Summary: | REGRESSION: Crash under createNotAnObjectError visiting SES test page | ||
---|---|---|---|
Product: | WebKit | Reporter: | Mark S. Miller <erights> |
Component: | JavaScriptCore | Assignee: | Nobody <webkit-unassigned> |
Status: | RESOLVED DUPLICATE | ||
Severity: | Critical | CC: | ap, erights, fpizlo, ggaren, oliver |
Priority: | P1 | Keywords: | InRadar |
Version: | 528+ (Nightly build) | ||
Hardware: | Mac (Intel) | ||
OS: | OS X 10.8 | ||
URL: | http://google-caja.googlecode.com/svn/trunk/src/com/google/caja/ses/explicit.html |
Description
Mark S. Miller
2013-03-21 12:52:40 PDT
0 com.apple.JavaScriptCore 0x0000000108f91ad5 JSC::JSCell::toPrimitive(JSC::ExecState*, JSC::PreferredPrimitiveType) const + 21 1 com.apple.JavaScriptCore 0x0000000108f928d6 JSC::JSValue::toStringSlowCase(JSC::ExecState*) const + 886 2 com.apple.JavaScriptCore 0x0000000108dfc049 JSC::createNotAnObjectError(JSC::ExecState*, JSC::JSValue) + 57 3 com.apple.JavaScriptCore 0x0000000108df9854 JSC::JSValue::synthesizePrototype(JSC::ExecState*) const + 132 4 com.apple.JavaScriptCore 0x0000000108e55795 JSC::JSValue::get(JSC::ExecState*, JSC::PropertyName, JSC::PropertySlot&) const + 53 5 com.apple.JavaScriptCore 0x0000000108de0910 cti_op_get_by_id_generic + 80 That test page works fine in Safari Version 14.1 (16611.1.21.161.3). Should this be closed? Thank you for the update! For some reason, this got fixed as bug 113236 without a mention here. *** This bug has been marked as a duplicate of bug 113236 *** |