findReferences() crashes when called with no arguments

RESOLVED FIXED

Status

()

Core
JavaScript Engine
--
critical
RESOLVED FIXED
6 years ago
6 years ago

People

(Reporter: decoder, Unassigned)

Tracking

(Blocks: 1 bug, {crash, testcase})

Trunk
x86_64
Linux
crash, testcase
Points:
---
Dependency tree / graph

Firefox Tracking Flags

(Not tracked)

Details

Attachments

(1 attachment)

(Reporter)

Description

6 years ago
The findReferences function introduced in bug 672736 crashes when called with no arguments (tested on m-i 29e59859d415):

js> findReferences
function findReferences() {[native code]}
js> findReferences();
Segmentation fault


This should be fixed to prevent fuzzers from hitting this.

Comment 1

6 years ago
Created attachment 551981 [details] [diff] [review]
Pass a string to a JS error reporter that expects one.

Updated

6 years ago
Attachment #551981 - Flags: review?(jorendorff)

Comment 2

6 years ago
Never mind, jblandy already fixed this and push with a (no bug) message. Humbug. Marking fixed; it should be picked up in the merge tomorrow.
Status: NEW → RESOLVED
Last Resolved: 6 years ago
Resolution: --- → FIXED

Updated

6 years ago
Attachment #551981 - Flags: review?(jorendorff)
You need to log in before you can comment on or make changes to this bug.