TM: double free and crash [@ tiny_free_list_add_ptr]

VERIFIED FIXED

Status

()

--
critical
VERIFIED FIXED
10 years ago
8 years ago

People

(Reporter: jruderman, Assigned: dvander)

Tracking

(Blocks: 1 bug, {crash, testcase, verified1.9.1})

Trunk
x86
Mac OS X
crash, testcase, verified1.9.1
Points:
---
Bug Flags:
wanted1.9.0.x -
in-testsuite +
in-litmus -

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: [sg:critical?][fixed-in-tracemonkey], crash signature)

Attachments

(2 attachments)

(Reporter)

Description

10 years ago
for each (let b in [eval, eval, 4, 4]) { 
  ++b; 
  for each (b in [(void 0), (void 0), (void 0), 3, (void 0), 3]) { 
    b ^= b; 
    for each (var c in [1/0]) {
    }
  } 
}
(Reporter)

Updated

10 years ago
Whiteboard: [sg:critical?]
Created attachment 349290 [details] [diff] [review]
proposed fix

Can't trash tree with live recorder.
Assignee: general → danderson
Status: NEW → ASSIGNED
Attachment #349290 - Flags: review?(gal)

Updated

10 years ago
Attachment #349290 - Flags: review?(gal) → review+
Pushed fix as changeset http://hg.mozilla.org/tracemonkey/rev/c8d272272215
Status: ASSIGNED → RESOLVED
Last Resolved: 10 years ago
Resolution: --- → FIXED

Comment 3

10 years ago
Created attachment 349424 [details]
js1_7/regress/regress-465686.js

Updated

10 years ago
Flags: in-testsuite+
Flags: in-litmus-

Comment 4

10 years ago
this is fixed on tracemonkey but not mozilla-central or mozilla-1.9.1
Status: RESOLVED → REOPENED
Resolution: FIXED → ---
Whiteboard: [sg:critical?] → [sg:critical?][fixed-in-tracemonkey]

Updated

10 years ago
Status: REOPENED → RESOLVED
Last Resolved: 10 years ago10 years ago
Resolution: --- → FIXED

Comment 5

10 years ago
Fixed on central and 1.9.1.

http://hg.mozilla.org/releases/mozilla-1.9.1/rev/3f171689eeb8

bc, what about getting the test on 1.9.1?

Updated

10 years ago
Keywords: fixed1.9.1

Comment 6

10 years ago
rob, we don't commit sensitive tests until they are made public. tomcat and i are both running this test privately around the clock on windows, linux and mac for all branches. I'll get caught up on verifications this weekend.

Comment 7

10 years ago
v 1.9.1, 1.9.2
Status: RESOLVED → VERIFIED
Keywords: fixed1.9.1 → verified1.9.1
Group: core-security
Flags: wanted1.9.0.x-

Comment 8

9 years ago
test checked into 1.9.0, 1.9.1, 1.9.2, tracemonkey. 1.9.3 will get picked up in the next merge.
Crash Signature: [@ tiny_free_list_add_ptr]
You need to log in before you can comment on or make changes to this bug.