Assertion failure: static_cast<Cell *>(thing)->isMarked(), at jsgc.cpp:3670

RESOLVED FIXED in mozilla13

Status

()

Core
JavaScript Engine
--
critical
RESOLVED FIXED
5 years ago
4 years ago

People

(Reporter: decoder, Assigned: billm)

Tracking

(Blocks: 1 bug, {assertion, testcase})

Trunk
mozilla13
x86_64
Linux
assertion, testcase
Points:
---
Bug Flags:
in-testsuite +

Firefox Tracking Flags

(Not tracked)

Details

Attachments

(1 attachment)

(Reporter)

Description

5 years ago
The following test asserts on mozilla-central revision 8a59519e137e (options -m -n):


gczeal(4);
var BUGNUMBER = 668024;
var summary =
print(BUGNUMBER + ": " + summary);
var arr = [0, 1, 2, 3, 4, 5, , 7];
var seen = [];
for (var p in arr) {
    if (seen.indexOf(unescape) >= 0) {}
    arr.splice(2, 3);
  seen.push(p);
}


Seems related to incremental GC, so not security relevant for now.
(Assignee)

Comment 1

5 years ago
Created attachment 592799 [details] [diff] [review]
patch

Looks like this has been missing since write barriers landed. Oops.
Attachment #592799 - Flags: review?(bhackett1024)
Attachment #592799 - Flags: review?(bhackett1024) → review+
(Assignee)

Comment 2

5 years ago
https://hg.mozilla.org/integration/mozilla-inbound/rev/32af27f89c49
Target Milestone: --- → mozilla13
Backed out in https://hg.mozilla.org/integration/mozilla-inbound/rev/71f5bf4df2f6 - one of the six in that push was crashing in js::gc::Mark<JSString>
Target Milestone: mozilla13 → ---
(Assignee)

Comment 4

5 years ago
https://hg.mozilla.org/integration/mozilla-inbound/rev/5fe3e1c45867
Target Milestone: --- → mozilla13
https://hg.mozilla.org/mozilla-central/rev/5fe3e1c45867
Status: NEW → RESOLVED
Last Resolved: 5 years ago
Resolution: --- → FIXED
(Reporter)

Comment 6

4 years ago
A testcase for this bug was automatically identified at js/src/jit-test/tests/basic/bug722028.js.
Flags: in-testsuite+
You need to log in before you can comment on or make changes to this bug.