Last Comment Bug 762450 - Assertion failure: !script()->formalIsAliased(i), at vm/Stack-inl.h:250
: Assertion failure: !script()->formalIsAliased(i), at vm/Stack-inl.h:250
Status: RESOLVED FIXED
js-triage-needed
: assertion, testcase
Product: Core
Classification: Components
Component: JavaScript Engine (show other bugs)
: Trunk
: x86 Linux
: -- critical (vote)
: mozilla16
Assigned To: Luke Wagner [:luke]
:
Mentors:
: 762014 (view as bug list)
Depends on:
Blocks: langfuzz
  Show dependency treegraph
 
Reported: 2012-06-07 05:25 PDT by Christian Holler (:decoder)
Modified: 2013-01-14 08:17 PST (History)
5 users (show)
choller: in‑testsuite+
See Also:
Crash Signature:
(edit)
QA Whiteboard:
Iteration: ---
Points: ---
Has Regression Range: ---
Has STR: ---


Attachments
patch and fix (1.85 KB, patch)
2012-06-07 14:00 PDT, Luke Wagner [:luke]
bhackett1024: review+
Details | Diff | Splinter Review
fix and test (2.64 KB, patch)
2012-06-07 14:44 PDT, Luke Wagner [:luke]
bhackett1024: review+
Details | Diff | Splinter Review

Description Christian Holler (:decoder) 2012-06-07 05:25:21 PDT
The following test asserts on mozilla-central revision cf4face65451 (options -m -n -a):


function f(a, b, c) {
    arguments.length = (c--) + 1;
}
f();
Comment 1 Luke Wagner [:luke] 2012-06-07 14:00:49 PDT
Created attachment 631124 [details] [diff] [review]
patch and fix

Nobody expects the js_InternalInterpret!
Comment 2 Luke Wagner [:luke] 2012-06-07 14:44:45 PDT
Created attachment 631151 [details] [diff] [review]
fix and test

Incredibly, DoIncDec is totally wrong when &v != slot.  (This was only exposed with bug 659577 which added the first such use.)
Comment 3 Brian Hackett (:bhackett) 2012-06-07 15:53:30 PDT
Comment on attachment 631151 [details] [diff] [review]
fix and test

Patch has unrelated changes in FinishVarIncOp
Comment 4 Luke Wagner [:luke] 2012-06-07 16:57:27 PDT
The changes in FinishVarIncOp is the patch in comment 1; the new patch adds the fix in DoIncDec.
Comment 6 Graeme McCutcheon [:graememcc] 2012-06-08 04:17:44 PDT
https://hg.mozilla.org/mozilla-central/rev/b1e796090d2c

(Merged by Ed Morley)
Comment 7 Luke Wagner [:luke] 2012-06-08 17:05:02 PDT
*** Bug 762014 has been marked as a duplicate of this bug. ***
Comment 8 Christian Holler (:decoder) 2013-01-14 08:17:17 PST
A testcase for this bug was automatically identified at js/src/jit-test/tests/basic/testBug762450.js.

Note You need to log in before you can comment on or make changes to this bug.