Assertion failure: isRealmIndependent(), at /js/src/jit/BaselineFrame.cpp:57 with experimental.self_hosted_cache=true
Categories
(Core :: JavaScript Engine, defect, P3)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox141 | --- | disabled |
People
(Reporter: decoder, Unassigned)
References
(Blocks 1 open bug)
Details
(5 keywords, Whiteboard: [bugmon:update,bisect])
Attachments
(2 files)
The following testcase crashes on mozilla-central revision 20250622-8ff7a1e30ec1 (debug build, run with --fuzzing-safe --ion-offthread-compile=off --setpref=experimental.self_hosted_cache=true test.js):
gczeal(6, 1)
a = [].values().drop(1).next()
Backtrace:
received signal SIGSEGV, Segmentation fault.
#0 0x0000632fd676e8a2 in js::jit::BaselineFrame::trace(JSTracer*, js::jit::JSJitFrameIter const&) ()
#1 0x0000632fd6cd2cd0 in js::jit::TraceJitActivations(JSContext*, JSTracer*) ()
#2 0x0000632fd663fde2 in js::gc::GCRuntime::traceRuntimeCommon(JSTracer*, js::gc::GCRuntime::TraceOrMarkRuntime) ()
#3 0x0000632fd663fcb8 in js::gc::GCRuntime::traceRuntimeForMajorGC(JSTracer*, js::gc::AutoGCSession&) ()
#4 0x0000632fd65cf247 in js::gc::GCRuntime::beginMarkPhase(js::gc::AutoGCSession&) ()
#5 0x0000632fd65d66de in js::gc::GCRuntime::incrementalSlice(JS::SliceBudget&, JS::GCReason, bool) ()
#6 0x0000632fd65da433 in js::gc::GCRuntime::gcCycle(bool, JS::SliceBudget const&, JS::GCReason) ()
#7 0x0000632fd65dbc8d in js::gc::GCRuntime::collect(bool, JS::SliceBudget const&, JS::GCReason) ()
#8 0x0000632fd65def22 in js::gc::GCRuntime::runDebugGC() ()
#9 0x0000632fd657e589 in void* js::gc::CellAllocator::AllocTenuredCell<(js::AllowGC)1>(JSContext*, js::gc::AllocKind) ()
#10 0x0000632fd5f16cbe in js::BaseScript::New(JSContext*, JS::Handle<JSFunction*>, JS::Handle<js::ScriptSourceObject*>, js::SourceExtent const&, unsigned int) ()
#11 0x0000632fd5f18edb in JSScript::fromStencil(JSContext*, js::frontend::CompilationAtomCache&, js::frontend::CompilationStencil const&, js::frontend::CompilationGCOutput&, js::frontend::TypedIndex<js::frontend::ScriptStencil>) ()
#12 0x0000632fd6517529 in js::frontend::CompilationStencil::delazifySelfHostedFunction(JSContext*, js::frontend::CompilationAtomCache&, js::frontend::ScriptIndexRange, JS::Handle<JSAtom*>, JS::Handle<JSFunction*>) ()
#13 0x0000632fd602ed98 in JSRuntime::delazifySelfHostedFunction(JSContext*, JS::Handle<js::PropertyName*>, JS::Handle<JSFunction*>) ()
#14 0x0000632fd5eaa811 in JSFunction::delazifySelfHostedLazyFunction(JSContext*, JS::Handle<JSFunction*>) ()
#15 0x0000632fd5b835c3 in JSFunction::getOrCreateScript(JSContext*, JS::Handle<JSFunction*>) ()
#16 0x0000632fd5ca3d4b in js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason) ()
#17 0x0000632fd677c6f0 in js::jit::DoCallFallback(JSContext*, js::jit::BaselineFrame*, js::jit::ICFallbackStub*, unsigned int, JS::Value*, JS::MutableHandle<JS::Value>) ()
#18 0x000033901ee590ff in ?? ()
#19 0xaaaaaaaaaaaaaaaa in ?? ()
[...]
#27 0x0000000000000000 in ?? ()
rax 0x0 0
rbx 0x7ffddc81c450 140728302945360
rcx 0x39 57
rdx 0x77ada28fd723 131587640383267
rsi 0x0 0
rdi 0x77ada28fea60 131587640388192
rbp 0x7ffddc81b070 140728302940272
rsp 0x7ffddc81b010 140728302940176
r8 0x75 117
r9 0x0 0
r10 0x0 0
r11 0x18 24
r12 0x7ffddc81c4a8 140728302945448
r13 0x77ada0242740 131587599771456
r14 0x7ffddc81c438 140728302945336
r15 0x7ffddc81b0d8 140728302940376
rip 0x632fd676e8a2 <js::jit::BaselineFrame::trace(JSTracer*, js::jit::JSJitFrameIter const&)+1298>
=> 0x632fd676e8a2 <_ZN2js3jit13BaselineFrame5traceEP8JSTracerRKNS0_14JSJitFrameIterE+1298>: mov %rcx,(%rax)
0x632fd676e8a5 <_ZN2js3jit13BaselineFrame5traceEP8JSTracerRKNS0_14JSJitFrameIterE+1301>: call 0x632fd5bbdf30 <abort>
S-s until triaged, feature is still disabled by default.
| Reporter | ||
Comment 1•1 year ago
|
||
| Reporter | ||
Comment 2•1 year ago
|
||
Comment 4•1 year ago
|
||
Unable to reproduce bug 1973445 using build mozilla-central 20250622091724-8ff7a1e30ec1. Without a baseline, bugmon is unable to analyze this bug.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.
Comment 5•1 year ago
|
||
same assertion as bug 1972804, FWIW. Test case looks different.
Updated•1 year ago
|
Comment 6•1 year ago
|
||
Yes, this looks pretty similar to bug 1972804. I'm going to investigate that bug first and I'll update this one once I can confirm whether or not this one is a duplicate.
Updated•1 year ago
|
Updated•1 year ago
|
Updated•5 months ago
|
Description
•