bugs fixed: * toJSON is now invoked with an argument list consisting of the property name. * In rare circumstances toJSON was invoked twice for a single object-valued property. This error has now been corrected. * Stringification no longer throws if the toJSON property of an object being stringified is an object but is not callable. * The replacer function is invoked exactly once for properties of objects when those properties are stringified. * If a replacer function is to be called, it will receive array indexes as strings instead of numbers, per ES5. Other improvements include: * Speedier internal methods are used, rather than slow external APIs. * Argument types are more specific (e.g. the "holder" argument is an object). * Logic to determine when to call the replacer function is unnecessary and has been removed. --HG-- extra : rebase_source : 1f2ee9ff4c14edebda3e48d33d6df32fc44b701d
This commit is contained in:
@ -214,6 +214,7 @@ INSTALLED_HEADERS = \
jslock.h \
jslong.h \
jsmath.h \
jsnum.h \
jsobj.h \
jsobjinlines.h \
json.h \
@ -48,6 +48,7 @@
#include "jsprvtd.h"
#include "jshash.h"
#include "jshashtable.h"
#include "jsnum.h"
#include "jspubtd.h"
#include "jsstr.h"
#include "jslock.h"
@ -114,6 +115,16 @@ IdToJsval(jsid id)
return Jsvalify(IdToValue(id));
static JS_ALWAYS_INLINE JSString *
IdToString(JSContext *cx, jsid id)
return JSID_TO_STRING(id);
return js_IntToString(cx, JSID_TO_INT(id));
return js_ValueToString(cx, IdToValue(id));
@ -278,10 +278,7 @@ public:
HashSet<JSObject *> objectStack;
static JSBool CallReplacerFunction(JSContext *cx, jsid id, JSObject *holder,
StringifyContext *scx, Value *vp);
static JSBool Str(JSContext *cx, jsid id, JSObject *holder,
StringifyContext *scx, Value *vp, bool callReplacer = true);
static JSBool Str(JSContext *cx, const Value &v, StringifyContext *scx);
static JSBool
WriteIndent(JSContext *cx, StringifyContext *scx, uint32 limit)
@ -323,197 +320,64 @@ class CycleDetector
JSObject *const obj;
static JSBool
JO(JSContext *cx, Value *vp, StringifyContext *scx)
* ES5 15.12.3 Str, steps 2-4, extracted to enable preprocessing of property
* values when stringifying objects in JO.
static bool
PreprocessValue(JSContext *cx, JSObject *holder, jsid key, Value *vp, StringifyContext *scx)
JSObject *obj = &vp->toObject();
CycleDetector detect(scx, obj);
if (!detect.init(cx))
return JS_FALSE;
if (!scx->sb.append('{'))
return JS_FALSE;
Value vec[3] = { NullValue(), NullValue(), NullValue() };
AutoArrayRooter tvr(cx, JS_ARRAY_LENGTH(vec), vec);
Value& outputValue = vec[0];
Value& whitelistElement = vec[1];
AutoIdRooter idr(cx);
jsid& id = *idr.addr();
Value *keySource = vp;
bool usingWhitelist = false;
// if the replacer is an array, we use the keys from it
if (scx->replacer && JS_IsArrayObject(cx, scx->replacer)) {
usingWhitelist = true;
keySource = &vec[2];
JSBool memberWritten = JS_FALSE;
AutoIdVector props(cx);
if (!GetPropertyNames(cx, &keySource->toObject(), JSITER_OWNONLY, &props))
return JS_FALSE;
for (size_t i = 0, len = props.length(); i < len; i++) {
if (!usingWhitelist) {
if (!js_ValueToStringId(cx, IdToValue(props[i]), &id))
return JS_FALSE;
} else {
// skip non-index properties
jsuint index = 0;
if (!js_IdIsIndex(props[i], &index))
if (!scx->replacer->getProperty(cx, props[i], &whitelistElement))
return JS_FALSE;
if (!js_ValueToStringId(cx, whitelistElement, &id))
return JS_FALSE;
// We should have a string id by this point. Either from
// JS_Enumerate's id array, or by converting an element
// of the whitelist.
if (!JS_GetPropertyById(cx, obj, id, Jsvalify(&outputValue)))
return JS_FALSE;
if (outputValue.isObjectOrNull() && !js_TryJSON(cx, &outputValue))
return JS_FALSE;
// call this here, so we don't write out keys if the replacer function
// wants to elide the value.
