The default bug view has changed. See this FAQ.

Infinite recursion crash with ArrayBuffer through js::ArrayBuffer::obj_lookupGeneric

RESOLVED FIXED

Status

()

Core
JavaScript Engine
--
critical
RESOLVED FIXED
5 years ago
4 years ago

People

(Reporter: decoder, Unassigned)

Tracking

(Blocks: 1 bug, {crash, testcase})

Trunk
x86_64
Linux
crash, testcase
Points:
---
Dependency tree / graph
Bug Flags:
in-testsuite +

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: js-triage-needed [jsbugmon:update,ignore])

(Reporter)

Description

5 years ago
The following test crashes on mozilla-central revision 55e7efcc1946 (no options required):


var o = Object.preventExtensions(new ArrayBuffer);
try { (function () { o.__proto__ = ({ __proto__: o, indexArray: ["abc"] }); })(); } catch(exc) {}
uneval(this);


Here's one cycle of the recursion that leads to the crash:

#250 0x0000000000543643 in LookupPropertyWithFlagsInline (cx=0xbaba90, obj=0x7ffff6115140, id=..., flags=1, objp=0x7fffffffc448, propp=0x7fffffffc440) at /srv/repos/mozilla-central/js/src/jsobj.cpp:4696
#251 0x00000000005437ef in js_LookupProperty (cx=0xbaba90, obj=0x7ffff6105080, id=..., objp=0x7fffffffc448, propp=0x7fffffffc440) at /srv/repos/mozilla-central/js/src/jsobj.cpp:4731
#252 0x00000000004078f1 in JSObject::lookupGeneric (this=0x7ffff6105080, cx=0xbaba90, id=..., objp=0x7fffffffc448, propp=0x7fffffffc440) at ../../jsobjinlines.h:1019
#253 0x00000000005cc241 in js::ArrayBuffer::obj_lookupGeneric (cx=0xbaba90, obj=0x7ffff61031a0, id=..., objp=0x7fffffffc448, propp=0x7fffffffc440) at /srv/repos/mozilla-central/js/src/jstypedarray.cpp:359
#254 0x00000000004078f1 in JSObject::lookupGeneric (this=0x7ffff61031a0, cx=0xbaba90, id=..., objp=0x7fffffffc448, propp=0x7fffffffc440) at ../../jsobjinlines.h:1019
See bug 728722.
See Also: → bug 728722
(Reporter)

Updated

5 years ago
Whiteboard: js-triage-needed → js-triage-needed [jsbugmon:update,bisect,bisectfix]
(Reporter)

Updated

5 years ago
Whiteboard: js-triage-needed [jsbugmon:update,bisect,bisectfix] → js-triage-needed [jsbugmon:update,ignore]
(Reporter)

Comment 2

5 years ago
JSBugMon: The testcase found in this bug no longer reproduces (tried revision f9a8fdb08193).
JSBugMon: Fix Bisection requested, result:
autoBisect shows this is probably related to the following changeset:

The first good revision is:
changeset:   99553:7a26f7c820bd
user:        Jeff Walden
date:        Wed Jun 27 18:35:56 2012 -0700
summary:     Bug 770344 - Experiment implementing __proto__ as an accessor.  r=luke
(Reporter)

Comment 3

5 years ago
Likely fixed by bug 728722, marking as fixed.
Status: NEW → RESOLVED
Last Resolved: 5 years ago
Depends on: 728722
Resolution: --- → FIXED
(Reporter)

Comment 4

4 years ago
Automatically extracted testcase for this bug was committed:

https://hg.mozilla.org/mozilla-central/rev/efaf8960a929
Flags: in-testsuite+
You need to log in before you can comment on or make changes to this bug.