The default bug view has changed. See this FAQ.

TI+JM: crash in mjit-generated code

RESOLVED FIXED

Status

()

Core
JavaScript Engine
RESOLVED FIXED
6 years ago
6 years ago

People

(Reporter: jandem, Unassigned)

Tracking

(Blocks: 1 bug)

Firefox Tracking Flags

(Not tracked)

Details

(Reporter)

Description

6 years ago
--
x = 2147483647;
(x+10, false) ? [x % x] : [2 * x];
--
Crashes with -n -a -m, revision f3acaebac193, 32 bit.
We called linkExit() without a subsequent leave() for the negative zero helper in JSOP_MOD (any way to assert the correctness of these leave calls rather than get random corruption?).

http://hg.mozilla.org/projects/jaegermonkey/rev/1d02bc092126
Status: NEW → RESOLVED
Last Resolved: 6 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.