Changeset 92804 in webkit
- Timestamp:
- Aug 10, 2011 5:17:05 PM (13 years ago)
- Location:
- trunk/Source/JavaScriptCore
- Files:
-
- 2 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/Source/JavaScriptCore/ChangeLog
r92797 r92804 1 2011-08-10 Filip Pizlo <fpizlo@apple.com> 2 3 REGRESSION(r92670-r92744): WebKit crashes when opening Gmail 4 https://bugs.webkit.org/show_bug.cgi?id=66010 5 6 Reviewed by Oliver Hunt. 7 8 Made sure that Construct calls use() on the this argument. 9 10 * dfg/DFGJITCodeGenerator.cpp: 11 (JSC::DFG::JITCodeGenerator::emitCall): 12 1 13 2011-08-10 Mark Hahnenberg <mhahnenberg@apple.com> 2 14 -
trunk/Source/JavaScriptCore/dfg/DFGJITCodeGenerator.cpp
r92732 r92804 1000 1000 m_jit.storePtr(GPRInfo::callFrameRegister, addressOfCallData(RegisterFile::CallerFrame)); 1001 1001 1002 if (node.op == Construct) 1003 use(m_jit.graph().m_varArgChildren[node.firstChild() + 1]); 1004 1002 1005 for (int argIdx = (node.op == Call ? 0 : 1); argIdx < numArgs; argIdx++) { 1003 1006 NodeIndex argNodeIndex = m_jit.graph().m_varArgChildren[node.firstChild() + 1 + argIdx];
Note: See TracChangeset
for help on using the changeset viewer.