Bug 52643 - [jsfunfuzz] Assertion in codegen for array of NaN constants
Summary: [jsfunfuzz] Assertion in codegen for array of NaN constants
Status: RESOLVED FIXED
Alias: None
Product: WebKit
Classification: Unclassified
Component: JavaScriptCore (show other bugs)
Version: 528+ (Nightly build)
Hardware: PC OS X 10.5
: P2 Normal
Assignee: Oliver Hunt
URL:
Keywords:
Depends on:
Blocks: 13638
  Show dependency treegraph
 
Reported: 2011-01-18 11:32 PST by Oliver Hunt
Modified: 2011-01-18 13:10 PST (History)
4 users (show)

See Also:


Attachments
Patch (4.31 KB, patch)
2011-01-18 12:52 PST, Oliver Hunt
koivisto: review+
Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Oliver Hunt 2011-01-18 11:32:44 PST
This asserts when trying to cache values in the number pool
tryItOut("/*p*/for (w in [(0/0), (0/0)(0/0), (0/0)(0/0), (0/0)(0), (0/0)(0/0), (0/0)(0/0), (0/0)(0/0), (0/0)(0/0), (0/0)(0/0), (0/0)(0/0), (0/0)(0/0), (0/0)(0/0), (0/0), (0/0), (0/0), (0/0), (0/0), (0/0), (0/0), (0/0), (0/0)]) { (eval = c); }")

I've reduced it to:
[(0/0), (0/0)(0/0), (0/0)(0/0), (0/0)(0), (0/0)(0/0), (0/0)(0/0), (0/0)(0/0), (0/0)(0/0), (0/0)(0/0), (0/0)(0/0), (0/0)(0/0), (0/0)(0/0), (0/0), (0/0), (0/0), (0/0), (0/0), (0/0), (0/0), (0/0), (0/0)]

You can't seem to remove any of the elements, but you can add more elements to the end.
Comment 1 Oliver Hunt 2011-01-18 12:52:48 PST
Created attachment 79312 [details]
Patch
Comment 2 Oliver Hunt 2011-01-18 13:10:15 PST
Committed r76049: <http://trac.webkit.org/changeset/76049>