Closed
Bug 1248420
Opened 8 years ago
Closed 8 years ago
js::ArraySetLength should return false when getGroup returns nullptr.
Categories
(Core :: JavaScript Engine, defect)
Core
JavaScript Engine
Tracking
()
RESOLVED
FIXED
mozilla47
Tracking | Status | |
---|---|---|
firefox47 | --- | fixed |
People
(Reporter: arai, Assigned: arai)
Details
Attachments
(1 file)
1.63 KB,
patch
|
jandem
:
review+
|
Details | Diff | Splinter Review |
Similar to bug 1248405, https://dxr.mozilla.org/mozilla-central/rev/e355cacefc881ba360d412853b57e8e060e966f4/js/src/jsarray.cpp#618 > ObjectGroup* arrGroup = arr->getGroup(cx); > if (!arr->isIndexed() && > !MOZ_UNLIKELY(!arrGroup || arrGroup->hasAllFlags(OBJECT_FLAG_ITERATED))) it should return false immediately when !arrGroup.
Assignee | ||
Comment 1•8 years ago
|
||
just handled group == nullptr case.
Assignee: nobody → arai.unmht
Attachment #8719517 -
Flags: review?(jdemooij)
Updated•8 years ago
|
Attachment #8719517 -
Flags: review?(jdemooij) → review+
Assignee | ||
Comment 2•8 years ago
|
||
https://hg.mozilla.org/integration/mozilla-inbound/rev/995ff53a4d50c9986e3475c1b4bc1ea8cc0f7aad Bug 1248420 - Handle JSObject::getGroup OOM in js::ArraySetLength. r=jandem
Comment 3•8 years ago
|
||
bugherder |
https://hg.mozilla.org/mozilla-central/rev/995ff53a4d50
Status: NEW → RESOLVED
Closed: 8 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla47
You need to log in
before you can comment on or make changes to this bug.
Description
•