[webkit-changes] [WebKit/WebKit] 590121: Speculative mitigation against a crash involving C...

Commit Queue noreply at github.com
Fri May 24 17:22:47 PDT 2024


  Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 59012130505d6145ec4e7a8dc6e718106a8baba7
      https://github.com/WebKit/WebKit/commit/59012130505d6145ec4e7a8dc6e718106a8baba7
  Author: Mark Lam <mark.lam at apple.com>
  Date:   2024-05-24 (Fri, 24 May 2024)

  Changed paths:
    M Source/JavaScriptCore/bytecode/CodeBlock.cpp
    M Source/JavaScriptCore/bytecode/MetadataTable.cpp
    M Source/JavaScriptCore/bytecode/MetadataTable.h

  Log Message:
  -----------
  Speculative mitigation against a crash involving CodeBlock::m_metadata.
https://bugs.webkit.org/show_bug.cgi?id=274691
rdar://127571559

Reviewed by Yijia Huang and Yusuke Suzuki.

We sometimes see crashes due to CodeBlock::m_metadata->unlinkedMetadata() being null.
This change adds a speculative null check to mitigate against stepping on this.

* Source/JavaScriptCore/bytecode/CodeBlock.cpp:
(JSC::CodeBlock::~CodeBlock):
* Source/JavaScriptCore/bytecode/MetadataTable.cpp:
(JSC::MetadataTable::destroy):
* Source/JavaScriptCore/bytecode/MetadataTable.h:
(JSC::MetadataTable::isDestroyed const):

Canonical link: https://commits.webkit.org/279300@main



To unsubscribe from these emails, change your notification settings at https://github.com/WebKit/WebKit/settings/notifications


More information about the webkit-changes mailing list