Closed Bug 768220 Opened 14 years ago Closed 4 years ago

Debugger: generator scopes lose unaliased variable values when the generator object is finalized

Categories

(Core :: JavaScript Engine, defect)

defect
Not set
normal

Tracking

()

RESOLVED WORKSFORME

People

(Reporter: luke, Unassigned)

References

(Blocks 1 open bug)

Details

(Whiteboard: [js:p3])

This test-case fails because, when the generator object is finalized, the scope proxy can't find the value of the unaliased variable 'y': var g = newGlobal('new-compartment'); new Debugger(g).onDebuggerStatement = function(frame) { frame.older.eval("escaped = function() { return y }"); } g.eval("function h() { debugger }"); g.eval("(function () { var y = 42; h(); yield })().next();"); assertEq(g.escaped(), 42); gc(); // generator object dies, but its scope lives on! assertEq(g.escaped(), 42); I think the fix is to eagerly copy frame values into the scope object when a generator yields. I wish there was a better way (like when you know the generator object will be finalized but, by that point, it's too late).
Whiteboard: [js:p3]

The bug assignee is inactive on Bugzilla, so the assignee is being reset.

Assignee: mail → nobody
Status: ASSIGNED → NEW

With small modifications to allow for changes in the newGlobal API / how generators are defined, this testcase now passes.

Status: NEW → RESOLVED
Closed: 4 years ago
Resolution: --- → WORKSFORME
You need to log in before you can comment on or make changes to this bug.