Closed Bug 1979345 Opened 1 year ago Closed 1 year ago

Assertion failure: (asBits_ & js::gc::CellAlignMask) == 0 (GC pointer is not aligned. Is this memory corruption?), at js/Value.h:715 with self_hosted_cache

Categories

(Core :: JavaScript Engine, defect, P2)

x86_64
Linux
defect

Tracking

()

RESOLVED DUPLICATE of bug 1973460
Tracking Status
firefox143 --- disabled

People

(Reporter: decoder, Assigned: bthrall)

References

(Blocks 1 open bug)

Details

(4 keywords, Whiteboard: [bugmon:update,bisect])

Attachments

(2 files)

The following testcase crashes on mozilla-central revision 20250725-12bf685e7003 (debug build, run with --fuzzing-safe --cpu-count=2 --ion-offthread-compile=off --setpref=experimental.self_hosted_cache=true --ion-warmup-threshold=0):

let lfRunTypeId = -1;
function checkGetOffsetsCoverage(fun) {
  var source = fun.toString();
  var g78 = newGlobal({newCompartment: true});
  var dbg = Debugger(g78);
  dbg.collectCoverageInfo = true;
  g78.eval(source);
}
loadFile("checkGetOffsetsCoverage(function () { });");
for (let i = 0; i < 10; ++i)
loadFile( `
function f1() {
    gc();
}
function f2() {
    f1();
}
function f3() {
    f2();
}
yield = options;
f3( ...   this + 1 ,  (yield    )         ) ;
var dbg = new Debugger(g93);
`);
function loadFile(lfVarx, lfForceRunType = 0, lfPatchSets = [new Set(), new Set(), new Set(), new Set(), new Set()]) {
    try {
        evaluate(lfVarx);
    } catch (lfVare) {
        print("Error: " + lfRunTypeId +  ": " + lfVare);
        if (lfVare instanceof SyntaxError) {       }
    }
}

Backtrace:

received signal SIGSEGV, Segmentation fault.
#0  0x0000555556eb43b1 in JS::Value::toObject() const ()
#1  0x00005555579ca70e in auto js::MapGCThingTyped<TraceTaggedPtrEdge<JS::Value>(JSTracer*, JS::Value*, char const*)::{lambda(auto:1)#1}>(JS::Value const&, TraceTaggedPtrEdge<JS::Value>(JSTracer*, JS::Value*, char const*)::{lambda(auto:1)#1}&&) ()
#2  0x00005555579ac545 in js::gc::TraceEdgeInternal(JSTracer*, JS::Value*, char const*) ()
#3  0x0000555558039fab in js::jit::IonScript::trace(JSTracer*) ()
#4  0x0000555558098289 in js::jit::JitScript::trace(JSTracer*) ()
#5  0x00005555579d2725 in bool js::GCMarker::processMarkStackTop<0u>(JS::SliceBudget&) ()
#6  0x00005555579d2322 in bool js::GCMarker::markOneColor<0u, (js::gc::MarkColor)2>(JS::SliceBudget&) ()
#7  0x00005555579b5ed4 in bool js::GCMarker::doMarking<0u>(JS::SliceBudget&, js::gc::ShouldReportMarkTime) ()
#8  0x000055555798dfa3 in js::GCMarker::markUntilBudgetExhausted(JS::SliceBudget&, js::gc::ShouldReportMarkTime) ()
#9  0x000055555798d24b in js::gc::GCRuntime::markUntilBudgetExhausted(JS::SliceBudget&, js::gc::GCRuntime::ParallelMarking, js::gc::ShouldReportMarkTime) ()
#10 0x0000555557992557 in js::gc::GCRuntime::incrementalSlice(JS::SliceBudget&, JS::GCReason, bool) ()
#11 0x0000555557996083 in js::gc::GCRuntime::gcCycle(bool, JS::SliceBudget const&, JS::GCReason) ()
#12 0x00005555579978dd in js::gc::GCRuntime::collect(bool, JS::SliceBudget const&, JS::GCReason) ()
#13 0x000055555797dd8a in js::gc::GCRuntime::gc(JS::GCOptions, JS::GCReason) ()
#14 0x000055555799f080 in JS::NonIncrementalGC(JSContext*, JS::GCOptions, JS::GCReason) ()
#15 0x000055555758b738 in GC(JSContext*, unsigned int, JS::Value*) ()
#16 0x000055555703eae5 in CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&) ()
#17 0x000055555703e1f0 in js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason) ()
#18 0x0000555557052059 in js::Interpret(JSContext*, js::RunState&) ()
#19 0x000055555703d764 in js::RunScript(JSContext*, js::RunState&) ()
#20 0x000055555703e216 in js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason) ()
#21 0x000055555703f78d in js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason) ()
#22 0x000055555705dd66 in js::SpreadCallOperation(JSContext*, JS::Handle<JSScript*>, unsigned char*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::MutableHandle<JS::Value>) ()
#23 0x0000555557b35505 in js::jit::DoSpreadCallFallback(JSContext*, js::jit::BaselineFrame*, js::jit::ICFallbackStub*, JS::Value*, JS::MutableHandle<JS::Value>) ()
#24 0x00002193e002371e in ?? ()
[...]
#49 0x0000000000000000 in ?? ()
rax	0x0	0
rbx	0x7fffffffa7a0	140737488332704
rcx	0x2cb	715
rdx	0x7ffff7804563	140737345766755
rsi	0x0	0
rdi	0x7ffff7805700	140737345771264
rbp	0x7fffffffa740	140737488332608
rsp	0x7fffffffa740	140737488332608
r8	0x0	0
r9	0x3	3
r10	0x0	0
r11	0x293	659
r12	0x7fffffffa7d0	140737488332752
r13	0x7ffff42444c0	140737289405632
r14	0xfffe0502f8b8b8c9	-557439632492343
r15	0x0	0
rip	0x555556eb43b1 <JS::Value::toObject() const+289>
=> 0x555556eb43b1 <_ZNK2JS5Value8toObjectEv+289>:	mov    %rcx,(%rax)
   0x555556eb43b4 <_ZNK2JS5Value8toObjectEv+292>:	call   0x555556f58350 <abort>

The test is highly intermittent, reproduces about 3-5% of all runs.

Attached file Testcase —
Flags: needinfo?(bthrall)
Assignee: nobody → bthrall
Flags: needinfo?(bthrall)
Severity: -- → S3
Priority: -- → P1
Priority: P1 → P2
Status: NEW → RESOLVED
Closed: 1 year ago
Duplicate of bug: 1973460
Resolution: --- → DUPLICATE

Unable to reproduce bug 1979345 using build mozilla-central 20250725093757-12bf685e7003. Without a baseline, bugmon is unable to analyze this bug.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.

Keywords: bugmon
Group: javascript-core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: