Closed Bug 1972784 Opened 1 year ago Closed 1 year ago

Assertion failure: frame.isDebuggee(), at /js/src/debugger/DebugAPI-inl.h:77 with experimental.self_hosted_cache=true

Categories

(Core :: JavaScript Engine, defect, P3)

x86_64
Linux
defect

Tracking

()

RESOLVED FIXED
142 Branch
Tracking Status
firefox-esr128 --- unaffected
firefox-esr140 --- wontfix
firefox139 --- unaffected
firefox140 --- wontfix
firefox141 --- wontfix
firefox142 --- fixed

People

(Reporter: decoder, Assigned: bthrall)

References

(Blocks 2 open bugs, Regression)

Details

(Keywords: assertion, regression, testcase, Whiteboard: [bugmon:update,bisect])

Attachments

(3 files)

The following testcase crashes on mozilla-central revision 20250618-5fb84cb353d4 (debug build, run with --fuzzing-safe --ion-offthread-compile=off --setpref=experimental.self_hosted_cache=true --more-compartments):

this.__defineGetter__("", eval);
a = newGlobal();
Debugger(a).onEnterFrame = function() {}
a.__defineGetter__();

Backtrace:

received signal SIGSEGV, Segmentation fault.
#0  0x000055555705ffaf in js::DebugAPI::onLeaveFrame(JSContext*, js::AbstractFramePtr, unsigned char const*, bool) ()
#1  0x0000555557c55063 in js::jit::DebugEpilogue(JSContext*, js::jit::BaselineFrame*, unsigned char const*, bool) ()
#2  0x00005555580713c4 in js::jit::HandleException(js::jit::ResumeFromException*) ()
#3  0x000012829ea44a76 in ?? ()
[...]
#41 0x0000000000000000 in ?? ()
rax	0x0	0
rbx	0x0	0
rcx	0x4d	77
rdx	0x1	1
rsi	0x0	0
rdi	0x7ffff7bee7d0	140737349871568
rbp	0x7fffffffbfd0	140737488338896
rsp	0x7fffffffbfa0	140737488338848
r8	0x0	0
r9	0x3	3
r10	0x0	0
r11	0x0	0
r12	0xd740059a060	14791873241184
r13	0x5555559ad048	93824996790344
r14	0x7ffff460a35f	140737293362015
r15	0x7ffff463a200	140737293558272
rip	0x55555705ffaf <js::DebugAPI::onLeaveFrame(JSContext*, js::AbstractFramePtr, unsigned char const*, bool)+799>
=> 0x55555705ffaf <_ZN2js8DebugAPI12onLeaveFrameEP9JSContextNS_16AbstractFramePtrEPKhb+799>:	mov    %rcx,(%rax)
   0x55555705ffb2 <_ZN2js8DebugAPI12onLeaveFrameEP9JSContextNS_16AbstractFramePtrEPKhb+802>:	callq  0x555556f5ff70 <abort>
Attached file Testcase —
Flags: needinfo?(bthrall)

Unable to reproduce bug 1972784 using build mozilla-central 20250618042918-5fb84cb353d4. Without a baseline, bugmon is unable to analyze this bug.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.

Keywords: bugmon
Regressed by: 1827914

Set release status flags based on info from the regressing bug 1827914

Set release status flags based on info from the regressing bug 1827914

Blocks: js-debugger
Severity: -- → S3
Priority: -- → P3

This is happening because Baseline code is compiled differently when debugging and the self_hosted_cache is reusing Baseline code that was compiled before the script was a debuggee.

Flags: needinfo?(bthrall)
Assignee: nobody → bthrall

Debuggee scripts are Baseline-compiled differently than those that aren't
debuggees, so we can't use one when the other is required. Not all scripts will
necessarily be debuggees, so it's good to store both debuggee and non-debuggee
versions in the cache so we can avoid thrashing.

Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Target Milestone: --- → 142 Branch
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: