Closed Bug 777653 Opened 14 years ago Closed 14 years ago

IonMonkey: Crash in jsreftests, under ReconstructPCStack

Categories

(Core :: JavaScript Engine, defect)

x86_64
Windows 7
defect
Not set
normal

Tracking

()

RESOLVED WORKSFORME

People

(Reporter: dvander, Unassigned)

References

()

Details

(Whiteboard: [ion:p1:fx18])

This crash appears in the J column for all platforms. The stack trace for win32-debug is: 0 mozjs.dll!SimulateOp [jsopcode.cpp:81146d7c9f51 : 5967 + 0x4e] eip = 0x6937b51f esp = 0x0019cd40 ebp = 0x0019cd54 ebx = 0x766b060c esi = 0x766a509b edi = 0x725a1440 eax = 0x00000000 ecx = 0x026948a7 edx = 0x7269e4d8 efl = 0x00000212 Found by: given as instruction pointer in context 1 mozjs.dll!ReconstructPCStack [jsopcode.cpp:81146d7c9f51 : 6090 + 0x1c] eip = 0x6937bbad esp = 0x0019cd5c ebp = 0x0019cd8c Found by: call frame info 2 mozjs.dll!js_DecompileValueGenerator [jsopcode.cpp:81146d7c9f51 : 5774 + 0x16] eip = 0x69380edf esp = 0x0019cd94 ebp = 0x0019cf30 Found by: call frame info (Full trace in the URL)
Whiteboard: [js:p1:fx18]
Whiteboard: [js:p1:fx18] → [ion:p1:fx18]
This is a decompiler regression from bug 767349. I reduced it to try { } catch(ex if ex instanceof TypeError) { } null[0]; The problem is that the JSOP_THROW (to rethrow the exception if not a TypeError) has SRC_HIDDEN. So before bug 767349 we didn't attempt to decompile it, but now we do and this asserts because pcdepth is 0 and nuses is 1. 00000: 1 try 6 (+6) 00001: 2 goto 42 (+41) 00006: 3 enterblock depth 0 {ex: 0} 00011: 3 exception 00012: 3 dup 00013: 3 setlocal 0 00016: 3 pop 00017: 3 getlocal 0 00020: 3 getgname "TypeError" 00025: 3 instanceof 00026: 3 ifeq 40 (+14) 00031: 3 pop 00032: 4 leaveblock 1 00035: 4 goto 42 (+7) --> 00040: 4 throw 00041: 4 nop 00042: 5 null 00043: 5 zero 00044: 5 getelem 00045: 5 pop 00046: 5 stop
Blocks: 767349
With the deprecation of the decompiler this seems to have gone away?
Status: NEW → RESOLVED
Closed: 14 years ago
Resolution: --- → WORKSFORME
You need to log in before you can comment on or make changes to this bug.