Summary: | JSC: assertion failure in SpeculativeJIT::compileGetByValOnIntTypedArray | ||||||
---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Samuel Groß <saelo> | ||||
Component: | JavaScriptCore | Assignee: | Michael Saboff <msaboff> | ||||
Status: | RESOLVED FIXED | ||||||
Severity: | Normal | CC: | bfulgham, commit-queue, darin, ews-feeder, fpizlo, mark.lam, msaboff, product-security, rmorisset, saam, tzagallo, webkit-bug-importer, ysuzuki | ||||
Priority: | P2 | Keywords: | InRadar | ||||
Version: | Safari 12 | ||||||
Hardware: | Unspecified | ||||||
OS: | Unspecified | ||||||
Attachments: |
|
Description
Samuel Groß
2019-07-22 02:44:04 PDT
Thanks for the report. This is not a security issue. Our static analysis in AI is conservative, the bug here is we're asserting that AI is precise. We shouldn't assert such things. Created attachment 375534 [details]
Patch
r=me too. Since this is not a security issue, should we move it out of the security-sensitive component? Committed r248271: <https://trac.webkit.org/changeset/248271> |