Closed
Bug 744285
Opened 14 years ago
Closed 14 years ago
Assertion failure: IsMarkedOrAllocated(static_cast<Cell *>(*thingp)), at jsgc.cpp:4278
Categories
(Core :: JavaScript Engine, defect)
Tracking
()
RESOLVED
FIXED
mozilla14
People
(Reporter: decoder, Assigned: billm)
References
Details
(Keywords: assertion, testcase, Whiteboard: js-triage-needed)
Attachments
(2 files)
|
2.12 KB,
application/javascript
|
Details | |
|
5.47 KB,
patch
|
igor
:
review+
|
Details | Diff | Splinter Review |
The attached test asserts on mozilla-central revision 3fa30b0edd15 (options -m -a -n).
Marking s-s because this assertion is GC-related.
Billm: Is this a dup of bug 740509 or some other issue?
| Assignee | ||
Comment 1•14 years ago
|
||
This is a regression from bug 739899. When doing conservative stack scanning, I checked the gcRunning flag to see if we should reject things in other compartments. However, this flag is set by AutoHeapSession (i.e., but pretty much anyone who will use the conservative scanner). We really need to be checking IS_GC_MARKING_TRACER.
This doesn't affect the GC or CC, so I don't think it's sensitive.
Attachment #614174 -
Flags: review?
| Assignee | ||
Updated•14 years ago
|
Group: core-security
| Assignee | ||
Updated•14 years ago
|
Attachment #614174 -
Flags: review? → review?(igor)
Comment 2•14 years ago
|
||
Comment on attachment 614174 [details] [diff] [review]
patch
Review of attachment 614174 [details] [diff] [review]:
-----------------------------------------------------------------
The test is really nice!
Attachment #614174 -
Flags: review?(igor) → review+
| Assignee | ||
Comment 5•14 years ago
|
||
Target Milestone: --- → mozilla14
Comment 6•14 years ago
|
||
Status: NEW → RESOLVED
Closed: 14 years ago
Resolution: --- → FIXED
| Reporter | ||
Comment 7•13 years ago
|
||
A testcase for this bug was automatically identified at js/src/jit-test/tests/basic/bug744285.js.
Flags: in-testsuite+
You need to log in
before you can comment on or make changes to this bug.
Description
•