Closed
Bug 1981780
Opened 1 year ago
Closed 1 year ago
Crash [@ JSObject::getClass() const] with experimental.self_hosted_cache=true
Categories
(Core :: JavaScript Engine, defect, P2)
Tracking
()
RESOLVED
DUPLICATE
of bug 1970438
| Tracking | Status | |
|---|---|---|
| firefox143 | --- | disabled |
People
(Reporter: decoder, Assigned: bthrall)
References
(Blocks 1 open bug)
Details
(Keywords: crash, regression, testcase, Whiteboard: [bugmon:update,bisect])
Crash Data
Attachments
(2 files)
The following testcase crashes on mozilla-central revision 20250807-cca3e1c9a2e7 (debug build, run with --fuzzing-safe --cpu-count=2 --ion-offthread-compile=off --setpref=experimental.self_hosted_cache=true):
gczeal(8, 1);
while(true) {
g41 = newGlobal({newCompartment: true});
g41.eval(`
function* count(n) {
if (n > 0) {
for (let x of count(n - 1))
yield x;
yield n;
}
}
`);
for (let k42 of g41.count(5)) {}
}
Backtrace:
received signal SIGSEGV, Segmentation fault.
0x0000555556ed20d4 in JSObject::getClass() const ()
#0 0x0000555556ed20d4 in JSObject::getClass() const ()
#1 0x00005555571edf45 in js::AbstractGeneratorObject::finalSuspend(JSContext*, JS::Handle<JSObject*>) ()
#2 0x0000555557c75fde in js::jit::FinalSuspend(JSContext*, JS::Handle<JSObject*>, unsigned char const*) ()
#3 0x000039052fbba67a in ?? ()
[...]
#16 0x00007fffffffb490 in ?? ()
#17 0x00005555570419da in js::Debug_CheckSelfHosted(JSContext*, JS::Handle<JS::Value>) ()
Backtrace stopped: previous frame inner to this frame (corrupt stack?)
rax 0x7fffffffb970 140737488337264
rbx 0x7ffff423c200 140737289372160
rcx 0x50 80
rdx 0x7ffff399ef69 140737280339817
rsi 0x7fffffffb430 140737488335920
rdi 0x4b4b4b4b4b4b 82786757856075
rbp 0x7fffffffb3d0 140737488335824
rsp 0x7fffffffb3d0 140737488335824
r8 0x4 4
r9 0x0 0
r10 0x0 0
r11 0xfffe000000000000 -562949953421312
r12 0x8 8
r13 0x7fffffffbe48 140737488338504
r14 0x4b4b4b4b4b4b 82786757856075
r15 0x7ffff423c200 140737289372160
rip 0x555556ed20d4 <JSObject::getClass() const+4>
=> 0x555556ed20d4 <_ZNK8JSObject8getClassEv+4>: mov (%rdi),%rax
0x555556ed20d7 <_ZNK8JSObject8getClassEv+7>: test $0x7,%al
Marking s-s because of the poison pattern.
| Reporter | ||
Comment 1•1 year ago
|
||
| Reporter | ||
Comment 2•1 year ago
|
||
| Reporter | ||
Updated•1 year ago
|
Group: javascript-core-security
| Reporter | ||
Updated•1 year ago
|
Flags: needinfo?(bthrall)
Comment 3•1 year ago
|
||
Unable to reproduce bug 1981780 using build mozilla-central 20250807093834-cca3e1c9a2e7. Without a baseline, bugmon is unable to analyze this bug.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.
Keywords: bugmon
| Assignee | ||
Comment 4•1 year ago
|
||
Thanks, :decoder!
I've spent the last couple days working on a testcase for bug 1970438, and it looks like this has a similar cause, if not the same cause.
Flags: needinfo?(bthrall)
| Assignee | ||
Updated•1 year ago
|
| Assignee | ||
Updated•1 year ago
|
Updated•1 year ago
|
Group: javascript-core-security
You need to log in
before you can comment on or make changes to this bug.
Description
•