Closed Bug 1973445 Opened 1 year ago Closed 1 year ago

Assertion failure: isRealmIndependent(), at /js/src/jit/BaselineFrame.cpp:57 with experimental.self_hosted_cache=true

Categories

(Core :: JavaScript Engine, defect, P3)

x86_64
Linux
defect

Tracking

()

RESOLVED DUPLICATE of bug 1972804
Tracking Status
firefox141 --- disabled

People

(Reporter: decoder, Unassigned)

References

(Blocks 1 open bug)

Details

(5 keywords, Whiteboard: [bugmon:update,bisect])

Attachments

(2 files)

The following testcase crashes on mozilla-central revision 20250622-8ff7a1e30ec1 (debug build, run with --fuzzing-safe --ion-offthread-compile=off --setpref=experimental.self_hosted_cache=true test.js):

gczeal(6, 1)
a = [].values().drop(1).next()

Backtrace:

received signal SIGSEGV, Segmentation fault.
#0  0x0000632fd676e8a2 in js::jit::BaselineFrame::trace(JSTracer*, js::jit::JSJitFrameIter const&) ()
#1  0x0000632fd6cd2cd0 in js::jit::TraceJitActivations(JSContext*, JSTracer*) ()
#2  0x0000632fd663fde2 in js::gc::GCRuntime::traceRuntimeCommon(JSTracer*, js::gc::GCRuntime::TraceOrMarkRuntime) ()
#3  0x0000632fd663fcb8 in js::gc::GCRuntime::traceRuntimeForMajorGC(JSTracer*, js::gc::AutoGCSession&) ()
#4  0x0000632fd65cf247 in js::gc::GCRuntime::beginMarkPhase(js::gc::AutoGCSession&) ()
#5  0x0000632fd65d66de in js::gc::GCRuntime::incrementalSlice(JS::SliceBudget&, JS::GCReason, bool) ()
#6  0x0000632fd65da433 in js::gc::GCRuntime::gcCycle(bool, JS::SliceBudget const&, JS::GCReason) ()
#7  0x0000632fd65dbc8d in js::gc::GCRuntime::collect(bool, JS::SliceBudget const&, JS::GCReason) ()
#8  0x0000632fd65def22 in js::gc::GCRuntime::runDebugGC() ()
#9  0x0000632fd657e589 in void* js::gc::CellAllocator::AllocTenuredCell<(js::AllowGC)1>(JSContext*, js::gc::AllocKind) ()
#10 0x0000632fd5f16cbe in js::BaseScript::New(JSContext*, JS::Handle<JSFunction*>, JS::Handle<js::ScriptSourceObject*>, js::SourceExtent const&, unsigned int) ()
#11 0x0000632fd5f18edb in JSScript::fromStencil(JSContext*, js::frontend::CompilationAtomCache&, js::frontend::CompilationStencil const&, js::frontend::CompilationGCOutput&, js::frontend::TypedIndex<js::frontend::ScriptStencil>) ()
#12 0x0000632fd6517529 in js::frontend::CompilationStencil::delazifySelfHostedFunction(JSContext*, js::frontend::CompilationAtomCache&, js::frontend::ScriptIndexRange, JS::Handle<JSAtom*>, JS::Handle<JSFunction*>) ()
#13 0x0000632fd602ed98 in JSRuntime::delazifySelfHostedFunction(JSContext*, JS::Handle<js::PropertyName*>, JS::Handle<JSFunction*>) ()
#14 0x0000632fd5eaa811 in JSFunction::delazifySelfHostedLazyFunction(JSContext*, JS::Handle<JSFunction*>) ()
#15 0x0000632fd5b835c3 in JSFunction::getOrCreateScript(JSContext*, JS::Handle<JSFunction*>) ()
#16 0x0000632fd5ca3d4b in js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason) ()
#17 0x0000632fd677c6f0 in js::jit::DoCallFallback(JSContext*, js::jit::BaselineFrame*, js::jit::ICFallbackStub*, unsigned int, JS::Value*, JS::MutableHandle<JS::Value>) ()
#18 0x000033901ee590ff in ?? ()
#19 0xaaaaaaaaaaaaaaaa in ?? ()
[...]
#27 0x0000000000000000 in ?? ()
rax	0x0	0
rbx	0x7ffddc81c450	140728302945360
rcx	0x39	57
rdx	0x77ada28fd723	131587640383267
rsi	0x0	0
rdi	0x77ada28fea60	131587640388192
rbp	0x7ffddc81b070	140728302940272
rsp	0x7ffddc81b010	140728302940176
r8	0x75	117
r9	0x0	0
r10	0x0	0
r11	0x18	24
r12	0x7ffddc81c4a8	140728302945448
r13	0x77ada0242740	131587599771456
r14	0x7ffddc81c438	140728302945336
r15	0x7ffddc81b0d8	140728302940376
rip	0x632fd676e8a2 <js::jit::BaselineFrame::trace(JSTracer*, js::jit::JSJitFrameIter const&)+1298>
=> 0x632fd676e8a2 <_ZN2js3jit13BaselineFrame5traceEP8JSTracerRKNS0_14JSJitFrameIterE+1298>:	mov    %rcx,(%rax)
   0x632fd676e8a5 <_ZN2js3jit13BaselineFrame5traceEP8JSTracerRKNS0_14JSJitFrameIterE+1301>:	call   0x632fd5bbdf30 <abort>

S-s until triaged, feature is still disabled by default.

Attached file Testcase —

This seems related to the self-hosted code cache.

Flags: needinfo?(bthrall)

Unable to reproduce bug 1973445 using build mozilla-central 20250622091724-8ff7a1e30ec1. Without a baseline, bugmon is unable to analyze this bug.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.

Keywords: bugmon

same assertion as bug 1972804, FWIW. Test case looks different.

See Also: → 1972804
Severity: -- → S3
Priority: -- → P3

Yes, this looks pretty similar to bug 1972804. I'm going to investigate that bug first and I'll update this one once I can confirm whether or not this one is a duplicate.

Flags: needinfo?(bthrall)
Status: NEW → RESOLVED
Closed: 1 year ago
Duplicate of bug: 1972804
Resolution: --- → DUPLICATE
Group: javascript-core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: