Last Comment Bug 656259 - TI: Assertion failure: !fe->data.inRegister(), at methodjit/FrameState-inl.h:909
: TI: Assertion failure: !fe->data.inRegister(), at methodjit/FrameState-inl.h:909
: assertion, testcase
Product: Core
Classification: Components
Component: JavaScript Engine (show other bugs)
: Trunk
: x86_64 Linux
-- critical (vote)
: ---
Assigned To: general
: Jason Orendorff [:jorendorff]
Depends on:
Blocks: infer-regress langfuzz
  Show dependency treegraph
Reported: 2011-05-11 05:37 PDT by Christian Holler (:decoder)
Modified: 2013-01-14 08:46 PST (History)
4 users (show)
choller: in‑testsuite+
See Also:
Crash Signature:
QA Whiteboard:
Iteration: ---
Points: ---
Has Regression Range: ---
Has STR: ---


Description User image Christian Holler (:decoder) 2011-05-11 05:37:04 PDT
The following testcase asserts on TI revision fd1abc43d698 (run with -m -n -a),
tested on 64 bit:

function throwsRangeError(t) {
    try {
        t: for (t[t++] in object) {
            break t;
    } catch (err) {}
Comment 1 User image Brian Hackett (:bhackett) 2011-05-11 10:26:25 PDT
Oversight, we would allow register allocations at join points to assign FP registers to entries which weren't being tracked by the analysis (only possible in scripts with try or switch blocks), and which we don't require to match analysis information at join points.
Comment 2 User image Christian Holler (:decoder) 2013-01-14 08:46:11 PST
A testcase for this bug was automatically identified at js/src/jit-test/tests/jaeger/bug656259.js.

Note You need to log in before you can comment on or make changes to this bug.