Closed
Bug 469621
Opened 16 years ago
Closed 16 years ago
"Assertion failure: *flagp != GCF_FINAL, at ../jsgc.cpp"
Categories
(Core :: JavaScript Engine, defect)
Tracking
()
VERIFIED
FIXED
People
(Reporter: gkw, Assigned: mrbkap)
Details
(4 keywords, Whiteboard: [sg:critical?] fixed-in-tracemonkey)
Attachments
(2 files)
750 bytes,
patch
|
crowderbt
:
review+
|
Details | Diff | Splinter Review |
2.46 KB,
text/plain
|
Details |
gczeal(2); eval('(function)', {}) asserts dbg at Assertion failure: *flagp != GCF_FINAL, at ../jsgc.cpp and different variants either crash debug js shell near null or at possibly exploitable locations. Possible regression of bug 446026?
Flags: blocking1.9.1?
Updated•16 years ago
|
Whiteboard: [sg:critical?]
Reporter | ||
Comment 1•16 years ago
|
||
Thanks Jesse for helping to reduce this testcase. TM is not needed to be enabled for this bug to occur.
Assignee | ||
Comment 2•16 years ago
|
||
Updated•16 years ago
|
Attachment #353132 -
Flags: review?(crowder) → review+
Comment 3•16 years ago
|
||
Comment on attachment 353132 [details] [diff] [review] Fix ugh, thanks
Assignee | ||
Comment 4•16 years ago
|
||
http://hg.mozilla.org/tracemonkey/rev/5f6d7c789505
Whiteboard: [sg:critical?] → [sg:critical?] fixed-in-tracemonkey
Updated•16 years ago
|
Flags: blocking1.9.1? → blocking1.9.1+
Comment 5•16 years ago
|
||
merged in mc
Status: ASSIGNED → RESOLVED
Closed: 16 years ago
Resolution: --- → FIXED
Comment 6•16 years ago
|
||
http://hg.mozilla.org/releases/mozilla-1.9.1/rev/ae3928490f31
Keywords: fixed1.9.1
Comment 7•16 years ago
|
||
Updated•16 years ago
|
Flags: in-testsuite+
Flags: in-litmus-
Comment 8•16 years ago
|
||
v 1.9.1, 1.9.2
Status: RESOLVED → VERIFIED
Keywords: fixed1.9.1 → verified1.9.1
Comment 9•14 years ago
|
||
when this bug is opened, the test should be checked in.
Flags: in-testsuite+ → in-testsuite?
Updated•11 years ago
|
Group: core-security
You need to log in
before you can comment on or make changes to this bug.
Description
•