Bug 217634

Summary: Array.prototype.sort's sortBucketSort accesses an array in an invalid way that can lead to incorrect results with indexed properties on the prototype chain
Product: WebKit Reporter: Saam Barati <saam>
Component: JavaScriptCoreAssignee: Saam Barati <saam>
Status: RESOLVED FIXED    
Severity: Normal CC: benjamin, cffsmith, ews-watchlist, fpizlo, ggaren, gskachkov, guijemont, joepeck, jsc32, keith_miller, mark.lam, msaboff, rmorisset, ross.kirsling, ticaiolima, tzagallo, webkit-bug-importer, ysuzuki
Priority: P2 Keywords: InRadar
Version: Other   
Hardware: Unspecified   
OS: Unspecified   
Attachments:
Description Flags
patch none

Saam Barati
Reported 2020-10-12 14:28:21 PDT
...
Attachments
patch (3.13 KB, patch)
2020-10-12 14:53 PDT, Saam Barati
no flags
Saam Barati
Comment 1 2020-10-12 14:28:53 PDT
Saam Barati
Comment 2 2020-10-12 14:53:50 PDT
Yusuke Suzuki
Comment 3 2020-10-12 14:56:37 PDT
Comment on attachment 411162 [details] patch r=me
Saam Barati
Comment 4 2020-10-12 16:13:51 PDT
*** Bug 217516 has been marked as a duplicate of this bug. ***
EWS
Comment 5 2020-10-12 16:21:29 PDT
Committed r268375: <https://trac.webkit.org/changeset/268375> All reviewed patches have been landed. Closing bug and clearing flags on attachment 411162 [details].
Note You need to log in before you can comment on or make changes to this bug.