Closed Bug 648004 Opened 9 years ago Closed 9 years ago
TI+JM: crash [@JSString::is
-- var x = eval("gc(); 30"); x.toString(); isNaN(x); -- Crashes at revision 7928f2dc3d4d with -n -m -a.
In ic::CallProp, js_GetClassPrototype could trigger a recompilation and pic->atom became invalid.
Assignee: general → jandemooij
Status: NEW → ASSIGNED
Attachment #524211 - Flags: review?(bhackett1024)
Comment on attachment 524215 [details] [diff] [review] Patch Erk. Really need to do a thorough review of MonoIC.cpp and PolyIC.cpp one of these days and kill these bugs.
Attachment #524215 - Flags: review?(bhackett1024) → review+
Status: ASSIGNED → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.