if (!CallReplacerFunction(cx, id, obj, scx, &outputValue))
return JS_FALSE;
JSType type = JS_TypeOfValue(cx, Jsvalify(outputValue));
// elide undefined values and functions and XML
if (outputValue.isUndefined() || type == JSTYPE_FUNCTION || type == JSTYPE_XML)
// output a comma unless this is the first member to write
if (memberWritten && !scx->sb.append(','))
return JS_FALSE;
memberWritten = JS_TRUE;
if (!WriteIndent(cx, scx, scx->depth))
return JS_FALSE;
// Be careful below, this string is weakly rooted
JSString *s = js_ValueToString(cx, IdToValue(id));
if (!s)
return JS_FALSE;
JS::Anchor<JSString *> anchor(s);
size_t length = s->length();
const jschar *chars = s->getChars(cx);
if (!chars)
return JS_FALSE;
if (!write_string(cx, scx->sb, chars, length) ||
!scx->sb.append(':') ||
!(scx->gap.empty() || scx->sb.append(' ')) ||
!Str(cx, id, obj, scx, &outputValue, true)) {
return JS_FALSE;
if (memberWritten && !WriteIndent(cx, scx, scx->depth - 1))
return JS_FALSE;
return scx->sb.append('}');
static JSBool
JA(JSContext *cx, Value *vp, StringifyContext *scx)
JSObject *obj = &vp->toObject();
CycleDetector detect(scx, obj);
if (!detect.init(cx))
return JS_FALSE;
if (!scx->sb.append('['))
return JS_FALSE;
jsuint length;
if (!js_GetLengthProperty(cx, obj, &length))
return JS_FALSE;
if (length != 0 && !WriteIndent(cx, scx, scx->depth))
return JS_FALSE;
AutoValueRooter outputValue(cx);
jsid id;
jsuint i;
for (i = 0; i < length; i++) {
id = INT_TO_JSID(i);
if (!obj->getProperty(cx, id, outputValue.addr()))
return JS_FALSE;
if (!Str(cx, id, obj, scx, outputValue.addr()))
return JS_FALSE;
if (outputValue.value().isUndefined()) {
if (!scx->sb.append("null"))
return JS_FALSE;
if (i < length - 1) {
if (!scx->sb.append(','))
return JS_FALSE;
if (!WriteIndent(cx, scx, scx->depth))
return JS_FALSE;
if (length != 0 && !WriteIndent(cx, scx, scx->depth - 1))
return JS_FALSE;
return scx->sb.append(']');
static JSBool
CallReplacerFunction(JSContext *cx, jsid id, JSObject *holder, StringifyContext *scx, Value *vp)
if (scx->replacer && scx->replacer->isCallable()) {
Value vec[2] = { IdToValue(id), *vp};
if (!JS_CallFunctionValue(cx, holder, OBJECT_TO_JSVAL(scx->replacer),
2, Jsvalify(vec), Jsvalify(vp))) {
return JS_FALSE;
return JS_TRUE;
static JSBool
Str(JSContext *cx, jsid id, JSObject *holder, StringifyContext *scx, Value *vp, bool callReplacer)
JS_CHECK_RECURSION(cx, return false);
* This method implements the Str algorithm in ES5 15.12.3, but we move
* property retrieval (step 1) into callers to stream the stringification
* process and avoid constantly copying strings.
