Crash in JSContext::verifyIsSafeToGC

RESOLVED FIXED in Firefox 58

Status

()

defect
P1
critical
RESOLVED FIXED
2 years ago
2 years ago

People

(Reporter: calixte, Assigned: aosmond)

Tracking

(Blocks 1 bug, {crash, regression})

58 Branch
mozilla58
Unspecified
Windows 10
Points:
---
Dependency tree / graph

Firefox Tracking Flags

(firefox-esr52 unaffected, firefox56 unaffected, firefox57 unaffected, firefox58 fixed)

Details

(Whiteboard: [gfx-noted][clouseau], crash signature)

Attachments

(1 attachment)

This bug was filed from the Socorro interface and is 
report bp-a538c70c-f7a2-484f-a729-c6b890171105.
=============================================================

There are 11 crashes in nightly 58 starting with buildid 20171101220120. In analyzing the backtrace, the regression may have been introduced by patch [1] to fix bug 1404422.

[1] https://hg.mozilla.org/mozilla-central/rev?node=1b420c5a7b11eaf2fa1849f90769659f5146a8e9
Flags: needinfo?(aosmond)
I see the oversight on my part. Simple enough to fix.
Assignee: nobody → aosmond
Status: NEW → ASSIGNED
Flags: needinfo?(aosmond)
Priority: -- → P1
Whiteboard: [clouseau] → [gfx-noted][clouseau]
Group: core-security
Duplicate of this bug: 1414433
Attachment #8925489 - Flags: review?(tnikkel) → review+
Status: ASSIGNED → RESOLVED
Closed: 2 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla58
Blocks: 1413981
Duplicate of this bug: 1413981
Duplicate of this bug: 1414913
Group: core-security → core-security-release
Duplicate of this bug: 1415476
Duplicate of this bug: 1414427
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.