Closed Bug 631923 Opened 9 years ago Closed 9 years ago

Crash [@ xpc::XrayWrapper<JSCrossCompartmentWrapper>::get(JSContext*, JSObject*, JSObject*, int, js::Value*) ][@ js::JSProxyHandler::get ]

Categories

(Core :: XPConnect, defect, critical)

x86
All
defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 631488
Tracking Status
blocking2.0 --- betaN+

People

(Reporter: scoobidiver, Assigned: gal)

Details

(Keywords: crash, regression, Whiteboard: [hardblocker])

Crash Data

It is a new crash signature that first appeared in 4.0b12pre/20110204.
It is #4 top crasher in 4.0b12pre/20110205.

Signature	xpc::XrayWrapper<JSCrossCompartmentWrapper>::get(JSContext*, JSObject*, JSObject*, int, js::Value*)
UUID	5dd157ba-a8f9-493e-8275-b81d32110205
Time 	2011-02-05 21:51:33.248876
Uptime	16
Last Crash	21 seconds before submission
Install Age	14083 seconds (3.9 hours) since version was first installed.
Product	Firefox
Version	4.0b12pre
Build ID	20110205030343
Branch	2.0
OS	Windows NT
OS Version	6.1.7600
CPU	x86
CPU Info	AuthenticAMD family 15 model 47 stepping 2
Crash Reason	EXCEPTION_ACCESS_VIOLATION_EXEC
Crash Address	0x10882b40
User Comments	Crash on facebook.com load (logged in- crash on 'feed' load)
App Notes 	AdapterVendorID: 1002, AdapterDeviceID: 68f9, AdapterDriverVersion: 8.801.0.0

Frame 	Module 	Signature [Expand] 	Source
0 		@0x10882b40 	
1 	xul.dll 	xpc::XrayWrapper<JSCrossCompartmentWrapper>::get 	js/src/xpconnect/wrappers/XrayWrapper.cpp:765
2 	mozjs.dll 	js::JSProxy::get 	js/src/jsproxy.cpp:798
3 	mozjs.dll 	js::proxy_GetProperty 	js/src/jsproxy.cpp:915
4 	mozjs.dll 	js::mjit::ic::GetProp 	js/src/methodjit/PolyIC.cpp:1692
5 	mozjs.dll 	js::mjit::ic::Call 	js/src/methodjit/MonoIC.cpp:860
6 	xul.dll 	nsWindow::OnPaint 	widget/src/windows/nsWindowGfx.cpp:669
7 	mozjs.dll 	js::mjit::ic::NativeCall 	js/src/methodjit/MonoIC.cpp:875

More reports at:
https://crash-stats.mozilla.com/report/list?product=Firefox&query_search=signature&query_type=exact&query=&range_value=4&range_unit=weeks&signature=xpc%3A%3AXrayWrapper%3CJSCrossCompartmentWrapper%3E%3A%3Aget%28JSContext*%2C%20JSObject*%2C%20JSObject*%2C%20int%2C%20js%3A%3AValue*%29
OS: Windows 7 → All
Summary: Crash [@ xpc::XrayWrapper<JSCrossCompartmentWrapper>::get(JSContext*, JSObject*, JSObject*, int, js::Value*) ] → Crash [@ xpc::XrayWrapper<JSCrossCompartmentWrapper>::get(JSContext*, JSObject*, JSObject*, int, js::Value*) ][@ js::JSProxyHandler::get ]
This is new on the trunk. It's not a significant volume but it's a regression. We don't have high number of users. It started to show up on 02/04. Can someone take a look and see if it's something that seems obvious. Adding Johnny and Dmandelin - add someone else if you are the wrong guys.
Assignee: nobody → gal
I believe there's a fix for this in bug 631488. Duping.
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 631488
blocking2.0: ? → betaN+
Whiteboard: [hardblocker]
Crash Signature: [@ xpc::XrayWrapper<JSCrossCompartmentWrapper>::get(JSContext*, JSObject*, JSObject*, int, js::Value*) ] [@ js::JSProxyHandler::get ]
You need to log in before you can comment on or make changes to this bug.