| Summary: | REGRESSION(r164493): DYEBench crash in JSCObject::put | ||
|---|---|---|---|
| Product: | WebKit | Reporter: | Ryosuke Niwa <rniwa> |
| Component: | JavaScriptCore | Assignee: | Ryosuke Niwa <rniwa> |
| Status: | RESOLVED WORKSFORME | ||
| Severity: | Normal | CC: | fpizlo, ggaren, mhahnenberg, webkit-bug-importer |
| Priority: | P2 | Keywords: | InRadar |
| Version: | 528+ (Nightly build) | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| URL: | https://trac.webkit.org/export/162218/trunk/PerformanceTests/DoYouEvenBench/Full.html | ||
|
Description
Ryosuke Niwa
2014-02-24 13:28:39 PST
Is there a symbolicated crash log somewhere to look at? This still reproduces with JSC_alwaysDoFullCollection=1 which implies it's not caused by the premature deallocation of a live object. (In reply to comment #3) > This still reproduces with JSC_alwaysDoFullCollection=1 which implies it's not caused by the premature deallocation of a live object. I should say, it's not a premature deallocation of a live object due to generational collection. We could still be blowing away a live object during a full collection. Throwing back to Ryosuke to verify that this has been fixed. No longer seeing the crash. |