Closed Bug 1708976 Opened 5 years ago Closed 5 years ago

Assertion failure: input->type() == MIRType::Double

Categories

(Core :: JavaScript Engine: JIT, defect)

defect

Tracking

()

RESOLVED DUPLICATE of bug 1593971

People

(Reporter: 1422930734, Unassigned)

Details

(Keywords: reporter-external, Whiteboard: [reporter-external] [client-bounty-form] [verif?])

Attachments

(1 file)

389 bytes, text/plain
Details
Attached file 1

Assertion failure: input->type() == MIRType::Double, at /root/AFL/compile/gecko-dev/js/src/jit/Lowering.cpp:2906
Segmentation fault (core dumped)

Flags: sec-bounty?
Group: firefox-core-security → core-security
Type: task → defect
Component: Security → JavaScript Engine: JIT
Product: Firefox → Core
Group: core-security → javascript-core-security

Thanks for the report.

I can't reproduce this on central so we'll need some additional information:

  • Which branch (and code commit) did you use? I checked the central/beta/release/esr78 branches and I don't see that assertion on Lowering.cpp:2906.
  • What's the architecture? 32-bit or 64-bit?
Flags: needinfo?(1422930734)

version: JavaScript-C72.0a1
architecture: 64-bit

Flags: needinfo?(1422930734)

Firefox 72 is no longer supported. You'll need to find a more recent build of Firefox that is affected.

Can you reproduce this issue on a more recent version? ESR78 is the most recent version that is still supported.

Flags: needinfo?(1422930734)

If we get more info we can reopen this bug, but looks like it got fixed some time in the last year+

In fact a bug with this assertion was fixed in Release 72 which would be later than your nightly build

Status: UNCONFIRMED → RESOLVED
Closed: 5 years ago
Resolution: --- → WORKSFORME

Same assert as bug 1593971, which was fixed in 72.

Group: javascript-core-security
Flags: sec-bounty? → sec-bounty-
Resolution: WORKSFORME → DUPLICATE
Flags: needinfo?(1422930734)
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: