Closed Bug 1981780 Opened 1 year ago Closed 1 year ago

Crash [@ JSObject::getClass() const] with experimental.self_hosted_cache=true

Categories

(Core :: JavaScript Engine, defect, P2)

x86_64
Linux
defect

Tracking

()

RESOLVED DUPLICATE of bug 1970438
Tracking Status
firefox143 --- disabled

People

(Reporter: decoder, Assigned: bthrall)

References

(Blocks 1 open bug)

Details

(Keywords: crash, regression, testcase, Whiteboard: [bugmon:update,bisect])

Crash Data

Attachments

(2 files)

The following testcase crashes on mozilla-central revision 20250807-cca3e1c9a2e7 (debug build, run with --fuzzing-safe --cpu-count=2 --ion-offthread-compile=off --setpref=experimental.self_hosted_cache=true):

gczeal(8, 1);
while(true) {
  g41 = newGlobal({newCompartment: true});
  g41.eval(`
    function* count(n) {
        if (n > 0) {
            for (let x of count(n - 1))
                yield x;
            yield n;
        }
    }
  `);
  for (let k42 of g41.count(5)) {}
}

Backtrace:

received signal SIGSEGV, Segmentation fault.
0x0000555556ed20d4 in JSObject::getClass() const ()
#0  0x0000555556ed20d4 in JSObject::getClass() const ()
#1  0x00005555571edf45 in js::AbstractGeneratorObject::finalSuspend(JSContext*, JS::Handle<JSObject*>) ()
#2  0x0000555557c75fde in js::jit::FinalSuspend(JSContext*, JS::Handle<JSObject*>, unsigned char const*) ()
#3  0x000039052fbba67a in ?? ()
[...]
#16 0x00007fffffffb490 in ?? ()
#17 0x00005555570419da in js::Debug_CheckSelfHosted(JSContext*, JS::Handle<JS::Value>) ()
Backtrace stopped: previous frame inner to this frame (corrupt stack?)
rax	0x7fffffffb970	140737488337264
rbx	0x7ffff423c200	140737289372160
rcx	0x50	80
rdx	0x7ffff399ef69	140737280339817
rsi	0x7fffffffb430	140737488335920
rdi	0x4b4b4b4b4b4b	82786757856075
rbp	0x7fffffffb3d0	140737488335824
rsp	0x7fffffffb3d0	140737488335824
r8	0x4	4
r9	0x0	0
r10	0x0	0
r11	0xfffe000000000000	-562949953421312
r12	0x8	8
r13	0x7fffffffbe48	140737488338504
r14	0x4b4b4b4b4b4b	82786757856075
r15	0x7ffff423c200	140737289372160
rip	0x555556ed20d4 <JSObject::getClass() const+4>
=> 0x555556ed20d4 <_ZNK8JSObject8getClassEv+4>:	mov    (%rdi),%rax
   0x555556ed20d7 <_ZNK8JSObject8getClassEv+7>:	test   $0x7,%al

Marking s-s because of the poison pattern.

Attached file Testcase —
Group: javascript-core-security
Flags: needinfo?(bthrall)

Unable to reproduce bug 1981780 using build mozilla-central 20250807093834-cca3e1c9a2e7. Without a baseline, bugmon is unable to analyze this bug.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.

Keywords: bugmon

Thanks, :decoder!

I've spent the last couple days working on a testcase for bug 1970438, and it looks like this has a similar cause, if not the same cause.

Flags: needinfo?(bthrall)
Assignee: nobody → bthrall
Severity: -- → S3
Priority: -- → P2
Status: NEW → RESOLVED
Closed: 1 year ago
Duplicate of bug: 1970438
Resolution: --- → DUPLICATE
Group: javascript-core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: