Status

()

--
critical
RESOLVED DUPLICATE of bug 579273
8 years ago
8 years ago

People

(Reporter: gkw, Unassigned)

Tracking

(Blocks: 1 bug, {crash, regression, testcase})

Trunk
x86
Mac OS X
crash, regression, testcase
Points:
---
Dependency tree / graph

Firefox Tracking Flags

(blocking2.0 betaN+)

Details

(Whiteboard: [ccbr], crash signature)

(Reporter)

Description

8 years ago
x = evalcx('')
Object.defineProperty(x, "x", ({
    get: wrap
}))(x.x)

crashes js opt shell on TM tip without -j at js_Call

Program received signal EXC_BAD_ACCESS, Could not access memory.
Reason: KERN_PROTECTION_FAILURE at address: 0x00000030
0x0007d1b2 in js_Call ()
(gdb) bt
#0  0x0007d1b2 in js_Call ()
#1  0x0006eec6 in js::Invoke ()
#2  0x0006fa13 in js::InternalInvoke ()
#3  0x0006fae2 in js::InternalGetOrSet ()
#4  0x000851d9 in js_NativeGet ()
#5  0x000855cc in js_GetPropertyHelper ()
#6  0x00085a1e in js_GetProperty ()
#7  0x0000f18e in JS_GetPropertyById ()
#8  0x0011a2d2 in JSCrossCompartmentWrapper::get ()
#9  0x000c251b in js::proxy_GetProperty ()
#10 0x0006a701 in js::Interpret ()
#11 0x0006e72b in js::Execute ()
#12 0x00014a58 in JS_ExecuteScript ()
#13 0x0000600c in Process ()
#14 0x00009866 in shell ()
#15 0x00009d77 in main ()
(gdb) x/i $eip
0x7d1b2 <_Z7js_CallP9JSContextjPN2js5ValueE+50>:        mov    0x30(%ecx),%eax
(gdb) x/b $ecx
0x0:    Cannot access memory at address 0x0
(Reporter)

Comment 1

8 years ago
autoBisect shows this is probably related to the following changeset:

The first bad revision is:
changeset:   47546:9c869e64ee26
user:        Luke Wagner
date:        Wed Jul 14 23:19:36 2010 -0700
summary:     Bug 549143 - fatvals
Blocks: 549143

Updated

8 years ago
Status: NEW → RESOLVED
Last Resolved: 8 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 579273

Updated

8 years ago
blocking2.0: ? → betaN+
Crash Signature: [@ js_Call]
You need to log in before you can comment on or make changes to this bug.