Closed Bug 1547467 Opened 7 months ago Closed 6 months ago

Assertion failure: JSID_IS_ATOM(id) && frontend::IsIdentifierNameOrPrivateName(JSID_TO_ATOM(id)), at js/src/vm/StringType.cpp:2216


(Core :: JavaScript Engine, defect, P1, critical)




The following testcase crashes on mozilla-central revision 0ec836eceb96 (build with --enable-posix-nspr-emulation --enable-valgrind --enable-gczeal --disable-tests --disable-profiling --enable-debug --enable-optimize, run with --fuzzing-safe --cpu-count=2):

class foo extends null {
    constructor(a = class bar extends bar {}) {}
new foo();


received signal SIGSEGV, Segmentation fault.
#0  js::IdToPrintableUTF8 (cx=<optimized out>, cx@entry=0x7ffff5f19000, id=id@entry=..., behavior=behavior@entry=js::IdToPrintableBehavior::IdIsIdentifier) at js/src/vm/StringType.cpp:2214
#1  0x00005555558d0726 in js::ReportRuntimeLexicalError (id=..., errorNumber=79, cx=0x7ffff5f19000) at js/src/vm/Interpreter.cpp:5304
#2  js::ReportRuntimeLexicalError (cx=<optimized out>, cx@entry=0x7ffff5f19000, errorNumber=errorNumber@entry=79, name=..., name@entry=...) at js/src/vm/Interpreter.cpp:5313
#3  0x00005555558d3dbb in js::ReportRuntimeLexicalError (cx=0x7ffff5f19000, errorNumber=79, script=..., pc=0x7ffff5ffb6a3 "\212\002") at js/src/vm/Interpreter.cpp:5336
#4  0x00005555558e5655 in js::ReportUninitializedLexical (pc=<optimized out>, script=..., cx=<optimized out>) at js/src/vm/Interpreter-inl.h:109
#5  js::CheckUninitializedLexical (val=..., pc=<optimized out>, script=..., cx=<optimized out>) at js/src/vm/Interpreter-inl.h:125
#6  Interpret (cx=0x7ffff5f19000, state=...) at js/src/vm/Interpreter.cpp:3445
#7  0x00005555558e8716 in js::RunScript (cx=0x7ffff5f19000, state=...) at js/src/vm/Interpreter.cpp:423
#16 main (argc=<optimized out>, argv=<optimized out>, envp=<optimized out>) at js/src/shell/js.cpp:11373
JSBugMon: Bisection requested, result:
autoBisect shows this is probably related to the following changeset:

The first bad revision is:
user:        Ashley Hauck
date:        Thu Apr 11 23:07:06 2019 +0000
summary:     Bug 1542448 - Copy .initializers to .localInitializers for derived classes. r=jorendorff

This iteration took 498.677 seconds to run.

Ashley, is bug 1542448 a likely regressor?

Regressed by: 1542448
Priority: -- → P1
Assignee: nobody → khyperia
Pushed by
Introduce another scope for .initializers, and remove .localInitializers. r=jorendorff
Closed: 6 months ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla69

Is this worth uplifting to 68?

I don't know - punting to sdetar for that question.

However, if you do take this, you should also take the bugs that were caused by this (bug 1553744 then bug 1555979).

Talking with Ashley about this, I would currently considering not recommending uplifting this Fx68 unless there is significant reason to do so as there seems to be some risks in doing so. These risks come from this is a complex problem to fix as well as a number of other dependent patches will also have to be uplifted. It does not seem like a simple uplift.

Jason, do you have any thoughts on that?

I agree: don't uplift. The feature is behind a pref.

