Closed Bug 584651 Opened 12 years ago Closed 12 years ago

JM: Crash [@ js::DefaultValue] or "Assertion failure: &obj != NULL,"

Categories

(Core :: JavaScript Engine, defect)

defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 584607

People

(Reporter: gkw, Assigned: dvander)

References

Details

(4 keywords)

Crash Data

(function () {
    print(a++)
    function a() {}
})()

asserts js debug shell on JM changeset 6347cf00d3ab with -m at Assertion failure: &obj != NULL, at ../../jsvalue.h:356 and crashes js opt shell at js::DefaultValue

Program received signal SIGSEGV, Segmentation fault.
0x080c565e in js::DefaultValue(JSContext*, JSObject*, JSType, js::Value*) ()
(gdb) x/i $eip
=> 0x80c565e <_ZN2js12DefaultValueEP9JSContextP8JSObject6JSTypePNS_5ValueE+238>:	cmp    %edx,0x4(%esi)
(gdb) x/b $edx
0x823d240 <js_StringClass>:	0x19
Depends on: 584957
Assignee: general → dvander
Status: NEW → ASSIGNED
This looks very similar to bug 584659.
Status: ASSIGNED → RESOLVED
Closed: 12 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 584607
Crash Signature: [@ js::DefaultValue]
You need to log in before you can comment on or make changes to this bug.