Last Comment Bug 649973 - TI+JM: crash in mjit-generated code
: TI+JM: crash in mjit-generated code
Status: RESOLVED FIXED
:
Product: Core
Classification: Components
Component: JavaScript Engine (show other bugs)
: unspecified
: All All
: -- normal (vote)
: ---
Assigned To: general
:
: Jason Orendorff [:jorendorff]
Mentors:
Depends on:
Blocks: infer-regress
  Show dependency treegraph
 
Reported: 2011-04-14 06:11 PDT by Jan de Mooij [:jandem]
Modified: 2011-04-14 17:30 PDT (History)
4 users (show)
See Also:
Crash Signature:
(edit)
QA Whiteboard:
Iteration: ---
Points: ---
Has Regression Range: ---
Has STR: ---


Attachments

Description Jan de Mooij [:jandem] 2011-04-14 06:11:57 PDT
--
x = 2147483647;
(x+10, false) ? [x % x] : [2 * x];
--
Crashes with -n -a -m, revision f3acaebac193, 32 bit.
Comment 1 Brian Hackett (:bhackett) 2011-04-14 17:30:43 PDT
We called linkExit() without a subsequent leave() for the negative zero helper in JSOP_MOD (any way to assert the correctness of these leave calls rather than get random corruption?).

http://hg.mozilla.org/projects/jaegermonkey/rev/1d02bc092126

Note You need to log in before you can comment on or make changes to this bug.