Assertion failure: regs.fp()->prev() == regs_->fp(), at js/src/vm/Stack.cpp:339 or Crash [@ CrashIfInvalidSlot]

RESOLVED FIXED in mozilla15

Status

()

Core
JavaScript Engine
--
critical
RESOLVED FIXED
5 years ago
4 years ago

People

(Reporter: decoder, Unassigned)

Tracking

(Blocks: 1 bug, {assertion, crash, testcase})

Trunk
mozilla15
x86_64
Linux
assertion, crash, testcase
Points:
---
Dependency tree / graph
Bug Flags:
in-testsuite +

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: [js:p1:fx15], crash signature)

Attachments

(1 attachment)

(Reporter)

Description

5 years ago
The following test crashes on mozilla-central revision 032d43b1770f (options -m -n -a):


var lfcode = new Array();
lfcode.push("");
lfcode.push("test();");
while (true) {
        var file = lfcode.shift(); if (file == undefined) { break; }
        loadFile(file);
}
function loadFile(lfVarx) {
        evaluate(lfVarx);
}



The test is very similar to bug 728191 (same assertion, but doesn't reproduce anymore), so it's likely the same underlying issue.

Comment 1

5 years ago
Created attachment 621625 [details] [diff] [review]
fix and test

ContextStack::pushExecuteFrame is sampling 'fp' before ensureOnTop flushes inlined frames which means that it doesn't get the most recent 'fp'.
Attachment #621625 - Flags: review?(bhackett1024)

Updated

5 years ago
Whiteboard: js-triage-needed → js-triage-done
Whiteboard: js-triage-done → [js:p1:fx15]
Whiteboard: [js:p1:fx15] → [js:p1:fx15][js:ni]
Attachment #621625 - Flags: review?(bhackett1024) → review+

Comment 2

5 years ago
https://hg.mozilla.org/integration/mozilla-inbound/rev/b6ce79884966
Target Milestone: --- → mozilla15

Comment 3

5 years ago
https://hg.mozilla.org/mozilla-central/rev/b6ce79884966
Status: NEW → RESOLVED
Last Resolved: 5 years ago
Resolution: --- → FIXED
Whiteboard: [js:p1:fx15][js:ni] → [js:p1:fx15]
(Reporter)

Updated

5 years ago
Duplicate of this bug: 728191
(Reporter)

Comment 5

4 years ago
A testcase for this bug was automatically identified at js/src/jit-test/tests/basic/testBug752379.js.
Flags: in-testsuite+
You need to log in before you can comment on or make changes to this bug.