The default bug view has changed. See this FAQ.

Crash [@ js_CheckForStringIndex] or [@ js::ArrayBuffer::obj_lookupProperty]

RESOLVED FIXED

Status

()

Core
JavaScript Engine
--
critical
RESOLVED FIXED
6 years ago
3 years ago

People

(Reporter: gkw, Unassigned)

Tracking

(Blocks: 1 bug, {crash, testcase})

Trunk
x86
Linux
crash, testcase
Points:
---
Bug Flags:
in-testsuite +

Firefox Tracking Flags

(firefox7-)

Details

(Whiteboard: js-triage-needed)

Attachments

(1 attachment)

(Reporter)

Description

6 years ago
Created attachment 541088 [details]
stack

o = (new Uint32Array).buffer
o.__proto__ = o
o.__proto__ = o

crashes js debug shell on TM changeset 0428dbdf3d58 with and without the patch in bug 665914, without any CLI arguments at js_CheckForStringIndex and crashes js opt shell at js::ArrayBuffer::obj_lookupProperty
0428dbdf3d58 is referring to some other changeset on TM.

The test case does fail before the patch attached to bug 665355, but raises type-error after that as it should.
(Reporter)

Comment 2

6 years ago
(In reply to comment #1)
> 0428dbdf3d58 is referring to some other changeset on TM.

I mean, that is the changeset which happened to be TM tip at the time of testing.
can you reproduce this after the set of patches that landed now? (latest is c3ceee49ac37)

Comment 4

6 years ago
The release team doesn't need to track this. If the JS team thinks it's important, they'll prioritize a fix and can ask for approval if that fix needs to land on branches.
tracking-firefox7: ? → -
Whiteboard: js-triage-needed

Comment 5

6 years ago
There are 2 other bugs logged with related signatures; bug 639337 and bug 591513. Did we regress the original crash or will this fix all of them.
(Reporter)

Comment 6

6 years ago
(In reply to Nikhil Marathe from comment #3)
> can you reproduce this after the set of patches that landed now? (latest is
> c3ceee49ac37)

Nope, can't reproduce this with JM changeset e0b67d8cc908 with patch v1 from bug 672892, this has m-c merge at rev a6c87fd27ba9.

Assuming fixed by patches for bug 665355.
Status: NEW → RESOLVED
Last Resolved: 6 years ago
Resolution: --- → FIXED
(Reporter)

Updated

6 years ago
Flags: in-testsuite?
Automatically extracted testcase for this bug was committed:

https://hg.mozilla.org/mozilla-central/rev/efaf8960a929
Flags: in-testsuite? → in-testsuite+
You need to log in before you can comment on or make changes to this bug.