If you think a bug might affect users in the 57 release, please set the correct tracking and status flags for Release Management.

TI: "Assertion failure: lval.isNull() || lval.isUndefined(),"

RESOLVED DUPLICATE of bug 655950

Status

()

Core
JavaScript Engine
--
critical
RESOLVED DUPLICATE of bug 655950
7 years ago
5 years ago

People

(Reporter: gkw, Unassigned)

Tracking

(Blocks: 3 bugs, {assertion, testcase})

Trunk
x86
Linux
assertion, testcase
Points:
---
Dependency tree / graph
Bug Flags:
in-testsuite -

Firefox Tracking Flags

(Not tracked)

Details

(Reporter)

Description

7 years ago
new(function() {})().s()

asserts js debug shell on JM changeset fd1abc43d698 with -m, -a and -n at Assertion failure: lval.isNull() || lval.isUndefined(),

(gdb) bt
#0  0xf7fdf430 in __kernel_vsyscall ()
#1  0xf7fb5ba0 in raise (sig=6) at ../nptl/sysdeps/unix/sysv/linux/pt-raise.c:42
#2  0x081fda8d in JS_Assert (s=0x845de44 "lval.isNull() || lval.isUndefined()", file=0x845d290 "/home/fuzz1/Desktop/jsfunfuzz-dbg-32-jm-69167-fd1abc43d698/compilePath/js/src/jsinterp.cpp", ln=4183)
    at /home/fuzz1/Desktop/jsfunfuzz-dbg-32-jm-69167-fd1abc43d698/compilePath/js/src/jsutil.cpp:89
#3  0x0839703f in js::Interpret (cx=0x84e4028, entryFrame=0xf76e4030, inlineCallCount=0, interpMode=js::JSINTERP_SAFEPOINT)
    at /home/fuzz1/Desktop/jsfunfuzz-dbg-32-jm-69167-fd1abc43d698/compilePath/js/src/jsinterp.cpp:4183
#4  0x08354b19 in js_InternalInterpret (returnData=0xf750f048, returnType=0xffff0007, returnReg=0x82b6370, f=...)
    at /home/fuzz1/Desktop/jsfunfuzz-dbg-32-jm-69167-fd1abc43d698/compilePath/js/src/methodjit/InvokeHelpers.cpp:1621
#5  0x082b6348 in JaegerInterpoline () at /home/fuzz1/Desktop/jsfunfuzz-dbg-32-jm-69167-fd1abc43d698/compilePath/js/src/methodjit/MethodJIT.cpp:152
#6  0x000f4240 in ?? ()
#7  0x00000000 in ?? ()
WFM, and this hits the busted cast fixed in bug 655950, so I'm guessing that's the problem.  Reopen if you can still repro.
Status: NEW → RESOLVED
Last Resolved: 7 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 655950
(Reporter)

Updated

6 years ago
Blocks: 349611
A testcase for this bug was already added in the original bug (bug 655950).
Flags: in-testsuite-
You need to log in before you can comment on or make changes to this bug.