crash [@ JS_ValueToString - JSValIDToString] with DEBUG_CAPS_HACKER

RESOLVED FIXED

Status

()

Core
Security: CAPS
--
critical
RESOLVED FIXED
13 years ago
10 years ago

People

(Reporter: timeless, Assigned: timeless)

Tracking

({crash})

Trunk
x86
Windows XP
crash
Points:
---

Firefox Tracking Flags

(Not tracked)

Details

(crash signature)

Attachments

(1 attachment)

690 bytes, patch
Christopher Aillon (sabbatical, not receiving bugmail)
: review+
dveditz
: superreview+
Details | Diff | Splinter Review
(Assignee)

Description

13 years ago
I had a crash under:
JS_ValueToString
JSValIDToString
PrintPropertyPolicy
PL_DHashTableEnumerate
PrintClassPolicy
nsScriptSecurityManager::PrintPolicyDB
nsScriptSecurityManager::InitPolicies
nsScriptSecurityManager::LookupPolicy
nsScriptSecurityManager::CanExecuteScripts
IsScriptEnabled

where arg/cx are null. note that certain pieces of the code use the safe 
context and the crashing piece uses the stack of active contexts.
(Assignee)

Comment 1

13 years ago
Created attachment 192141 [details] [diff] [review]
fall back to safe [checked in]
Attachment #192141 - Flags: superreview?(dveditz)
Attachment #192141 - Flags: review?(caillon)
Comment on attachment 192141 [details] [diff] [review]
fall back to safe [checked in]

sr=dveditz
Attachment #192141 - Flags: superreview?(dveditz) → superreview+
Attachment #192141 - Flags: review?(caillon) → review+
Comment on attachment 192141 [details] [diff] [review]
fall back to safe [checked in]

This patch got checked in a long time ago. Is there more work needing to be done in this bug or can it be marked FIXED?
Attachment #192141 - Attachment description: fall back to safe → fall back to safe [checked in]
(Assignee)

Comment 4

10 years ago
Comment on attachment 192141 [details] [diff] [review]
fall back to safe [checked in]

mozilla/caps/src/nsScriptSecurityManager.cpp 	1.269
Status: NEW → RESOLVED
Last Resolved: 10 years ago
Resolution: --- → FIXED
Crash Signature: [@ JS_ValueToString - JSValIDToString]
You need to log in before you can comment on or make changes to this bug.