mirror of
https://github.com/fergalmoran/ladybird.git
synced 2025-12-27 03:37:53 +00:00
LibJS: Do not invoke Cell::vm in constructors before Cell is constructed
In a subclass of Cell, we cannot use Cell::vm() before the base Cell object itself is constructed. Use the Realm's VM instead. This was caught by UBSAN with vptr sanitation enabled.
This commit is contained in:
committed by
Andreas Kling
parent
3efe611dbf
commit
85e313077a
@@ -13,7 +13,7 @@
|
||||
namespace JS {
|
||||
|
||||
AsyncFunctionConstructor::AsyncFunctionConstructor(Realm& realm)
|
||||
: NativeFunction(vm().names.AsyncFunction.as_string(), *realm.intrinsics().function_constructor())
|
||||
: NativeFunction(realm.vm().names.AsyncFunction.as_string(), *realm.intrinsics().function_constructor())
|
||||
{
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user