Bug 30137 - [V8] Protect JS listener object from GC while clearing a property on it.
Summary: [V8] Protect JS listener object from GC while clearing a property on it.
Status: RESOLVED FIXED
Alias: None
Product: WebKit
Classification: Unclassified
Component: WebCore Misc. (show other bugs)
Version: 528+ (Nightly build)
Hardware: All All
: P2 Normal
Assignee: Nobody
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2009-10-06 13:09 PDT by Vitaly Repeshko
Modified: 2009-10-07 10:25 PDT (History)
4 users (show)

See Also:


Attachments
patch (1.41 KB, patch)
2009-10-06 14:26 PDT, Vitaly Repeshko
no flags Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Vitaly Repeshko 2009-10-06 13:09:23 PDT
[V8] Protect JS listener object from GC while clearing a property on it.
Comment 1 Vitaly Repeshko 2009-10-06 14:26:17 PDT
Created attachment 40745 [details]
patch
Comment 2 Adam Barth 2009-10-07 09:33:10 PDT
Comment on attachment 40745 [details]
patch

I don't see how this is possible to test.  We'd need to force GC during the clearWrapper call, but I don't think that re-enters JavaScript....  Thoughts?
Comment 3 WebKit Commit Bot 2009-10-07 10:25:13 PDT
Comment on attachment 40745 [details]
patch

Clearing flags on attachment: 40745

Committed r49252: <http://trac.webkit.org/changeset/49252>
Comment 4 WebKit Commit Bot 2009-10-07 10:25:17 PDT
All reviewed patches have been landed.  Closing bug.