The default bug view has changed. See this FAQ.

TI+JM: crash in mjit-generated code

RESOLVED FIXED

Status

()

Core
JavaScript Engine
RESOLVED FIXED
6 years ago
6 years ago

People

(Reporter: jandem, Unassigned)

Tracking

(Blocks: 1 bug)

Firefox Tracking Flags

(Not tracked)

Details

(Reporter)

Description

6 years ago
--
(function () {
    var x;
    x = arguments.length;
    return function () {
        [1][x = arguments.length];
    };
}).call().apply();
--
This crashes 64-bit shell with -m -n -a.
During frame prologues for scripts which use their arguments, we make sure the number of actual arguments is correctly set even if nargs == nactual, to speed up accesses to arguments.length and bounds checks on arguments[i] later on.  On x64 we used a 32 bit store but would later do 64 bit arithmetic on it, so we could end up reading uninitialized high bits from the field.

http://hg.mozilla.org/projects/jaegermonkey/rev/6d423e5f2e48
Status: NEW → RESOLVED
Last Resolved: 6 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.