Closed Bug 783278 Opened 7 years ago Closed 7 years ago

Intermittent crash in jsreftest.html?test=js1_8_5/regress/regress-383902.js [@ js::gc::MarkInternal<js::PropertyName>]

Categories

(Core :: JavaScript Engine, defect, critical)

x86_64
Linux
defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 783315

People

(Reporter: emorley, Unassigned)

References

Details

(Keywords: crash, intermittent-failure)

Crash Data

Rev3 Fedora 12x64 mozilla-central debug test jsreftest on 2012-08-16 06:52:43 PDT for push 3940df6f9356

slave: talos-r3-fed64-008

https://tbpl.mozilla.org/php/getParsedLog.php?id=14436563&tree=Firefox

{
REFTEST TEST-START | file:///home/cltbld/talos-slave/test/build/jsreftest/tests/jsreftest.html?test=js1_8_5/regress/regress-383902.js | 3086 / 3198 (96%)
++DOMWINDOW == 40 (0x3e77140) [serial = 5756] [outer = 0x3703670]
REFTEST TEST-PASS | file:///home/cltbld/talos-slave/test/build/jsreftest/tests/jsreftest.html?test=js1_8_5/regress/regress-383902.js | ok  item 1
REFTEST INFO | Loading a blank page
++DOMWINDOW == 41 (0x2639d930) [serial = 5757] [outer = 0x3703670]
TEST-UNEXPECTED-FAIL | file:///home/cltbld/talos-slave/test/build/jsreftest/tests/jsreftest.html?test=js1_8_5/regress/regress-383902.js | Exited with code 1 during test run
INFO | automation.py | Application ran for: 0:11:26.380208
INFO | automation.py | Reading PID log: /tmp/tmp6ucWLTpidlog
Downloading symbols from: http://ftp.mozilla.org/pub/mozilla.org/firefox/tinderbox-builds/mozilla-central-linux64-debug/1345122900/firefox-17.0a1.en-US.linux-x86_64.crashreporter-symbols.zip
PROCESS-CRASH | file:///home/cltbld/talos-slave/test/build/jsreftest/tests/jsreftest.html?test=js1_8_5/regress/regress-383902.js | application crashed (minidump found)
Crash dump filename: /tmp/tmpVdUFeq/minidumps/674acceb-0fdf-19f0-3eb284de-67d45e94.dmp
Operating system: Linux
                  0.0.0 Linux 2.6.31.5-127.fc12.x86_64 #1 SMP Sat Nov 7 21:11:14 EST 2009 x86_64
CPU: amd64
     family 6 model 23 stepping 10
     2 CPUs

Crash reason:  SIGSEGV
Crash address: 0x0

Thread 0 (crashed)
 0  libxul.so!js::gc::MarkInternal<js::PropertyName> [Heap.h : 1010 + 0x0]
    rbx = 0x024b23b8   r12 = 0xcdcdcdc8   r13 = 0x8efe1d18   r14 = 0x0257cbc0
    r15 = 0x8efe1d18   rip = 0x601f0da8   rsp = 0x8efe1cc0   rbp = 0x8efe1d00
    Found by: given as instruction pointer in context
 1  libxul.so!JSScript::markChildren [jsscript.cpp : 232 + 0x4]
    rbx = 0x21c54238   r12 = 0x024b23b8   r13 = 0x0257cbb8   r14 = 0x0257cbc0
    r15 = 0x8efe1d18   rip = 0x600da7d2   rsp = 0x8efe1d10   rbp = 0x8efe1d50
    Found by: call frame info
 2  libxul.so!js::gc::PushArenaTyped<JSScript> [Marking.cpp : 913 + 0x7]
    rbx = 0x8efe1d60   r12 = 0x024b23b8   r13 = 0x024b23b8   r14 = 0x8efe1fe0
    r15 = 0x024b24f0   rip = 0x601e83d0   rsp = 0x8efe1d60   rbp = 0x8efe1dc0
    Found by: call frame info
 3  libxul.so!js::GCMarker::markDelayedChildren [jsgc.cpp : 2059 + 0x4]
    rbx = 0x21c54000   r12 = 0x21c54000   r13 = 0x024b23b8   r14 = 0x8efe1fe0
    r15 = 0x024b24f0   rip = 0x600120ba   rsp = 0x8efe1dd0   rbp = 0x8efe1e60
    Found by: call frame info
 4  libxul.so!js::GCMarker::markDelayedChildren [jsgc.cpp : 2087 + 0x4]
    rbx = 0x21c54000   r12 = 0x024b23b8   r13 = 0x0000001c   r14 = 0x8efe1fe0
    r15 = 0x024b24f0   rip = 0x60012453   rsp = 0x8efe1e70   rbp = 0x8efe1ea0
    Found by: call frame info
 5  libxul.so!js::GCMarker::drainMarkStack [Marking.cpp : 1265 + 0xa]
    rbx = 0x024b23b8   r12 = 0x8efe1fe0   r13 = 0x024b2150   r14 = 0x00000000
    r15 = 0x8efe2070   rip = 0x601edda2   rsp = 0x8efe1eb0   rbp = 0x8efe1ed0
    Found by: call frame info
 6  libxul.so!IncrementalCollectSlice [jsgc.cpp : 3874 + 0xf]
    rbx = 0x024b2150   r12 = 0x00000000   r13 = 0x00000009   r14 = 0x00000000
    r15 = 0x8efe2070   rip = 0x60026258   rsp = 0x8efe1ee0   rbp = 0x8efe2050
    Found by: call frame info
 7  libxul.so!GCCycle [jsgc.cpp : 4131 + 0x10]
    rbx = 0x024b2150   r12 = 0x00000000   r13 = 0x00000009   r14 = 0x00000000
    r15 = 0x8efe2070   rip = 0x60027df7   rsp = 0x8efe2060   rbp = 0x8efe20b0
    Found by: call frame info
 8  libxul.so!Collect [jsgc.cpp : 4239 + 0xd]
    rbx = 0x024b2150   r12 = 0x00000009   r13 = 0x00000000   r14 = 0x024b24f0
    r15 = 0x00000000   rip = 0x600298fe   rsp = 0x8efe20c0   rbp = 0x8efe2100
    Found by: call frame info
 9  libxul.so!JS_TransplantObject [jsapi.cpp : 1625 + 0xd]
    rbx = 0x21c33080   r12 = 0x03703ac0   r13 = 0x21c33140   r14 = 0x21c69080
    r15 = 0x03703ac0   rip = 0x5ffba923   rsp = 0x8efe2110   rbp = 0x8efe2210
}
Blocks: 783315
This should be fixed by bug 783315.  Hopefully we can close this once the fix gets to m-c.
Feel free to reopen if this happens again.
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 783315
Whiteboard: [orange]
You need to log in before you can comment on or make changes to this bug.