[jsdbg2] Assertion failure: !fp->isEvalFrame(), at jsinterpinlines.h:276

RESOLVED FIXED in mozilla9

Status

()

Core
JavaScript Engine
--
critical
RESOLVED FIXED
6 years ago
4 years ago

People

(Reporter: decoder, Assigned: luke)

Tracking

(Blocks: 1 bug, {assertion, testcase})

Other Branch
mozilla9
x86_64
Linux
assertion, testcase
Points:
---
Bug Flags:
in-testsuite +

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: [inbound])

Attachments

(1 attachment)

(Reporter)

Description

6 years ago
The following code asserts on jsdbg2 branch (revision 82545b1e4129, options -j -m -d):


var g = newGlobal('new-compartment');
var dbg = new Debugger(g);
dbg.onDebuggerStatement = function (frame) {
    var code = "assertEq(c, 'ok');\n";
    assertEq(frame.evalWithBindings("eval(s)", {s: code, a: 1234}).return, undefined);
};
g.eval("function first() { return second(); }");
g.eval("function second() { return eval('third()'); }");
g.eval("function third() { debugger; }");
g.evaluate("first();");
Reduced a bit:

var g = newGlobal('new-compartment');
var dbg = new Debugger(g);
dbg.onDebuggerStatement = function (frame) {
    frame.eval("eval('0')");
};
g.eval("(function () { debugger; })();");
This happens in m-i too, with -d:

function f() {}
trap(f, 0, 'eval("2+2")');
f();
(Assignee)

Comment 3

6 years ago
Created attachment 552259 [details] [diff] [review]
fix for m-i

Sorry about ignoring your vote; I already had the patch :)

The heavyweight assert was removed since evalInFrame let's you put an eval frame inside a non-heavyweight function.
Assignee: general → luke
Status: NEW → ASSIGNED
Attachment #552259 - Flags: review?(jorendorff)
Comment on attachment 552259 [details] [diff] [review]
fix for m-i

Great!
Attachment #552259 - Flags: review?(jorendorff) → review+
(Assignee)

Comment 5

6 years ago
http://hg.mozilla.org/integration/mozilla-inbound/rev/2e2e0dc4654c
Whiteboard: [inbound]
http://hg.mozilla.org/mozilla-central/rev/2e2e0dc4654c
Status: ASSIGNED → RESOLVED
Last Resolved: 6 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla9
(Reporter)

Comment 7

4 years ago
A testcase for this bug was automatically identified at js/src/jit-test/tests/basic/testBug677367.js.
Flags: in-testsuite+
You need to log in before you can comment on or make changes to this bug.