Last Comment Bug 703544 - Crash [@ JS::Value::isMarkable]
: Crash [@ JS::Value::isMarkable]
: crash, testcase
Product: Core
Classification: Components
Component: JavaScript Engine (show other bugs)
: Trunk
: x86 Linux
-- critical (vote)
: mozilla11
Assigned To: Bill McCloskey (:billm)
: Jason Orendorff [:jorendorff]
Depends on:
Blocks: langfuzz
  Show dependency treegraph
Reported: 2011-11-18 03:26 PST by Christian Holler (:decoder)
Modified: 2013-01-14 08:26 PST (History)
3 users (show)
choller: in‑testsuite+
See Also:
Crash Signature:
QA Whiteboard:
Iteration: ---
Points: ---
Has Regression Range: ---
Has STR: ---

fix (2.32 KB, patch)
2011-11-18 17:36 PST, Bill McCloskey (:billm)
bhackett1024: review+
Details | Diff | Splinter Review

Description User image Christian Holler (:decoder) 2011-11-18 03:26:39 PST
The following test crashes on mozilla-central revision b62e6ee5ba9b (options -m -a -n):

function testInterpreterReentry7() {
    var arr = [0, 1, 2, 3, 4];
    for (var i = (1); i < 5; i++)
        arr[i] = "grue";
assertEq(testInterpreterReentry7(), "grue bleen");


==9568== Invalid read of size 4
==9568==    at 0x8058C45: JS::Value::isMarkable() const (jsapi.h:467)
==9568==    by 0x8100CD8: js::gc::MarkValueRaw(JSTracer*, JS::Value const&) (jsgcmark.cpp:462)
==9568==    by 0x8100D72: js::gc::MarkValueUnbarriered(JSTracer*, JS::Value const&, char const*) (jsgcmark.cpp:472)
==9568==    by 0x839B4B2: js::mjit::stubs::WriteBarrier(js::VMFrame&, JS::Value*) (StubCalls.cpp:2558)
==9568==    by 0x4C738DE: ???
==9568==    by 0x8523FF3: ??? (in /srv/repos/mozilla-central/js/src/debug32/shell/js)
==9568==  Address 0x56136c8c is not stack'd, malloc'd or (recently) free'd

This is gczeal(4) only, therefore I assume it's related to incremental GC and not s-s until incremental GC lands.
Comment 1 User image Bill McCloskey (:billm) 2011-11-18 17:36:05 PST
Created attachment 575607 [details] [diff] [review]
Comment 2 User image Bill McCloskey (:billm) 2011-11-18 17:38:47 PST
Comment on attachment 575607 [details] [diff] [review]

Sometimes I hate bugzilla and it's stupid behavior when you hit enter in the wrong place.
Comment 3 User image Bill McCloskey (:billm) 2011-11-18 17:41:37 PST
Comment on attachment 575607 [details] [diff] [review]

Well, good enough I guess.
Comment 5 User image Ed Morley [:emorley] 2011-11-19 05:11:25 PST
Comment 6 User image Christian Holler (:decoder) 2013-01-14 08:26:08 PST
A testcase for this bug was automatically identified at js/src/jit-test/tests/basic/bug703544.js.

Note You need to log in before you can comment on or make changes to this bug.