[JSC] HeapUtil should care pointer overflow
Created attachment 347485 [details] Patch
Comment on attachment 347485 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=347485&action=review > Source/JavaScriptCore/ChangeLog:3 > + [JSC] HeapUtil should care pointer overflow care pointer => care about pointer > Source/JavaScriptCore/ChangeLog:8 > + `pointer - sizeof(IndexingHeader) - 1` causes an undefined behavior if a pointer is overflow. is overflow => overflows
Comment on attachment 347485 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=347485&action=review Thank you! >> Source/JavaScriptCore/ChangeLog:3 >> + [JSC] HeapUtil should care pointer overflow > > care pointer => care about pointer Thanks, fixed. >> Source/JavaScriptCore/ChangeLog:8 >> + `pointer - sizeof(IndexingHeader) - 1` causes an undefined behavior if a pointer is overflow. > > is overflow => overflows Fixed.
Committed r235161: <https://trac.webkit.org/changeset/235161>
<rdar://problem/43592586>