| Summary: | Segmentation fault in JSC::JSGenericTypedArrayView<JSC::Int32Adaptor>::sort with concurrent write access on SharedArrayBuffer | ||
|---|---|---|---|
| Product: | WebKit | Reporter: | André Bargull <andre.bargull> |
| Component: | JavaScriptCore | Assignee: | Yusuke Suzuki <ysuzuki> |
| Status: | RESOLVED DUPLICATE | ||
| Severity: | Normal | CC: | anthony, bilgorajskim, fpizlo, keith_miller, webkit-bug-importer, ysuzuki |
| Priority: | P2 | Keywords: | InRadar |
| Version: | WebKit Local Build | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
|
Description
André Bargull
2019-04-23 01:44:20 PDT
*** This bug has been marked as a duplicate of bug 197634 *** Thanks for your report! This is fixed in bug 197634 :) Ah, no. Wrong bug close. The problem is that sort is assuming that we do not break total ordering of the already sorted values. But this is wrong in this case: shared array buffer is shared, and the other thread can modify it while sorting. Will fix as a part of bug 212069's patch. Thanks! *** This bug has been marked as a duplicate of bug 212069 *** |