If you think a bug might affect users in the 57 release, please set the correct tracking and status flags for Release Management.

TM: "Assertion failure: numSideExitsBefore >= fragment->root->treeInfo->sideExits.length(), at ../jstracer.cpp"

RESOLVED FIXED

Status

()

Core
JavaScript Engine
--
critical
RESOLVED FIXED
8 years ago
5 years ago

People

(Reporter: gkw, Assigned: luke)

Tracking

(Blocks: 1 bug, {assertion, regression, testcase})

Trunk
x86
Mac OS X
assertion, regression, testcase
Points:
---
Dependency tree / graph
Bug Flags:
in-testsuite +

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: fixed-in-tracemonkey)

Attachments

(1 attachment)

(Reporter)

Description

8 years ago
var magicNumbers = [1, -1, 0, 0];
var magicIndex = 0;

function foo(n) {
    for (var i = 0; i < n; ++i) {
        bar();
    }
}

function bar() {
    var q = magicNumbers[magicIndex++];
    if (q != -1) {
        foo(q);
    }
}

foo(3);


asserts js debug shell with -j on TM tip at Assertion failure: numSideExitsBefore >= fragment->root->treeInfo->sideExits.length(), at ../jstracer.cpp:2560

Many thanks to Jesse for his help in reduction of the testcase.

autoBisect shows this has the following (not exactly the smallest regression window):

http://hg.mozilla.org/tracemonkey/pushloghtml?fromchange=81afd53646d4&tochange=30f8f6dcf808
(Reporter)

Comment 1

8 years ago
This is impacting jsfunfuzz significantly. :(
(Reporter)

Comment 2

8 years ago
After some manual bisects, this is probably related to bug 520636.
Blocks: 520636
(Assignee)

Comment 3

8 years ago
Created attachment 412742 [details] [diff] [review]
fix flipped assert, add test

Flipped relational operator; pretty dim on my part.  At first I was surprised that something so wrong could pass debug trace-tests, but its actually quite a corner case, so I'm adding it.  Thanks again Gary!
Assignee: general → lw
Status: NEW → ASSIGNED
Attachment #412742 - Flags: review?(dvander)
Attachment #412742 - Flags: review?(dvander) → review+
(Assignee)

Comment 4

8 years ago
http://hg.mozilla.org/tracemonkey/rev/81b3a2e0c807
Whiteboard: fixed-in-tracemonkey

Comment 5

8 years ago
http://hg.mozilla.org/mozilla-central/rev/81b3a2e0c807
Status: ASSIGNED → RESOLVED
Last Resolved: 8 years ago
Resolution: --- → FIXED
A testcase for this bug was automatically identified at js/src/jit-test/tests/basic/testBug529147.js.
Flags: in-testsuite+
You need to log in before you can comment on or make changes to this bug.