Summary: | DFG 32_64 backend doesn't check for hasArrayStorage() in NewArrayWithSize | ||
---|---|---|---|
Product: | WebKit | Reporter: | Filip Pizlo <fpizlo> |
Component: | JavaScriptCore | Assignee: | Filip Pizlo <fpizlo> |
Status: | RESOLVED FIXED | ||
Severity: | Normal | CC: | ggaren, mhahnenberg, msaboff |
Priority: | P2 | Keywords: | InRadar |
Version: | 528+ (Nightly build) | ||
Hardware: | All | ||
OS: | All |
Description
Filip Pizlo
2013-01-16 18:31:03 PST
Already reviewed by Michael Saboff in person. I couldn't easily come up with a good test case - this flaw would lead to code "just working" in a surprising number of cases. Landed in http://trac.webkit.org/changeset/139949 |