JSString *keyStr = NULL;
/* Step 2. */
if (vp->isObject() && !js_TryJSON(cx, vp))
return false;
if (vp->isObject()) {
Value toJSON;
jsid id = ATOM_TO_JSID(cx->runtime->atomState.toJSONAtom);
if (!js_GetMethod(cx, &vp->toObject(), id, JSGET_NO_METHOD_BARRIER, &toJSON))
return false;
if (js_IsCallable(toJSON)) {
keyStr = IdToString(cx, key);
if (!keyStr)
return false;
InvokeArgsGuard args;
if (!cx->stack().pushInvokeArgs(cx, 1, &args))
return false;
args.callee() = toJSON;
args.thisv() = *vp;
args[0] = StringValue(keyStr);
if (!Invoke(cx, args, 0))
return false;
*vp = args.rval();
/* Step 3. */
if (callReplacer && !CallReplacerFunction(cx, id, holder, scx, vp))
return false;
if (scx->replacer && scx->replacer->isCallable()) {
if (!keyStr) {
keyStr = IdToString(cx, key);
if (!keyStr)
return false;
InvokeArgsGuard args;
if (!cx->stack().pushInvokeArgs(cx, 2, &args))
return false;
args.callee() = ObjectValue(*scx->replacer);
args.thisv() = ObjectValue(*holder);
args[0] = StringValue(keyStr);
args[1] = *vp;
if (!Invoke(cx, args, 0))
return false;
*vp = args.rval();
/* Step 4. */
if (vp->isObject()) {
@ -531,12 +395,231 @@ Str(JSContext *cx, jsid id, JSObject *holder, StringifyContext *scx, Value *vp,
} else if (clasp == &js_BooleanClass) {
*vp = obj->getPrimitiveThis();
return true;
* Determines whether a value which has passed by ES5 150.2.3 Str steps 1-4's
* gauntlet will result in Str returning |undefined|. This function is used to
* properly omit properties resulting in such values when stringifying objects,
* while properly stringifying such properties as null when they're encountered
* in arrays.
static inline bool
IsFilteredValue(const Value &v)
return v.isUndefined() || js_IsCallable(v) || (v.isObject() && v.toObject().isXML());
/* ES5 15.12.3 JO. */
static JSBool
JO(JSContext *cx, JSObject *obj, StringifyContext *scx)
* This method implements the JO algorithm in ES5 15.12.3, but:
* * The algorithm is somewhat reformulated to allow the final string to
* be streamed into a single buffer, rather than be created and copied
* into place incrementally as the ES5 algorithm specifies it. This
* requires moving portions of the Str call in 8a into this algorithm
* (and in JA as well).
/* Steps 1-2, 11. */
CycleDetector detect(scx, obj);
if (!detect.init(cx))
return JS_FALSE;
if (!scx->sb.append('{'))
return JS_FALSE;
AutoIdRooter idr(cx);
jsid& id = *idr.addr();
/* Steps 5-7. */
/* XXX Bug 648471: Do this in js_Stringify, rename keySource. */
Value keySource = ObjectValue(*obj);
bool usingWhitelist = false;
// if the replacer is an array, we use the keys from it
if (scx->replacer && JS_IsArrayObject(cx, scx->replacer)) {
usingWhitelist = true;
bool wroteMember = false;
AutoIdVector props(cx);
if (!GetPropertyNames(cx, &keySource.toObject(), JSITER_OWNONLY, &props))
return JS_FALSE;
/* Steps 8-10, 13. */
for (size_t i = 0, len = props.length(); i < len; i++) {
if (!usingWhitelist) {
if (!js_ValueToStringId(cx, IdToValue(props[i]), &id))
return JS_FALSE;
} else {
// skip non-index properties
jsuint index = 0;
if (!js_IdIsIndex(props[i], &index))
Value whitelistElement;
if (!scx->replacer->getProperty(cx, props[i], &whitelistElement))
return JS_FALSE;
if (!js_ValueToStringId(cx, whitelistElement, &id))
return JS_FALSE;
* Steps 8a-8b. Note that the call to Str is broken up into 1) getting
* the property; 2) processing for toJSON, calling the replacer, and
* handling boxed Number/String/Boolean objects; 3) filtering out
* values which process to |undefined|, and 4) stringifying all values
* which pass the filter.
Value outputValue;
if (!obj->getProperty(cx, id, &outputValue))
return JS_FALSE;
if (!PreprocessValue(cx, obj, id, &outputValue, scx))
return JS_FALSE;
if (IsFilteredValue(outputValue))
/* Output a comma unless this is the first member to write. */
if (wroteMember && !scx->sb.append(','))
return JS_FALSE;
wroteMember = true;
if (!WriteIndent(cx, scx, scx->depth))
return JS_FALSE;
// Be careful below: this string is weakly rooted!
