Last Comment Bug 756781 - IonMonkey: Assertion failure: IsMarkedOrAllocated(static_cast<Cell *>(thing)), at jsgc.cpp:4466
: IonMonkey: Assertion failure: IsMarkedOrAllocated(static_cast<Cell *>(thing))...
Status: VERIFIED FIXED
[jsbugmon:update][fuzzblocker]
: assertion, testcase
Product: Core
Classification: Components
Component: JavaScript Engine (show other bugs)
: Other Branch
: x86_64 Linux
: -- major (vote)
: ---
Assigned To: David Anderson [:dvander]
:
Mentors:
Depends on:
Blocks: langfuzz IonFuzz
  Show dependency treegraph
 
Reported: 2012-05-19 07:46 PDT by Christian Holler (:decoder)
Modified: 2013-01-14 08:43 PST (History)
7 users (show)
choller: in‑testsuite+
See Also:
Crash Signature:
(edit)
QA Whiteboard:
Iteration: ---
Points: ---
Has Regression Range: ---
Has STR: ---


Attachments
fix (1.46 KB, patch)
2012-05-21 15:28 PDT, David Anderson [:dvander]
wmccloskey: review+
Details | Diff | Review

Description Christian Holler (:decoder) 2012-05-19 07:46:32 PDT
The following testcase asserts on ionmonkey revision 890dd17b4187 (run with --ion -n -m --ion-eager):


function AddTestCase( description, expect, actual ) {
  new TestCase( SECTION, description, expect, actual );
}
function TestCase(n, d, e, a) {}
var SECTION = "String/match-004.js";
re = /0./;
s = 10203040506070809000;
Number.prototype.match = String.prototype.match;
AddRegExpCases(  re, "re = " + re , s, String(s), 1, ["02"]);
AddRegExpCases(  re, re, s, ["02"]);
function AddRegExpCases(
  regexp, str_regexp, string, str_string, index, matches_array ) {
  if ( regexp.exec(string) == null || matches_array == null ) {
    AddTestCase( string.match(regexp) );
  }
  AddTestCase( string.match(regexp).input );
  gczeal(4);
}
Comment 1 David Anderson [:dvander] 2012-05-21 15:28:49 PDT
Created attachment 625787 [details] [diff] [review]
fix

Sweet, I can actually debug these now. For technical reasons we can't trace invalidated IonCode objects, so tracing the IonScript later doesn't suffice for incremental GC. We can just force a trace here.
Comment 2 David Anderson [:dvander] 2012-05-21 16:43:58 PDT
http://hg.mozilla.org/projects/ionmonkey/rev/454dcc349cbb
Comment 3 Christian Holler (:decoder) 2012-05-21 17:37:59 PDT
JSBugMon: This bug has been automatically verified fixed.
Comment 4 Christian Holler (:decoder) 2013-01-14 08:43:32 PST
A testcase for this bug was automatically identified at js/src/jit-test/tests/ion/bug756781.js.

Note You need to log in before you can comment on or make changes to this bug.