Closed
Bug 489440
Opened 16 years ago
Closed 16 years ago
QueryInterface in XPCWrappedNative::FlatJSObjectFinalized can reenter JS
Categories
(Core :: XPConnect, defect)
Tracking
()
RESOLVED
FIXED
People
(Reporter: dbaron, Assigned: mrbkap)
References
Details
(Keywords: fixed1.9.1)
Attachments
(2 files)
|
8.76 KB,
patch
|
Details | Diff | Splinter Review | |
|
1.41 KB,
patch
|
peterv
:
review+
peterv
:
superreview+
beltzner
:
approval1.9.1+
|
Details | Diff | Splinter Review |
mrbkap says I should file this as a bug, and that it's a regression from peterv's change a month ago:
nsWrapperCache *cache = nsnull;
CallQueryInterface(mIdentity, &cache);
if(cache)
cache->ClearWrapper();
added in http://hg.mozilla.org/mozilla-central/rev/1e484f30d821
Note that leak-monitor might be needed to trigger this; it's on the stack, but only as the caller to js_GC. mrbkap says you also need a double-wrapped object in a context that's already had its Components object removed.
| Assignee | ||
Comment 1•16 years ago
|
||
This seems like the easiest way to fix this bug. I think it's correct, since if we're a double wrapped object, we can't have possibly cached a wrapper.
Assignee: nobody → mrbkap
Status: NEW → ASSIGNED
Attachment #373945 -
Flags: superreview?(peterv)
Attachment #373945 -
Flags: review?(peterv)
Updated•16 years ago
|
Attachment #373945 -
Flags: superreview?(peterv)
Attachment #373945 -
Flags: superreview+
Attachment #373945 -
Flags: review?(peterv)
Attachment #373945 -
Flags: review+
| Assignee | ||
Comment 2•16 years ago
|
||
Status: ASSIGNED → RESOLVED
Closed: 16 years ago
Resolution: --- → FIXED
Comment 3•16 years ago
|
||
Do we want this on branch (bug 484692 is on it)?
| Reporter | ||
Comment 4•16 years ago
|
||
I certainly would. Without it, leak monitor would be pretty crashy, I think.
Flags: wanted1.9.1?
Comment 5•16 years ago
|
||
Comment on attachment 373945 [details] [diff] [review]
Proposed fix
Should take this on branch, needed to make Leak Monitor work.
Attachment #373945 -
Flags: approval1.9.1?
Comment 6•16 years ago
|
||
Comment on attachment 373945 [details] [diff] [review]
Proposed fix
a191=beltzner
Attachment #373945 -
Flags: approval1.9.1? → approval1.9.1+
| Assignee | ||
Comment 7•16 years ago
|
||
Keywords: fixed1.9.1
You need to log in
before you can comment on or make changes to this bug.
Description
•