Summary: | Crash in JSC::MarkedBlock::FreeList JSC::MarkedBlock::sweepHelper | ||||||
---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Ryosuke Niwa <rniwa> | ||||
Component: | JavaScriptCore | Assignee: | Oliver Hunt <oliver> | ||||
Status: | RESOLVED FIXED | ||||||
Severity: | Normal | CC: | arkr17997, benjamin, cmarcelo, fpizlo, ggaren, msaboff, ojan.autocc, oliver, webkit.review.bot | ||||
Priority: | P2 | ||||||
Version: | 528+ (Nightly build) | ||||||
Hardware: | Unspecified | ||||||
OS: | Unspecified | ||||||
Attachments: |
|
Description
Ryosuke Niwa
2013-02-28 02:18:57 PST
So with some fiddling i can make this die fairly easily, implying a validation logic bug. Can't work out of course, and lldb is trying hard to beat gdb for the prize of "least good at debugging optimized code" so seeing if i can make it repro in a debug build Created attachment 190776 [details]
Patch
r=me too Committed r144346: <http://trac.webkit.org/changeset/144346> Was it doing implicit conversion to bool prior to the operator? (In reply to comment #5) > Was it doing implicit conversion to bool prior to the operator? Yup :( |