Closed Bug 1497568 Opened Last year Closed 20 days ago
Crash in js::jit::ICCall
This bug was filed from the Socorro interface and is report bp-c56e82c3-e91a-4eaa-b876-ae99a0181008. ============================================================= This startup crash is newly showing up in the 20181008100121 nightly builds. Top 8 frames of crashing thread: 0 xul.dll js::jit::ICCall_Scripted::ICCall_Scripted js/src/jit/BaselineIC.cpp:5883 1 xul.dll class js::jit::ICCall_Scripted* js::jit::ICStubSpace::allocate<js::jit::ICCall_Scripted, js::jit::JitCode*&, js::jit::ICStub*&, JS::Rooted<JSFunction*>&, JS::Rooted<JSObject*>&, unsigned int&> js/src/jit/ICStubSpace.h:36 2 xul.dll js::jit::ICCallScriptedCompiler::getStub js/src/jit/BaselineIC.h:2311 3 xul.dll static bool js::jit::TryAttachCallStub js/src/jit/BaselineIC.cpp:3537 4 xul.dll static bool js::jit::DoCallFallback js/src/jit/BaselineIC.cpp:3779 5 @0x27badb36ab9 6 xul.dll exp2 7 xul.dll exp2 =============================================================
I do not see anything obvious from this crashes. From my point of view the only way to explain this would be if the ICStubSpace, which uses LifoAlloc allocator were to return a pointer which is not in a BumpChunk. Which does not make any sense.
Status: NEW → RESOLVED
Closed: 20 days ago
Resolution: --- → WORKSFORME
You need to log in before you can comment on or make changes to this bug.