Assertion failure: frame.isDebuggee(), at /js/src/debugger/DebugAPI-inl.h:77 with experimental.self_hosted_cache=true
Categories
(Core :: JavaScript Engine, defect, P3)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox-esr128 | --- | unaffected |
| firefox-esr140 | --- | wontfix |
| firefox139 | --- | unaffected |
| firefox140 | --- | wontfix |
| firefox141 | --- | wontfix |
| firefox142 | --- | fixed |
People
(Reporter: decoder, Assigned: bthrall)
References
(Blocks 2 open bugs, Regression)
Details
(Keywords: assertion, regression, testcase, Whiteboard: [bugmon:update,bisect])
Attachments
(3 files)
The following testcase crashes on mozilla-central revision 20250618-5fb84cb353d4 (debug build, run with --fuzzing-safe --ion-offthread-compile=off --setpref=experimental.self_hosted_cache=true --more-compartments):
this.__defineGetter__("", eval);
a = newGlobal();
Debugger(a).onEnterFrame = function() {}
a.__defineGetter__();
Backtrace:
received signal SIGSEGV, Segmentation fault.
#0 0x000055555705ffaf in js::DebugAPI::onLeaveFrame(JSContext*, js::AbstractFramePtr, unsigned char const*, bool) ()
#1 0x0000555557c55063 in js::jit::DebugEpilogue(JSContext*, js::jit::BaselineFrame*, unsigned char const*, bool) ()
#2 0x00005555580713c4 in js::jit::HandleException(js::jit::ResumeFromException*) ()
#3 0x000012829ea44a76 in ?? ()
[...]
#41 0x0000000000000000 in ?? ()
rax 0x0 0
rbx 0x0 0
rcx 0x4d 77
rdx 0x1 1
rsi 0x0 0
rdi 0x7ffff7bee7d0 140737349871568
rbp 0x7fffffffbfd0 140737488338896
rsp 0x7fffffffbfa0 140737488338848
r8 0x0 0
r9 0x3 3
r10 0x0 0
r11 0x0 0
r12 0xd740059a060 14791873241184
r13 0x5555559ad048 93824996790344
r14 0x7ffff460a35f 140737293362015
r15 0x7ffff463a200 140737293558272
rip 0x55555705ffaf <js::DebugAPI::onLeaveFrame(JSContext*, js::AbstractFramePtr, unsigned char const*, bool)+799>
=> 0x55555705ffaf <_ZN2js8DebugAPI12onLeaveFrameEP9JSContextNS_16AbstractFramePtrEPKhb+799>: mov %rcx,(%rax)
0x55555705ffb2 <_ZN2js8DebugAPI12onLeaveFrameEP9JSContextNS_16AbstractFramePtrEPKhb+802>: callq 0x555556f5ff70 <abort>
| Reporter | ||
Comment 1•1 year ago
|
||
| Reporter | ||
Comment 2•1 year ago
|
||
| Reporter | ||
Updated•1 year ago
|
Comment 3•1 year ago
|
||
Unable to reproduce bug 1972784 using build mozilla-central 20250618042918-5fb84cb353d4. Without a baseline, bugmon is unable to analyze this bug.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.
Comment 4•1 year ago
|
||
Set release status flags based on info from the regressing bug 1827914
Updated•1 year ago
|
Updated•1 year ago
|
Comment 5•1 year ago
|
||
Set release status flags based on info from the regressing bug 1827914
| Assignee | ||
Updated•1 year ago
|
| Assignee | ||
Comment 6•1 year ago
|
||
This is happening because Baseline code is compiled differently when debugging and the self_hosted_cache is reusing Baseline code that was compiled before the script was a debuggee.
| Assignee | ||
Updated•1 year ago
|
Updated•1 year ago
|
| Assignee | ||
Comment 7•1 year ago
|
||
Debuggee scripts are Baseline-compiled differently than those that aren't
debuggees, so we can't use one when the other is required. Not all scripts will
necessarily be debuggees, so it's good to store both debuggee and non-debuggee
versions in the cache so we can avoid thrashing.
Comment 9•1 year ago
|
||
| bugherder | ||
Updated•1 year ago
|
Description
•