SpiderMonkey IonMonkey Type Confusion
Posted by deepcore on March 28, 2019 – 11:05 pm
A bug in IonMonkeys type inference system when JIT compiling and entering a constructor function via on-stack replacement (OSR) allows the compilation of JITed functions that cause type confusions between arbitrary objects.
Post a reply
You must be logged in to post a comment.