Object property rules, regular-expression objects, and function introspection
A deeper pass over how faithfully the engine follows the JavaScript standard for objects, regular expressions and functions. Defining a property on an object now enforces the rules the language requires: it reports a clear error for an invalid request (a bad target, a malformed description, or an attempt to change a property that was locked down) and records exactly which parts of a property are fixed, so code that inspects or guards its objects behaves the way it does in other browsers. Regular expressions now act like the standard objects they are: they expose their pattern and option letters through the same accessors other engines provide, always in the canonical order, and they carry the built-in hooks the language's text search, match, split and replace operations rely on. And functions now report their name and their number of arguments correctly to code that inspects them, which a great deal of library and framework code reads. None of this changes code that was already correct. The JavaScript language aspect moves 89 to 90; the overall platform score stays at 70.