Closed Bug 754828 Opened 7 years ago Closed 7 years ago

Intermittent crash during nested-delete-name-in-evalcode.js [@ js::gc::GetGCThingTraceKind]

Categories

(Core :: JavaScript Engine, defect, critical)

x86
macOS
defect
Not set
critical

Tracking

()

RESOLVED WORKSFORME

People

(Reporter: emorley, Unassigned)

References

Details

(Keywords: crash, intermittent-failure, Whiteboard: [js:t])

Crash Data

Rev3 MacOSX Leopard 10.5.8 mozilla-inbound debug test jsreftest on 2012-05-12 16:12:18 PDT for push f77082549e0e

slave: talos-r3-leopard-048

https://tbpl.mozilla.org/php/getParsedLog.php?id=11710871&tree=Mozilla-Inbound

{
REFTEST INFO | Loading a blank page
++DOMWINDOW == 9 (0xb5b5c888) [serial = 2643] [outer = 0xb122e40]
REFTEST TEST-START | file:///Users/cltbld/talos-slave/test/build/jsreftest/tests/jsreftest.html?test=ecma_5/Expressions/nested-delete-name-in-evalcode.js | 1363 / 3409 (39%)
++DOMWINDOW == 10 (0x4b42e0c8) [serial = 2644] [outer = 0xb122e40]
616294: |delete x| inside a function in eval code, where that eval code includes |var x| at top level, actually does delete the binding for x
All tests passed!
Assertion failure: allocated(), at ../../../js/src/gc/Heap.h:497
TEST-UNEXPECTED-FAIL | file:///Users/cltbld/talos-slave/test/build/jsreftest/tests/jsreftest.html?test=ecma_5/Expressions/nested-delete-name-in-evalcode.js | Exited with code 1 during test run
INFO | automation.py | Application ran for: 0:07:19.396806
INFO | automation.py | Reading PID log: /var/folders/Xr/Xr--yJnSEY0U11ET5NZuMU+++TM/-Tmp-/tmpau-dsJpidlog
Downloading symbols from: http://ftp.mozilla.org/pub/mozilla.org/firefox/tinderbox-builds/mozilla-inbound-macosx-debug/1336863408/firefox-15.0a1.en-US.mac.crashreporter-symbols.zip
PROCESS-CRASH | file:///Users/cltbld/talos-slave/test/build/jsreftest/tests/jsreftest.html?test=ecma_5/Expressions/nested-delete-name-in-evalcode.js | application crashed (minidump found)
Crash dump filename: /var/folders/Xr/Xr--yJnSEY0U11ET5NZuMU+++TM/-Tmp-/tmpO7rbo5/minidumps/64EB296B-486B-48C5-8AE5-80FBEBA10233.dmp
Operating system: Mac OS X
                  10.5.8 9L31a
CPU: x86
     GenuineIntel family 6 model 23 stepping 10
     2 CPUs

Crash reason:  EXC_BAD_ACCESS / KERN_PROTECTION_FAILURE
Crash address: 0x0

Thread 0 (crashed)
 0  XUL!js::gc::GetGCThingTraceKind [Heap.h : 497 + 0x1a]
    eip = 0x05e3116f   esp = 0xbfffcde0   ebp = 0xbfffcdf8   ebx = 0x05e3111d
    esi = 0x126eb000   edi = 0x00000000   eax = 0x00000000   ecx = 0x00000000
    edx = 0x00000000   efl = 0x00010246
    Found by: given as instruction pointer in context
 1  XUL!js::gc::MarkKind [Marking.cpp : 230 + 0x7]
    eip = 0x05e2caeb   esp = 0xbfffce00   ebp = 0xbfffce38   ebx = 0x05e2cac4
    esi = 0xbfffce6c   edi = 0x00000000
    Found by: call frame info
 2  XUL!js::gc::MarkValueInternal [Marking.cpp : 329 + 0x12]
    eip = 0x05e2cdc7   esp = 0xbfffce40   ebp = 0xbfffce88   ebx = 0x05e2cd24
    esi = 0x1011c478   edi = 0x0065f180
    Found by: call frame info
 3  XUL!proxy_TraceObject [jsproxy.cpp : 1259 + 0x19]
    eip = 0x05c664cf   esp = 0xbfffce90   ebp = 0xbfffceb8   ebx = 0x05c664ae
    esi = 0x1011c460   edi = 0x0065f180
    Found by: call frame info
 4  XUL!js::GCMarker::processMarkStackTop [Marking.cpp : 1092 + 0xe]
    eip = 0x05e37e32   esp = 0xbfffcec0   ebp = 0xbfffcf68   ebx = 0x05e37a21
    esi = 0x10bca6b8   edi = 0x064116c0
    Found by: call frame info
 5  XUL!js::GCMarker::drainMarkStack [Marking.cpp : 1136 + 0xb]
    eip = 0x05e301dc   esp = 0xbfffcf70   ebp = 0xbfffcfa8   ebx = 0x0065f19c
    esi = 0x0065f180   edi = 0xbfffd05c
    Found by: call frame info
 6  XUL!GCCycle [jsgc.cpp : 3471 + 0x14]
    eip = 0x05b7d46c   esp = 0xbfffcfb0   ebp = 0xbfffd0a8   ebx = 0x05b7cba1
    esi = 0x0065f180   edi = 0x0065f914
    Found by: call frame info
 7  XUL!Collect [jsgc.cpp : 3719 + 0x1d]
    eip = 0x05b7dec3   esp = 0xbfffd0b0   ebp = 0xbfffd128   ebx = 0x05b7dc0e
    esi = 0x0065f208   edi = 0x0065f000
    Found by: call frame info
 8  XUL!js::GCSlice [jsgc.cpp : 3749 + 0x2a]
    eip = 0x05b7e2d4   esp = 0xbfffd130   ebp = 0xbfffd148   ebx = 0x0439b30e
    esi = 0x00000000   edi = 0x06dee000
    Found by: call frame info
 9  XUL!js::IncrementalGC [jsfriendapi.cpp : 179 + 0x19]
    eip = 0x05b4ec30   esp = 0xbfffd150   ebp = 0xbfffd168   ebx = 0x0439b30e
}
bug 754674 also involves proxy_TraceObject, though it dies in a different place.
Blocks: 754856
Whiteboard: [orange] → [js:t][orange]
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → WORKSFORME
Whiteboard: [js:t][orange] → [js:t]
You need to log in before you can comment on or make changes to this bug.