Who can spot the use-after-free bug in this code? hg.mozilla.org/mozilla-centr…
1
@nsIAnswers nothing's holding a ref to *result, so the NS_SetThreadName might release it?
2
@vvuk @nsIAnswers I don't think so; NS_NewThread leaves the object w/ refcount=1, and that 1 ref is reserved for caller of NS_NewNamedThread
2
@CodingExon @vvuk @nsIAnswers Assuming it hasn't been put in a member variable from which it can be released before fn finishes
Apr 17, 2014 · 1:00 AM UTC



