Bug 64562 - DFG JIT crashes on host constructor calls in debug mode
Summary: DFG JIT crashes on host constructor calls in debug mode
Alias: None
Product: WebKit
Classification: Unclassified
Component: JavaScriptCore (show other bugs)
Version: 528+ (Nightly build)
Hardware: All All
: P2 Normal
Assignee: Nobody
Depends on:
Reported: 2011-07-14 14:43 PDT by Filip Pizlo
Modified: 2011-07-14 16:38 PDT (History)
4 users (show)

See Also:

the patch (4.14 KB, patch)
2011-07-14 14:52 PDT, Filip Pizlo
no flags Details | Formatted Diff | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Filip Pizlo 2011-07-14 14:43:27 PDT
The DFG JIT's support for host constructor calls has a broken ASSERT statement that results in crashes in debug mode.
Comment 1 Filip Pizlo 2011-07-14 14:52:15 PDT
Created attachment 100867 [details]
the patch
Comment 2 WebKit Review Bot 2011-07-14 16:26:58 PDT
Comment on attachment 100867 [details]
the patch

Clearing flags on attachment: 100867

Committed r91034: <http://trac.webkit.org/changeset/91034>
Comment 3 WebKit Review Bot 2011-07-14 16:27:02 PDT
All reviewed patches have been landed.  Closing bug.
Comment 4 Vincent Scheib 2011-07-14 16:38:23 PDT
Committed r91035: <http://trac.webkit.org/changeset/91035>