Summary: | Equivalence PropertyCondition needs to check the offset it uses to load the value from is not invalidOffset | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Keith Miller <keith_miller> | ||||||||
Component: | New Bugs | Assignee: | Keith Miller <keith_miller> | ||||||||
Status: | RESOLVED FIXED | ||||||||||
Severity: | Normal | CC: | commit-queue, mark.lam, msaboff, saam | ||||||||
Priority: | P2 | ||||||||||
Version: | WebKit Nightly Build | ||||||||||
Hardware: | Unspecified | ||||||||||
OS: | Unspecified | ||||||||||
Attachments: |
|
Description
Keith Miller
2016-01-08 11:40:35 PST
Created attachment 269501 [details]
Patch
Note that this patch does not fix https://bugs.webkit.org/show_bug.cgi?id=134641, which is still a race and is not so awesome. Comment on attachment 269501 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=269501&action=review > Source/JavaScriptCore/tests/stress/global-property-into-variable-get-from-scope.js:5 > +load("resources/standalone-pre.js"); > + > +noInline(); > + > +for (i = 0; i < 100000; i++); How does this test the above issue? Created attachment 269511 [details]
Patch
(In reply to comment #3) > Comment on attachment 269501 [details] > Patch > > View in context: > https://bugs.webkit.org/attachment.cgi?id=269501&action=review > > > Source/JavaScriptCore/tests/stress/global-property-into-variable-get-from-scope.js:5 > > +load("resources/standalone-pre.js"); > > + > > +noInline(); > > + > > +for (i = 0; i < 100000; i++); > > How does this test the above issue? Added a comment that should hopefully clarify what I knew about the cause of the bug to the test. Created attachment 269512 [details]
Patch
Comment on attachment 269512 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=269512&action=review r=me > Source/JavaScriptCore/tests/stress/global-property-into-variable-get-from-scope.js:7 > +// at that point and we would attempt to access the value at an invalid offset. nit: Maybe add a "See https://bugs.webkit.org/show_bug.cgi?id=152912." here? Comment on attachment 269512 [details] Patch Clearing flags on attachment: 269512 Committed r195462: <http://trac.webkit.org/changeset/195462> All reviewed patches have been landed. Closing bug. |