Last Comment Bug 657585 - Crash [@ js_GetPropertyHelperInline] or [@ js_str_charAt] or [@ js_ValueToString]
: Crash [@ js_GetPropertyHelperInline] or [@ js_str_charAt] or [@ js_ValueToStr...
: crash, regression, testcase
Product: Core
Classification: Components
Component: JavaScript Engine (show other bugs)
: Trunk
: All All
-- critical (vote)
: mozilla6
Assigned To: Jeff Walden [:Waldo] (remove +bmo to email)
: Jason Orendorff [:jorendorff]
Depends on:
Blocks: jsfunfuzz 645468
  Show dependency treegraph
Reported: 2011-05-17 05:03 PDT by Gary Kwong [:gkw] [:nth10sd]
Modified: 2011-06-13 10:01 PDT (History)
5 users (show)
See Also:
Crash Signature:
QA Whiteboard:
Iteration: ---
Points: ---
Has Regression Range: ---
Has STR: ---

stacks (4.75 KB, text/plain)
2011-05-17 05:03 PDT, Gary Kwong [:gkw] [:nth10sd]
no flags Details
Patch and test (2.26 KB, patch)
2011-05-17 10:48 PDT, Jeff Walden [:Waldo] (remove +bmo to email)
luke: review+
Details | Diff | Splinter Review

Description User image Gary Kwong [:gkw] [:nth10sd] 2011-05-17 05:03:12 PDT
Created attachment 532927 [details]

(e = []);
(e.toString = "".charAt);

crashes js debug shell on TM changeset 0cf1acdb20b1 without any CLI parameters at js_GetPropertyHelperInline and crashes js opt shell at js_str_charAt. js_ValueToString is also on both stacks.
Comment 1 User image Gary Kwong [:gkw] [:nth10sd] 2011-05-17 05:44:21 PDT
autoBisect shows this is probably related to the following changeset:

The first bad revision is:
changeset:   64602:0906d9490eaf
user:        Jeff Walden
date:        Mon Mar 28 20:01:53 2011 -0700
summary:     Bug 645468 - Remove js_TryMethod: its semantics aren't what most of its users want, and its utility is limited.  r=luke
Comment 2 User image Jeff Walden [:Waldo] (remove +bmo to email) 2011-05-17 10:48:52 PDT
Created attachment 533008 [details] [diff] [review]
Patch and test
Comment 3 User image Jeff Walden [:Waldo] (remove +bmo to email) 2011-05-18 14:35:17 PDT
Comment 4 User image Chris Leary [:cdleary] (not checking bugmail) 2011-05-23 14:12:45 PDT
cdleary-bot mozilla-central merge info:

Note You need to log in before you can comment on or make changes to this bug.