JM: "Assertion failure: nuses <= stackDepth,"

RESOLVED FIXED

Status

()

Core
JavaScript Engine
--
critical
RESOLVED FIXED
8 years ago
5 years ago

People

(Reporter: gkw, Assigned: billm)

Tracking

(Blocks: 1 bug, {assertion, regression, testcase})

Trunk
assertion, regression, testcase
Points:
---
Dependency tree / graph
Bug Flags:
in-testsuite +

Firefox Tracking Flags

(blocking2.0 beta8+)

Details

(Whiteboard: fixed-in-tracemonkey)

Attachments

(2 attachments)

(Reporter)

Description

8 years ago
Created attachment 480433 [details]
testcase

Testcase asserts js debug shell on TM changeset 0230a9e80c1f with -m at Assertion failure: nuses <= stackDepth,
(Reporter)

Updated

8 years ago
blocking2.0: --- → ?
This is caused by that patch. The previous version, 60b9a07d3d29, does not assert.

Updated

8 years ago
Blocks: 600193
(Reporter)

Comment 2

8 years ago
autoBisect shows this is probably related to the following changeset:

The first bad revision is:
changeset:   54650:427282865362
user:        Bill McCloskey
date:        Wed Sep 29 13:21:36 2010 -0700
summary:     Bug 535912 - Eliminate blockChain from JSStackFrame (r=cdleary)
Blocks: 535912

Updated

8 years ago
blocking2.0: ? → beta8+
Created attachment 480780 [details] [diff] [review]
fix

I think that this is the correct fix. The problem was that the return JS_TRUE statement caused us to skip the decrement of cg->emitLevel at the bottom of the function. That meant that OptimizeSpanDeps was not called when it should have been.

To avoid this in the future, I used some C++ magic to ensure that the decrement happens no matter what.
Assignee: general → wmccloskey
Status: NEW → ASSIGNED
Attachment #480780 - Flags: review?(brendan)
Comment on attachment 480780 [details] [diff] [review]
fix

>+class EmitLevelManager
>+{
>+private:
>+    JSCodeGenerator *cg;
>+    
>+public:
>+    EmitLevelManager(JSCodeGenerator *cg) : cg(cg) { cg->emitLevel++; }
>+
>+    ~EmitLevelManager() { cg->emitLevel--; }
>+};

Nice to have C++ -- we were C for so long, MUST_FLOW_THROUGH static analysis macrology and the analysis itself evolved to help cope with lack of RAII balancers. We should rip out the MUST_FLOW_... calls now, replacing where necessary with RAII.

>+    EmitLevelManager emgr(cg);

Custom dictates naming this elm, not emgr. Plus, Unix mail nerd homage.

>-    cg->emitLevel++;
>+    //cg->emitLevel++;

Remove, or move the elm decl here with a better-spaced version of this comment.

r=me with these mods.

/be
Attachment #480780 - Flags: review?(brendan) → review+
Whiteboard: fixed-in-tracemonkey

Comment 6

8 years ago
http://hg.mozilla.org/mozilla-central/rev/ca4d24b04c2c
Status: ASSIGNED → RESOLVED
Last Resolved: 8 years ago
Resolution: --- → FIXED
Automatically extracted testcase for this bug was committed:

https://hg.mozilla.org/mozilla-central/rev/efaf8960a929
Flags: in-testsuite+
You need to log in before you can comment on or make changes to this bug.