diff --git a/js/src/util/StringBuffer.cpp b/js/src/util/StringBuffer.cpp index 8209e467b8db6..d9425600c70f2 100644 --- a/js/src/util/StringBuffer.cpp +++ b/js/src/util/StringBuffer.cpp @@ -97,14 +97,16 @@ JSLinearString* StringBuffer::finishStringInternal(JSContext* cx, gc::Heap heap) { size_t len = length(); + // Taintfox: Disable static string return + if (!this->taint()) { + if (JSAtom* staticStr = cx->staticStrings().lookup(begin(), len)) { + return staticStr; + } + } + // Taintfox: propagate taint SafeStringTaint taint = this->taint().safeCopy(); - // Taintfox: Disable static string return - // if (JSAtom* staticStr = cx->staticStrings().lookup(begin(), len)) { - // return staticStr; - // } - if (JSInlineString::lengthFits(len)) { mozilla::Range range(begin(), len); JSLinearString* str = NewInlineString(cx, range);