[Webkit-unassigned] [Bug 65128] DFG JIT bytecode parser misuses pointers into objects allocated as part of a WTF::Vector

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Mon Jul 25 14:57:02 PDT 2011


https://bugs.webkit.org/show_bug.cgi?id=65128


Filip Pizlo <fpizlo at apple.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
 Attachment #101900|0                           |1
        is obsolete|                            |




--- Comment #6 from Filip Pizlo <fpizlo at apple.com>  2011-07-25 14:57:02 PST ---
Created an attachment (id=101916)
 --> (https://bugs.webkit.org/attachment.cgi?id=101916&action=review)
the patch (fixed for real this time)

This addresses the issue that Darin noticed.  Tests still running, will change review/commit-queue to ? once (if) they pass.

-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.



More information about the webkit-unassigned mailing list