<rdar://problem/48722162>
Created attachment 364052 [details] proposed patch.
Comment on attachment 364052 [details] proposed patch. View in context: https://bugs.webkit.org/attachment.cgi?id=364052&action=review > Source/JavaScriptCore/heap/MarkedBlockInlines.h:308 > // This produces a free list that is ordered in reverse through the block. > // This is fine, since the allocation code makes no assumptions about the > // order of the free list. I should also fix this comment.
Created attachment 364054 [details] proposed patch.
Since this does not randomize bump pointer, I'm not sure there is much protection here.
Comment on attachment 364054 [details] proposed patch. Taking this out of review while I do some A/B testing.