Summary: | REGRESSION (r179357-r179359): WebContent Crash using AOL Mail @ com.apple.JavascriptCore JSC::linkPolymorphicCall(JSC::ExecState*, JSC::CallLinkInfo&, JSC::CallVariant, JSC::RegisterPreservationMode) + 1584 | ||||||
---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Michael Saboff <msaboff> | ||||
Component: | JavaScriptCore | Assignee: | Michael Saboff <msaboff> | ||||
Status: | RESOLVED FIXED | ||||||
Severity: | Normal | CC: | benjamin | ||||
Priority: | P2 | Keywords: | InRadar | ||||
Version: | WebKit Nightly Build | ||||||
Hardware: | All | ||||||
OS: | All | ||||||
Attachments: |
|
Description
Michael Saboff
2015-10-23 14:26:53 PDT
Created attachment 263954 [details]
Patch
Comment on attachment 263954 [details]
Patch
r=me
View in context: https://bugs.webkit.org/attachment.cgi?id=263954&action=review > Source/JavaScriptCore/jit/Repatch.cpp:686 > // If we cannot handle a callee, assume that it's better for this whole thing to be a > // virtual call. It would be good to update the comment too. > Source/JavaScriptCore/runtime/VM.h:635 > + bool m_failNextNewCodeBlock; Let's use m_failNextNewCodeBlock { false } then you don't need the initializer in the constructor. > Tools/DumpRenderTree/TestRunner.cpp:1940 > + if (argumentCount < 1) > + return JSValueMakeUndefined(context); > + ??? Do we care about argument here? Committed r191530: <http://trac.webkit.org/changeset/191530> |