JSString *s = js_ValueToString(cx, IdToValue(id));
if (!s)
return JS_FALSE;
JS::Anchor<JSString *> anchor(s);
size_t length = s->length();
const jschar *chars = s->getChars(cx);
if (!chars)
return JS_FALSE;
if (!write_string(cx, scx->sb, chars, length) ||
!scx->sb.append(':') ||
!(scx->gap.empty() || scx->sb.append(' ')) ||
!Str(cx, outputValue, scx)) {
return JS_FALSE;
if (wroteMember && !WriteIndent(cx, scx, scx->depth - 1))
return JS_FALSE;
return scx->sb.append('}');
/* ES5 15.12.3 JA. */
static JSBool
JA(JSContext *cx, JSObject *obj, StringifyContext *scx)
* This method implements the JA algorithm in ES5 15.12.3, but:
* * The algorithm is somewhat reformulated to allow the final string to
* be streamed into a single buffer, rather than be created and copied
* into place incrementally as the ES5 algorithm specifies it. This
* requires moving portions of the Str call in 8a into this algorithm
* (and in JO as well).
/* Steps 1-2, 11. */
CycleDetector detect(scx, obj);
if (!detect.init(cx))
return JS_FALSE;
if (!scx->sb.append('['))
return JS_FALSE;
/* Step 6. */
jsuint length;
if (!js_GetLengthProperty(cx, obj, &length))
return JS_FALSE;
/* Steps 7-10. */
if (length != 0) {
/* Steps 4, 10b(i). */
if (!WriteIndent(cx, scx, scx->depth))
return JS_FALSE;
/* Steps 7-10. */
Value outputValue;
for (jsuint i = 0; i < length; i++) {
jsid id = INT_TO_JSID(i);
* Steps 8a-8c. Again note how the call to the spec's Str method
* is broken up into getting the property, running it past toJSON
* and the replacer and maybe unboxing, and interpreting some
* values as |null| in separate steps.
if (!obj->getProperty(cx, id, &outputValue))
return JS_FALSE;
if (!PreprocessValue(cx, obj, id, &outputValue, scx))
return JS_FALSE;
if (IsFilteredValue(outputValue)) {
if (!scx->sb.append("null"))
return JS_FALSE;
} else {
if (!Str(cx, outputValue, scx))
return JS_FALSE;
/* Steps 3, 4, 10b(i). */
if (i < length - 1) {
if (!scx->sb.append(','))
return JS_FALSE;
if (!WriteIndent(cx, scx, scx->depth))
return JS_FALSE;
/* Step 10(b)(iii). */
if (!WriteIndent(cx, scx, scx->depth - 1))
return JS_FALSE;
return scx->sb.append(']');
static JSBool
Str(JSContext *cx, const Value &v, StringifyContext *scx)
/* Step 11 must be handled by the caller. */
JS_CHECK_RECURSION(cx, return false);
* This method implements the Str algorithm in ES5 15.12.3, but:
* * We move property retrieval (step 1) into callers to stream the
* stringification process and avoid constantly copying strings.
* * We move the preprocessing in steps 2-4 into a helper function to
* allow both JO and JA to use this method. While JA could use it
* without this move, JO must omit any |undefined|-valued property per
* so it can't stream out a value using the Str method exactly as
* defined by ES5.
* * We move step 11 into callers, again to ease streaming.
/* Step 8. */
if (vp->isString()) {
JSString *str = vp->toString();
if (v.isString()) {
JSString *str = v.toString();
size_t length = str->length();
const jschar *chars = str->getChars(cx);
if (!chars)
@ -545,42 +628,36 @@ Str(JSContext *cx, jsid id, JSObject *holder, StringifyContext *scx, Value *vp,
/* Step 5. */
if (vp->isNull())
if (v.isNull())
return scx->sb.append("null");
/* Steps 6-7. */
if (vp->isBoolean())
return vp->toBoolean() ? scx->sb.append("true") : scx->sb.append("false");
if (v.isBoolean())
return v.toBoolean() ? scx->sb.append("true") : scx->sb.append("false");
/* Step 9. */
if (vp->isNumber()) {
if (vp->isDouble()) {
jsdouble d = vp->toDouble();
if (v.isNumber()) {
if (v.isDouble()) {
if (!JSDOUBLE_IS_FINITE(v.toDouble()))
return scx->sb.append("null");
StringBuffer sb(cx);
if (!NumberValueToStringBuffer(cx, *vp, sb))
if (!NumberValueToStringBuffer(cx, v, sb))
return false;
return scx->sb.append(sb.begin(), sb.length());
/* Step 10. */
if (vp->isObject() && !IsFunctionObject(*vp) && !IsXML(*vp)) {
JSBool ok;
JSBool ok;
