Summary: | Crash when executing setTimeout / Date / document.write Javascript (bugtraq) | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Kevin Broderick <kbroderick> | ||||||
Component: | JavaScriptCore | Assignee: | Darin Adler <darin> | ||||||
Status: | RESOLVED FIXED | ||||||||
Severity: | Normal | CC: | mrowe | ||||||
Priority: | P1 | ||||||||
Version: | 420+ | ||||||||
Hardware: | Mac | ||||||||
OS: | OS X 10.4 | ||||||||
Attachments: |
|
Description
Kevin Broderick
2005-08-09 17:19:35 PDT
Created attachment 3302 [details]
Javascript that crashes WebKit
Confirmed with ToT WebKit. Bumping to P1 as it's a reproducible crash. Simple problem in document logic; unnecessary code to destroy the tokenizer twice. Created attachment 3806 [details]
patch to fix this by removing some uneeded code from document.close
It's hard to see the actual code change, given all the formatting changes. OK, r=me if the layout tests all still pass. Make sure to add the test case as a layout test. Had to change the test quite a bit to land it as a layout test, but I came up with something. |