Equivalence PropertyCondition needs to check the offset it uses to load the value from is not invalidOffset
Created attachment 269501 [details] Patch
Note that this patch does not fix https://bugs.webkit.org/show_bug.cgi?id=134641, which is still a race and is not so awesome.
Comment on attachment 269501 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=269501&action=review > Source/JavaScriptCore/tests/stress/global-property-into-variable-get-from-scope.js:5 > +load("resources/standalone-pre.js"); > + > +noInline(); > + > +for (i = 0; i < 100000; i++); How does this test the above issue?
Created attachment 269511 [details] Patch
(In reply to comment #3) > Comment on attachment 269501 [details] > Patch > > View in context: > https://bugs.webkit.org/attachment.cgi?id=269501&action=review > > > Source/JavaScriptCore/tests/stress/global-property-into-variable-get-from-scope.js:5 > > +load("resources/standalone-pre.js"); > > + > > +noInline(); > > + > > +for (i = 0; i < 100000; i++); > > How does this test the above issue? Added a comment that should hopefully clarify what I knew about the cause of the bug to the test.
Created attachment 269512 [details] Patch
Comment on attachment 269512 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=269512&action=review r=me > Source/JavaScriptCore/tests/stress/global-property-into-variable-get-from-scope.js:7 > +// at that point and we would attempt to access the value at an invalid offset. nit: Maybe add a "See https://bugs.webkit.org/show_bug.cgi?id=152912." here?
Comment on attachment 269512 [details] Patch Clearing flags on attachment: 269512 Committed r195462: <http://trac.webkit.org/changeset/195462>
All reviewed patches have been landed. Closing bug.