Closed
Bug 1158407
Opened 9 years ago
Closed 9 years ago
[jsdbg2] Crash under Debugger::appendAllocationSite
Categories
(DevTools :: Debugger, defect)
DevTools
Debugger
Tracking
(firefox40 fixed)
RESOLVED
FIXED
Firefox 40
Tracking | Status | |
---|---|---|
firefox40 | --- | fixed |
People
(Reporter: fitzgen, Assigned: shu)
Details
Attachments
(1 file, 1 obsolete file)
7.47 KB,
patch
|
terrence
:
review+
|
Details | Diff | Splinter Review |
STR: * Load amazon.com * Open devtools profiler * Enable "record memory" in profiler options menu * start recording * refresh
Reporter | ||
Comment 1•9 years ago
|
||
The VM function NewGCObject[0] called by Ion from createThisWithTemplate[1] calls the object metadata hook with a not-yet-fully-initialized JSObject in the nursery that doesn't have its group set yet. [0] https://dxr.mozilla.org/mozilla-central/source/js/src/jit/VMFunctions.cpp#97 [1] https://dxr.mozilla.org/mozilla-central/source/js/src/jit/CodeGenerator.cpp#4806
Assignee | ||
Comment 2•9 years ago
|
||
Not sure how to fix this without duplicating all of masm.initGCThing inside NewGCObject, which is gross.
Assignee | ||
Comment 3•9 years ago
|
||
Assignee | ||
Updated•9 years ago
|
Attachment #8597554 -
Flags: review?(terrence)
Comment 5•9 years ago
|
||
Comment on attachment 8597554 [details] [diff] [review] Stop using this one weird allocation fallback for MCreateThisWithTemplate. Review of attachment 8597554 [details] [diff] [review]: ----------------------------------------------------------------- \o/ It's absolutely *wonderful* to see that go!
Attachment #8597554 -
Flags: review?(terrence) → review+
Comment 7•9 years ago
|
||
https://hg.mozilla.org/mozilla-central/rev/6adf6c6f9794
Status: NEW → RESOLVED
Closed: 9 years ago
status-firefox40:
--- → fixed
Resolution: --- → FIXED
Target Milestone: --- → Firefox 40
Updated•9 years ago
|
Assignee: nobody → shu
Updated•6 years ago
|
Product: Firefox → DevTools
You need to log in
before you can comment on or make changes to this bug.
Description
•