Note: There are a few cases of duplicates in user autocompletion which are being worked on.

[jsdbg2] Crash when a scripted proxy handler throws Error.prototype

RESOLVED FIXED in mozilla9

Status

()

Core
JavaScript Engine
RESOLVED FIXED
6 years ago
6 years ago

People

(Reporter: jorendorff, Assigned: jorendorff)

Tracking

9 Branch
mozilla9
x86
Mac OS X
Points:
---

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: [inbound])

Attachments

(1 attachment, 1 obsolete attachment)

(Assignee)

Description

6 years ago
Waldo spotted this by reading the code.

var g = newGlobal('new-compartment');
var dbg = Debugger(g);
dbg.onDebuggerStatement = function (frame) {
    try {
	frame.arguments[0].deleteProperty("x");
    } catch (exc) {
	return;
    }
    throw new Error("deleteProperty should throw");
};

g.eval("function h(x) { debugger; }");
g.eval("h(Proxy.create({delete: function () { throw Error.prototype; }}));");
(Assignee)

Comment 1

6 years ago
Created attachment 553206 [details] [diff] [review]
v1

Note that this also adds ErrorCopiers to a few other places where we run the risk of causing the debuggee to run.
Assignee: general → jorendorff
Attachment #553206 - Flags: review?(jimb)
(Assignee)

Comment 2

6 years ago
Created attachment 553914 [details] [diff] [review]
v2

Same as v1, but actually include the test. Shift review to jwalden since jimb is on vacation.
Attachment #553206 - Attachment is obsolete: true
Attachment #553206 - Flags: review?(jimb)
Attachment #553914 - Flags: review?(jwalden+bmo)
Comment on attachment 553914 [details] [diff] [review]
v2

Review of attachment 553914 [details] [diff] [review]:
-----------------------------------------------------------------

This is kind of rubberstampy, I don't actually know that you've addressed every place where this has to happen, but it looks plausible.  Someone else can find the remaining instances, if there are any.
Attachment #553914 - Flags: review?(jwalden+bmo) → review+
(Assignee)

Comment 4

6 years ago
hg.mozilla.org/integration/mozilla-inbound/rev/6bb148047bb5
Whiteboard: [inbound]
Target Milestone: --- → mozilla8
Version: Other Branch → 9 Branch
http://hg.mozilla.org/mozilla-central/rev/6bb148047bb5
Status: NEW → RESOLVED
Last Resolved: 6 years ago
Resolution: --- → FIXED
Target Milestone: mozilla8 → mozilla9
(Assignee)

Updated

6 years ago
Duplicate of this bug: 684587
You need to log in before you can comment on or make changes to this bug.