Summary: | Segmentation fault in JSC::JSGenericTypedArrayView<JSC::Int32Adaptor>::sort with concurrent write access on SharedArrayBuffer | ||
---|---|---|---|
Product: | WebKit | Reporter: | André Bargull <andre.bargull> |
Component: | JavaScriptCore | Assignee: | Yusuke Suzuki <ysuzuki> |
Status: | RESOLVED DUPLICATE | ||
Severity: | Normal | CC: | anthony, bilgorajskim, fpizlo, keith_miller, webkit-bug-importer, ysuzuki |
Priority: | P2 | Keywords: | InRadar |
Version: | WebKit Local Build | ||
Hardware: | Unspecified | ||
OS: | Unspecified |
Description
André Bargull
2019-04-23 01:44:20 PDT
*** This bug has been marked as a duplicate of bug 197634 *** Thanks for your report! This is fixed in bug 197634 :) Ah, no. Wrong bug close. The problem is that sort is assuming that we do not break total ordering of the already sorted values. But this is wrong in this case: shared array buffer is shared, and the other thread can modify it while sorting. Will fix as a part of bug 212069's patch. Thanks! *** This bug has been marked as a duplicate of bug 212069 *** |