diff --git a/mozilla/js/src/jslock.c b/mozilla/js/src/jslock.c index 54b4da4bf90..0a0e126c830 100644 --- a/mozilla/js/src/jslock.c +++ b/mozilla/js/src/jslock.c @@ -1242,6 +1242,15 @@ js_LockObj(JSContext *cx, JSObject *obj) JSScope *scope; JS_ASSERT(OBJ_IS_NATIVE(obj)); + + /* + * We must test whether the GC is calling and return without mutating any + * state, especially cx->lockedSealedScope. Note asymmetry with respect to + * js_UnlockObj, which is a thin-layer on top of js_UnlockScope. + */ + if (CX_THREAD_IS_RUNNING_GC(cx)) + return; + for (;;) { scope = OBJ_SCOPE(obj); if (SCOPE_IS_SEALED(scope) && scope->object == obj &&