This is a followup for the bug 681884 comment 6. ArenaLists::refillFreeList, http://hg.mozilla.org/mozilla-central/file/a351ae35f2c4/js/src/jsgc.cpp#l1439 , contains: /* * For compatibility with older code we tolerate calling the allocator * during the GC in optimized builds. */ JSRuntime *rt = cx->runtime; JS_ASSERT(!rt->gcRunning); if (rt->gcRunning) return NULL; As that check is done each time we refil the free list it does not come for free. We should remove that and fix the broken callers that tries to allocate during the GC from finalizers or the GC callback.
Created attachment 561288 [details] [diff] [review] v1 The patch removes rt->gcRunning check from ArenaLists::refillFreeList. It was not necessary to make the try server green. Besides that check the patch also passes JSCompartment *, not JSContext *, to various helper methods that refillFreeList calls. It emphasis that error reporting is only done in refil and makes my other patches smaller.
Comment on attachment 561288 [details] [diff] [review] v1 Cool.