The default bug view has changed. See this FAQ.

IonMonkey: Crash [@ js::gc::ChunkBitmap::markIfUnmarked]

RESOLVED FIXED

Status

()

Core
JavaScript Engine
--
major
RESOLVED FIXED
5 years ago
4 years ago

People

(Reporter: decoder, Assigned: dvander)

Tracking

(Blocks: 2 bugs, {crash, testcase})

Other Branch
x86_64
Linux
crash, testcase
Points:
---
Dependency tree / graph
Bug Flags:
in-testsuite +

Firefox Tracking Flags

(Not tracked)

Details

(crash signature)

Attachments

(3 attachments)

(Reporter)

Description

5 years ago
The following testcase crashes on ionmonkey revision d66c148e0756 (run with --ion -n), tested on 64 bit:


var o0 = [];
var o4 = {};
var o5 = Math;
function f6(o) { o[("Keywords")] = o;};
for(var i=0; i<20; i++) {
    f6(o0);
    f6(o4);
    f6(o5);
}
gc();
(Assignee)

Comment 1

5 years ago
The bug here is that lhs == rhs in the register allocator, and then we generate code like:

   push lhs
   mov [lhs.slots], lhs
   mov rhs, [lhs]
   pop lhs

So we just need to get an extra register. But before that I'd like to refactor the SetProperty stuff so it looks more like GetProperty/GetElement.
(Assignee)

Comment 2

5 years ago
Created attachment 595519 [details] [diff] [review]
part 1: split MGenericSetProperty up

This patch splits MGenericSetProperty into MCallSetProperty and MSetPropertyCache. LCallSetPropertyV/T are then combined into one unspecialized LCallSetProperty.
Assignee: general → dvander
Status: NEW → ASSIGNED
Attachment #595519 - Flags: review?(jdemooij)
(Assignee)

Comment 3

5 years ago
Created attachment 595521 [details] [diff] [review]
part 2, rename LCacheSetProperty to LSetPropertyCache
Attachment #595521 - Flags: review?(jdemooij)
(Assignee)

Comment 4

5 years ago
Created attachment 595537 [details] [diff] [review]
part 3, fix the bug
Attachment #595537 - Flags: review?(jdemooij)
(Assignee)

Updated

5 years ago
Duplicate of this bug: 725073
Comment on attachment 595519 [details] [diff] [review]
part 1: split MGenericSetProperty up

Review of attachment 595519 [details] [diff] [review]:
-----------------------------------------------------------------

::: js/src/ion/MIR.h
@@ +2959,5 @@
>      bool strict_;
> +
> +  protected:
> +    MSetPropertyInstruction(MDefinition *obj, MDefinition *value, JSAtom *atom,
> +                        bool strict)

Nit: this needs some extra spaces
Attachment #595519 - Flags: review?(jdemooij) → review+
Comment on attachment 595521 [details] [diff] [review]
part 2, rename LCacheSetProperty to LSetPropertyCache

Review of attachment 595521 [details] [diff] [review]:
-----------------------------------------------------------------

What about renaming GetPropertyCache so these instructions use either a Call* or a Cache* prefix?
Attachment #595521 - Flags: review?(jdemooij) → review+

Updated

5 years ago
Attachment #595537 - Flags: review?(jdemooij) → review+
(Assignee)

Comment 8

5 years ago
http://hg.mozilla.org/projects/ionmonkey/rev/9cd94217ee4f
http://hg.mozilla.org/projects/ionmonkey/rev/d546f1b141b9
http://hg.mozilla.org/projects/ionmonkey/rev/28c66941856b

I think I prefer Call/Cache as suffixes, but it's not a strong preference.
Status: ASSIGNED → RESOLVED
Last Resolved: 5 years ago
Resolution: --- → FIXED
(Reporter)

Comment 9

4 years ago
A testcase for this bug was automatically identified at js/src/jit-test/tests/ion/bug725067.js.
Flags: in-testsuite+
You need to log in before you can comment on or make changes to this bug.