ok = (JS_IsArrayObject(cx, &vp->toObject()) ? JA : JO)(cx, vp, scx);
ok = (JS_IsArrayObject(cx, &v.toObject()) ? JA : JO)(cx, &v.toObject(), scx);
return ok;
/* Step 11. */
return true;
return ok;
@ -596,12 +673,15 @@ js_Stringify(JSContext *cx, Value *vp, JSObject *replacer, const Value &space,
return JS_FALSE;
AutoObjectRooter tvr(cx, obj);
if (!obj->defineProperty(cx, ATOM_TO_JSID(cx->runtime->atomState.emptyAtom),
jsid emptyId = ATOM_TO_JSID(cx->runtime->atomState.emptyAtom);
if (!obj->defineProperty(cx, emptyId, *vp, NULL, NULL, JSPROP_ENUMERATE))
return JS_FALSE;
return Str(cx, ATOM_TO_JSID(cx->runtime->atomState.emptyAtom), obj, &scx, vp);
if (!PreprocessValue(cx, obj, emptyId, vp, &scx))
return JS_FALSE;
if (IsFilteredValue(*vp))
return JS_TRUE;
return Str(cx, *vp, &scx);
// helper to determine whether a character could be part of a number
@ -269,9 +269,9 @@ class ToString {
JSAutoByteString mBytes;
class IdToString : public ToString {
class IdStringifier : public ToString {
IdToString(JSContext *cx, jsid id, JSBool aThrow = JS_FALSE)
IdStringifier(JSContext *cx, jsid id, JSBool aThrow = JS_FALSE)
: ToString(cx, IdToJsval(id), aThrow)
{ }
@ -5118,7 +5118,7 @@ its_addProperty(JSContext *cx, JSObject *obj, jsid id, jsval *vp)
if (!its_noisy)
return JS_TRUE;
IdToString idString(cx, id);
IdStringifier idString(cx, id);
fprintf(gOutFile, "adding its property %s,", idString.getBytes());
ToString valueString(cx, *vp);
fprintf(gOutFile, " initial value %s\n", valueString.getBytes());
@ -5131,7 +5131,7 @@ its_delProperty(JSContext *cx, JSObject *obj, jsid id, jsval *vp)
if (!its_noisy)
return JS_TRUE;
IdToString idString(cx, id);
IdStringifier idString(cx, id);
fprintf(gOutFile, "deleting its property %s,", idString.getBytes());
ToString valueString(cx, *vp);
fprintf(gOutFile, " initial value %s\n", valueString.getBytes());
@ -5144,7 +5144,7 @@ its_getProperty(JSContext *cx, JSObject *obj, jsid id, jsval *vp)
if (!its_noisy)
return JS_TRUE;
IdToString idString(cx, id);
IdStringifier idString(cx, id);
fprintf(gOutFile, "getting its property %s,", idString.getBytes());
ToString valueString(cx, *vp);
fprintf(gOutFile, " initial value %s\n", valueString.getBytes());
@ -5154,7 +5154,7 @@ its_getProperty(JSContext *cx, JSObject *obj, jsid id, jsval *vp)
static JSBool
its_setProperty(JSContext *cx, JSObject *obj, jsid id, JSBool strict, jsval *vp)
IdToString idString(cx, id);
IdStringifier idString(cx, id);
if (its_noisy) {
fprintf(gOutFile, "setting its property %s,", idString.getBytes());
ToString valueString(cx, *vp);
@ -5225,7 +5225,7 @@ its_resolve(JSContext *cx, JSObject *obj, jsid id, uintN flags,
JSObject **objp)
if (its_noisy) {
IdToString idString(cx, id);
IdStringifier idString(cx, id);
fprintf(gOutFile, "resolving its property %s, flags {%s,%s,%s}\n",
(flags & JSRESOLVE_QUALIFIED) ? "qualified" : "",
@ -5521,7 +5521,7 @@ env_setProperty(JSContext *cx, JSObject *obj, jsid id, JSBool strict, jsval *vp)
#if !defined XP_OS2 && !defined SOLARIS
int rv;
IdToString idstr(cx, id, JS_TRUE);
IdStringifier idstr(cx, id, JS_TRUE);
if (idstr.threw())
return JS_FALSE;
ToString valstr(cx, *vp, JS_TRUE);
@ -5600,7 +5600,7 @@ env_resolve(JSContext *cx, JSObject *obj, jsid id, uintN flags,
return JS_TRUE;
IdToString idstr(cx, id, JS_TRUE);
IdStringifier idstr(cx, id, JS_TRUE);
if (idstr.threw())
return JS_FALSE;
@ -1,6 +1,12 @@
url-prefix ../../jsreftest.html?test=ecma_5/JSON/
script cyclic-stringify.js
script small-codepoints.js
script trailing-comma.js
script stringify-gap.js
script stringify-boxed-primitives.js
script stringify-call-replacer-once.js
script stringify-call-toJSON-once.js
script stringify-gap.js
script stringify-ignore-noncallable-toJSON.js
script stringify-replacer-with-array-indexes.js
script stringify-toJSON-arguments.js
script trailing-comma.js
@ -0,0 +1,34 @@
// Any copyright is dedicated to the Public Domain.
