Crash [@ js_GetPropertyHelperInline] or [@ js_str_charAt] or [@ js_ValueToString]

RESOLVED FIXED in mozilla6

Status

()

Core
JavaScript Engine
--
critical
RESOLVED FIXED
6 years ago
6 years ago

People

(Reporter: gkw, Assigned: Waldo)

Tracking

(Blocks: 1 bug, {crash, regression, testcase})

Trunk
mozilla6
crash, regression, testcase
Points:
---
Dependency tree / graph

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: fixed-in-tracemonkey, crash signature)

Attachments

(2 attachments)

(Reporter)

Description

6 years ago
Created attachment 532927 [details]
stacks

(e = []);
(e.toString = "".charAt);
(e::E);

crashes js debug shell on TM changeset 0cf1acdb20b1 without any CLI parameters at js_GetPropertyHelperInline and crashes js opt shell at js_str_charAt. js_ValueToString is also on both stacks.
(Reporter)

Comment 1

6 years ago
autoBisect shows this is probably related to the following changeset:

The first bad revision is:
changeset:   64602:0906d9490eaf
user:        Jeff Walden
date:        Mon Mar 28 20:01:53 2011 -0700
summary:     Bug 645468 - Remove js_TryMethod: its semantics aren't what most of its users want, and its utility is limited.  r=luke
Blocks: 645468
Created attachment 533008 [details] [diff] [review]
Patch and test
Assignee: general → jwalden+bmo
Status: NEW → ASSIGNED
Attachment #533008 - Flags: review?(luke)

Updated

6 years ago
Attachment #533008 - Flags: review?(luke) → review+
http://hg.mozilla.org/tracemonkey/rev/8af92dba2480
OS: Mac OS X → All
Hardware: x86 → All
Whiteboard: fixed-in-tracemonkey
Target Milestone: --- → mozilla6
cdleary-bot mozilla-central merge info:
http://hg.mozilla.org/mozilla-central/rev/8af92dba2480
Status: ASSIGNED → RESOLVED
Last Resolved: 6 years ago
Resolution: --- → FIXED
Crash Signature: [@ js_GetPropertyHelperInline] [@ js_str_charAt] [@ js_ValueToString]
You need to log in before you can comment on or make changes to this bug.