Closed Bug 451984 Opened 13 years ago Closed 13 years ago
TM Google Documents crashes with JIT Content enabled
Trying to go into Google Documents crashes the browser with no BreakPad Report. 1. Login to your Google account 2. Try to visit Documents - note the crash Gmail seems to work as does Calendar, just can't get into Documents. Using build: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.1a2pre) Gecko/20080823032129 Minefield/3.1a2pre Firefox/3.0 ID:20080823032129 on Vista HP SP1 1.4ghz Athlon Thunderbird (non-SSE enabled) 1 gig RAM
Still crashed here after updating to today's build: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.1a2pre) Gecko/20080824031931 Minefield/3.1a2pre Firefox/3.0 ID:20080824031931 Disabling Flash 10 RC1 I got a breakpad: http://crash-stats.mozilla.com/report/index/fc8ea3fd-7230-11dd-a036-0013211cbf8a
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1a2pre) Gecko/20080824081856 Minefield/3.1a2pre Yeah, crashes here too with breakpad.
13 years ago
Duplicate of this bug: 451902
This crash happens because (after we've recorded) we're in the middle of a JSOP_ADD on an object that has a scripted OBJ_DEFAULT_VALUE implementation. Our jump into this implementation is hidden from the tracer thanks to the magic of js_DefaultValue calling js_InternalInvoke directly. Then, we try to continue recording in the scripted function, are unable to find argv[-1] (since we're not tracking it) and crash.
Assignee: general → mrbkap
But there's something else too: we should have bailed after trying to record a JSOP_ADD with at least one non-number argument.
With the update merge from TM to M-C on 9/2/8 I am no longer crashing on any of the Google Document pages using build: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.1b1pre) Gecko/20080903113031 Minefield/3.1b1pre Firefox/3.0 ID:20080903113031 I have both JIT Chrome & Content enabled.
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → FIXED
Resolution: FIXED → WORKSFORME
You need to log in before you can comment on or make changes to this bug.