Status: New
Owner: ----

New issue 191 by nth10sd:  
CHECK(context_ext->GetLocalPropertyAttribute(*name) == mode) failed
http://code.google.com/p/v8/issues/detail?id=191

({}).__proto__.__defineSetter__("x", function(){});
function f(foo) { eval(foo); }
f("var x, x = null;");

This seems to work as expected in opt compiled with "scons mode=release
library=static snapshot=on sample=shell".

This asserts debug compiled with "scons mode=debug library=shared
snapshot=on sample=shell" at
CHECK(context_ext->GetLocalPropertyAttribute(*name) == mode) failed

===

$ ./shell_g
V8 version 0.4.8 (candidate)
> ({}).__proto__.__defineSetter__("x", function(){});
function f(foo) { eval(foo); }
f("var x, x = null;");
[object Object]
> >

#
# Fatal error in src/runtime.cc, line 557
# CHECK(context_ext->GetLocalPropertyAttribute(*name) == mode) failed
#


==== Stack trace ============================================

Security context: 0x1c0d449 <JS Object>#0#
     1: /* anonymous */(this=0x1c0d47d <JS Global Object>#1#)
     2: arguments adaptor frame: 1->0
     3: f(this=0x1c0d47d <JS Global Object>#1#,foo=0x1e07171 <String[16]:
var x, x = null;>)
     4: /* anonymous */(this=0x1c0d47d <JS Global Object>#1#)

==== Details ================================================

[1]: /* anonymous */(this=0x1c0d47d <JS Global Object>#1#) {
   // stack-allocated locals
   var .result = 0x1e00135 <undefined>
   // expression stack (top to bottom)
   [04] : 0
   [03] : 0
   [02] : 0x1e001e1 <String[1]: x>
   [01] : 0x181fd75 <FixedArray[7]>#2#
--------- s o u r c e   c o d e ---------
var x, x = null;
-----------------------------------------
}

[2]: arguments adaptor frame: 1->0 {
   // actual arguments
   [00] : 0x1e07171 <String[16]: var x, x = null;>  // not passed to callee
}

[3]: f(this=0x1c0d47d <JS Global Object>#1#,foo=0x1e07171 <String[16]: var
x, x = null;>) {
   // heap-allocated locals
   var .arguments = 0x181fd55 <an Arguments>>#3#
   var arguments = 0x181fd55 <an Arguments>>#3#
   // expression stack (top to bottom)
   [00] : 0x1c0f8e5 <JS Function>#4#
--------- s o u r c e   c o d e ---------
function f(foo) { eval(foo); }
-----------------------------------------
}

[4]: /* anonymous */(this=0x1c0d47d <JS Global Object>#1#) {
   // stack-allocated locals
   var .result = 0x1e00135 <undefined>
   // expression stack (top to bottom)
   [01] : 0x1e03ed9 <String[1]: f>
--------- s o u r c e   c o d e ---------
f("var x, x = null;");?
-----------------------------------------
}

==== Key         ============================================

  #0# 0x1c0d449: 0x1c0d449 <JS Object>
                NaN: 0x1e03e4d <Number: nan>
               Math: 0x180ed29 <a MathConstructor>>#5#
           Infinity: 0x1e04111 <Number: inf>
          undefined: 0x1e00135 <undefined>
  #1# 0x1c0d47d: 0x1c0d47d <JS Global Object>
  #2# 0x181fd75: 0x181fd75 <FixedArray[7]>
                  0: 0x1c0f83d <JS Function f>#6#
                  1: 0x181fd75 <FixedArray[7]>#2#
                  2: 0
                  3: 0x181fff1 <JS Object>#7#
                  4: 0x1c0d449 <JS Object>#0#
                  5: 0x181fd55 <an Arguments>>#3#
                  6: 0x181fd55 <an Arguments>>#3#
  #3# 0x181fd55: 0x181fd55 <an Arguments>>
             callee: 0x1c0f83d <JS Function f>#6#
             length: 1
  #4# 0x1c0f8e5: 0x1c0f8e5 <JS Function>
  #5# 0x180ed29: 0x180ed29 <a MathConstructor>>
                  E: 0x1e05695 <Number: 2.718281828459045>
                 PI: 0x1e05715 <Number: 3.141592653589793>
                LN2: 0x1e056c5 <Number: 0.6931471805599453>
               LN10: 0x1e056ad <Number: 2.302585092994046>
              SQRT2: 0x1e0574d <Number: 1.414213562373095>
              LOG2E: 0x1e056e1 <Number: 1.442695040888963>
             LOG10E: 0x1e056fd <Number: 0.4342944819032518>
            SQRT1_2: 0x1e05731 <Number: 0.7071067811865476>
  #6# 0x1c0f83d: 0x1c0f83d <JS Function f>
  #7# 0x181fff1: 0x181fff1 <JS Object>
=====================

Abort trap
$ svn log | head
------------------------------------------------------------------------
r1072 | [email protected] | 2009-01-14 20:13:26 +0800 (Wed, 14 Jan 2009) |
7 lines

Fix issue 186:

     http://code.google.com/p/v8/issues/detail?id=186

Create a new instance type for context extension objects.  Use it to
not use the __proto__ accessor for context extension objects.
Review URL: http://codereview.chromium.org/18044

--
You received this message because you are listed in the owner
or CC fields of this issue, or because you starred this issue.
You may adjust your issue notification preferences at:
http://code.google.com/hosting/settings

--~--~---------~--~----~------------~-------~--~----~
v8-dev mailing list
[email protected]
http://groups.google.com/group/v8-dev
-~----------~----~----~----~------~----~------~--~---

Reply via email to