Closed
Bug 618614
Opened 14 years ago
Closed 14 years ago
Incorrect result for array, for-in without GC
Categories
(Core :: JavaScript Engine, defect)
Tracking
()
RESOLVED
FIXED
Tracking | Status | |
---|---|---|
blocking2.0 | --- | betaN+ |
People
(Reporter: jandem, Assigned: dvander)
References
Details
(Keywords: regression, Whiteboard: [sg:nse][fixed-in-tracemonkey])
Attachments
(1 file)
2.38 KB,
patch
|
gal
:
review+
|
Details | Diff | Splinter Review |
Consider this test case: --- for(var i=0; i<3; i++) { var s = ''; var a = [0, 1]; a.b = 10; for (var x in a) { s += x; a.pop(); } print(s); //gc(); } --- This prints (interpreter/JM): 0b 01b 01b Commenting out the gc() call makes the problem go away: 0b 0b 0b
Reporter | ||
Comment 1•14 years ago
|
||
(In reply to comment #0) > Commenting out the gc() call makes the problem go away: s/commenting out/uncommenting
Reporter | ||
Updated•14 years ago
|
blocking2.0: --- → ?
Updated•14 years ago
|
Keywords: regression
Whiteboard: [sg:critical?]
Updated•14 years ago
|
blocking2.0: ? → betaN+
Assignee | ||
Comment 3•14 years ago
|
||
This is probably not sg:anything.
Attachment #497560 -
Flags: review?(gal)
Updated•14 years ago
|
Attachment #497560 -
Flags: review?(gal) → review+
Assignee | ||
Comment 4•14 years ago
|
||
http://hg.mozilla.org/tracemonkey/rev/abd854c5d634
Whiteboard: [sg:critical?] → [sg:critical?][fixed-in-tracemonkey]
Comment 5•14 years ago
|
||
http://hg.mozilla.org/mozilla-central/rev/abd854c5d634
Status: NEW → RESOLVED
Closed: 14 years ago
Resolution: --- → FIXED
Comment 7•13 years ago
|
||
not an exploit per comment 3
Whiteboard: [sg:critical?][fixed-in-tracemonkey] → [sg:nse][fixed-in-tracemonkey]
Updated•13 years ago
|
Group: core-security
You need to log in
before you can comment on or make changes to this bug.
Description
•