// http://creativecommons.org/licenses/publicdomain/
var gTestfile = 'stringify-call-replacer-once.js';
var BUGNUMBER = 584909;
var summary = "Call replacer function exactly once per value";
print(BUGNUMBER + ": " + summary);
var factor = 1;
function replacer(k, v)
if (k === "")
return v;
return v * ++factor;
var obj = { a: 1, b: 2, c: 3 };
assertEq(JSON.stringify(obj, replacer), '{"a":2,"b":6,"c":12}');
assertEq(factor, 4);
if (typeof reportCompare === "function")
reportCompare(true, true);
print("Tests complete");
@ -0,0 +1,32 @@
// Any copyright is dedicated to the Public Domain.
// http://creativecommons.org/licenses/publicdomain/
var gTestfile = 'stringify-call-toJSON-once.js';
var BUGNUMBER = 584909;
var summary = "Stringification of Boolean/String/Number objects";
print(BUGNUMBER + ": " + summary);
var obj =
p: {
toJSON: function()
return { toJSON: function() { return 17; } };
assertEq(JSON.stringify(obj), '{"p":{}}');
if (typeof reportCompare === "function")
reportCompare(true, true);
print("Tests complete");
@ -0,0 +1,28 @@
// Any copyright is dedicated to the Public Domain.
// http://creativecommons.org/licenses/publicdomain/
var gTestfile = 'stringify-ignore-noncallable-toJSON.js';
var BUGNUMBER = 584909;
var summary = "If the toJSON property isn't callable, don't try to call it";
print(BUGNUMBER + ": " + summary);
var obj =
p: { toJSON: null },
m: { toJSON: {} }
assertEq(JSON.stringify(obj), '{"p":{"toJSON":null},"m":{"toJSON":{}}}');
if (typeof reportCompare === "function")
reportCompare(true, true);
print("Tests complete");
@ -0,0 +1,56 @@
// Any copyright is dedicated to the Public Domain.
// http://creativecommons.org/licenses/publicdomain/
var gTestfile = 'stringify-replacer-with-array-indexes.js';
var BUGNUMBER = 584909;
var summary =
"Call the replacer function for array elements with stringified indexes";
print(BUGNUMBER + ": " + summary);
var arr = [0, 1, 2, 3, 4];
var seenTopmost = false;
var index = 0;
function replacer()
assertEq(arguments.length, 2);
var key = arguments[0], value = arguments[1];
// Topmost array: ignore replacer call.
if (key === "")
assertEq(seenTopmost, false);
seenTopmost = true;
return value;
assertEq(seenTopmost, true);
assertEq(typeof key, "string");
assertEq(key === index, false);
assertEq(key === index + "", true);
assertEq(value, index);
assertEq(this, arr);
return value;
assertEq(JSON.stringify(arr, replacer), '[0,1,2,3,4]');
if (typeof reportCompare === "function")
reportCompare(true, true);
print("Tests complete");
@ -0,0 +1,34 @@
// Any copyright is dedicated to the Public Domain.
// http://creativecommons.org/licenses/publicdomain/
var gTestfile = 'stringify-toJSON-arguments.js';
var BUGNUMBER = 584909;
var summary = "Arguments when an object's toJSON method is called";
print(BUGNUMBER + ": " + summary);
var obj =
p: {
toJSON: function(key)
assertEq(arguments.length, 1);
assertEq(key, "p");
return 17;
assertEq(JSON.stringify(obj), '{"p":17}');
if (typeof reportCompare === "function")
reportCompare(true, true);
print("Tests complete");
Ссылка в новой задаче