Open Bug 1941192 Opened 7 months ago Updated 4 months ago

With semispace nursery enabled, crash with a large image input on https://stefan-oltmann.de/exif-viewer/

Categories

(Core :: JavaScript Engine, defect, P3)

defect

Tracking

()

Tracking Status
firefox-esr115 --- unaffected
firefox-esr128 --- disabled
firefox134 --- disabled
firefox135 --- disabled
firefox136 --- disabled

People

(Reporter: mayankleoboy1, Unassigned, NeedInfo)

References

(Blocks 1 open bug, Regression, )

Details

(Keywords: regression)

Attachments

(3 files)

5.90 MB, application/x-zip-compressed
Details
9.00 MB, application/octet-stream
Details
9.00 MB, application/octet-stream
Details

Enable semispace nurser by setting javascript.options.mem.gc_experimental_semispace_nursery = true
Restart Firefox
Go to https://stefan-oltmann.de/exif-viewer/
Select the attached image (or use a 30MB+ local .PNG file as input)

AR: Crash. https://crash-stats.mozilla.org/report/index/910f72be-f1d4-45ad-af5b-a8e000250112#tab-bugzilla
ER: Not so

Flags: needinfo?(jcoppeard)
Attached file free_down.zip
Attached file free_down.z01
Attached file free_down.z02
No longer blocks: 1787526
Regressed by: 1787526

Set release status flags based on info from the regressing bug 1787526

This bug is not related to the topcrash signature since it requires enabling semispace nursery which is disabled by default.

Keywords: topcrash

Sometimes the tab will just hang without using any CPU.

Blocks: GC.stability
Severity: -- → S4
Crash Signature: [@ js::gc::InCollectedNurseryRegion ]
Priority: -- → P3
Summary: With semispace nursery enabled, crash with a large image input on https://stefan-oltmann.de/exif-viewer/ [@ js::gc::InCollectedNurseryRegion ] → With semispace nursery enabled, crash with a large image input on https://stefan-oltmann.de/exif-viewer/

The stack shows this going through StoreBuffer::traceWasmAnyRefs so it may be a problem with postbarriers in Wasm.

See Also: → 1963626
Crash Signature: [@ js::gc::InCollectedNurseryRegion ]
Crash Signature: [@ js::gc::InCollectedNurseryRegion ]

still crashes.

You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: