Summary: | [JSC] JSCell_freeListNext and JSCell_structureID are considered not overlapping | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Benjamin Poulain <benjamin> | ||||||
Component: | New Bugs | Assignee: | Benjamin Poulain <benjamin> | ||||||
Status: | RESOLVED FIXED | ||||||||
Severity: | Normal | CC: | commit-queue, fpizlo | ||||||
Priority: | P2 | ||||||||
Version: | WebKit Nightly Build | ||||||||
Hardware: | Unspecified | ||||||||
OS: | Unspecified | ||||||||
Attachments: |
|
Description
Benjamin Poulain
2016-03-02 18:34:13 PST
Created attachment 272717 [details]
Patch
Comment on attachment 272717 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=272717&action=review > Source/JavaScriptCore/ftl/FTLAbstractHeapRepository.h:57 > + macro(JSCell_header, OBJECT_OFFSETOF(MarkedBlock::FreeList, head)) \ I would change the offset to just 0. The reason why MarkedBlock::FreeList::head overlaps with JSCell::structure is that they are both the first thing in the cell. "0" really is the best way of saying that. Created attachment 272723 [details]
Patch for landing
Comment on attachment 272723 [details] Patch for landing Clearing flags on attachment: 272723 Committed r197491: <http://trac.webkit.org/changeset/197491> All reviewed patches have been landed. Closing bug. |