| Summary: | Malloc called beneath MachineThreads::gatherFromOtherThread(), while forbidden | ||||||
|---|---|---|---|---|---|---|---|
| Product: | WebKit | Reporter: | Mark Hahnenberg <mhahnenberg> | ||||
| Component: | JavaScriptCore | Assignee: | Mark Hahnenberg <mhahnenberg> | ||||
| Status: | RESOLVED FIXED | ||||||
| Severity: | Normal | CC: | mitz | ||||
| Priority: | P2 | Keywords: | InRadar | ||||
| Version: | 528+ (Nightly build) | ||||||
| Hardware: | Unspecified | ||||||
| OS: | Unspecified | ||||||
| Bug Depends on: | 128203 | ||||||
| Bug Blocks: | |||||||
| Attachments: |
|
||||||
|
Description
Mark Hahnenberg
2014-02-04 12:08:10 PST
Created attachment 223194 [details]
Patch
Comment on attachment 223194 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=223194&action=review r=me > Source/JavaScriptCore/heap/GCSegmentedArray.h:137 > + if (!m_currentSegment) > + return *this; This should be an ASSERT. It's undefined behavior to ++ past the end of an iterator. Committed r163450: <http://trac.webkit.org/changeset/163450> |