JSC is failing to propagate anonymous slot count on some transitions
Created attachment 47694 [details]
Comment on attachment 47694 [details]
> + push(@implContent, " ASSERT((int)(this->structure()->anonymousSlotCount()) >= (int)AnonymousSlotCount);\n");
Why are these casts needed? If they are needed, why use C-style casts instead of C++-style?
Committed r54073: <http://trac.webkit.org/changeset/54073>
I rolled this out in r54100 as it introduced many thousands of leaks.
Created attachment 47817 [details]
Comment on attachment 47817 [details]
*** Bug 34403 has been marked as a duplicate of this bug. ***
This has been given the name CVE-2010-1387