Summary: | Crashes in Photo Booth at com.apple.JavaScriptCore: JSC::Heap::markRoots + 746 | ||||||
---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Geoffrey Garen <ggaren> | ||||
Component: | JavaScriptCore | Assignee: | Geoffrey Garen <ggaren> | ||||
Status: | RESOLVED FIXED | ||||||
Severity: | Normal | CC: | barraclough, sam, webkit-ews | ||||
Priority: | P2 | ||||||
Version: | 528+ (Nightly build) | ||||||
Hardware: | PC | ||||||
OS: | OS X 10.5 | ||||||
Attachments: |
|
Description
Geoffrey Garen
2010-12-02 16:55:03 PST
Created attachment 75435 [details]
patch
Comment on attachment 75435 [details]
patch
I think you should also call synchronize in ~APICallbackShim.
Thread A could be running JS code, call out to a callback, release a lock (in client code), then thread B could run, schedule a GC, exit the VM, release its lock, then the callback in thread A could return from the callback & be running inside JSC with a GC scheduled on thread B.
r+ with the fix.
Committed revision 73223. Attachment 75435 [details] did not build on qt: Build output: http://queues.webkit.org/results/6844014 |