Merged r11133, r11134 into trunk branch.

Check double array bounds in HasElementImpl.

Fix missing write barrier in CopyObjectToObjectElements.

BUG=chromium:119925,chromium:119926

R=jkummerow@chromium.org

Review URL: https://chromiumcodereview.appspot.com/9856012

git-svn-id: http://v8.googlecode.com/svn/trunk@11136 ce2b1a6d-e550-0410-aec6-3dcde31c8c00
6 files changed