Created attachment 557574 [details] testcase Attached ~50-line testcase crashes js debug shell on m-c changeset 7d3d1c2c75f8 with -m, -a and -d. Because it's on Windows, I don't yet have a stack. Since this involves gc, I'm locking just-in-case, as per normal. This was found using a triple combination of an existing js test, jsfunfuzz and jandem's method fuzzer.
Created attachment 557977 [details] [diff] [review] patch The fix for bug 679461 was disabled when bug 674251 landed. This is a better fix, closer to the problem --- the debugger shouldn't try to recompile scripts during GC.
Attachment #557977 - Flags: review?(jorendorff)
Whiteboard: js-triage-needed → fixed-in-jaegermonkey
Comment on attachment 557977 [details] [diff] [review] patch Sure, ok. The comment might be too confident--are we really sure the script is necessarily being destroyed? Perhaps something else is being GC'd and we are calling JS_ClearTrap from a finalize hook. Skipping recompilation is harmless in any case.
Attachment #557977 - Flags: review?(jorendorff) → review+
Status: NEW → RESOLVED
Last Resolved: 7 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.