Closed Bug 808164 Opened 12 years ago Closed 12 years ago

Crash [@ libxul.so!js::ion::AutoFlushCache::updateTop]

Categories

(Core :: JavaScript Engine, defect)

ARM
Android
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 792873

People

(Reporter: rnewman, Unassigned)

Details

Crash Data

https://tbpl.mozilla.org/php/getParsedLog.php?id=16699800&tree=Firefox

Android Tegra 250 mozilla-central opt test mochitest-2 [testfailed]
using revision: mozilla-central/5a29e32cc48b

PROCESS-CRASH | automation.py | application crashed (minidump found)
Crash dump filename: /tmp/tmpM7DSCO/09e05b95-17c0-9ee6-5ab239ee-4024a8a6.dmp
Operating system: Android
                  0.0.0 Linux 2.6.32.9-00002-gd8084dc-dirty #1 SMP PREEMPT Wed Feb 2 11:32:06 PST 2011 armv7l nvidia/harmony/harmony/harmony:2.2/FRF91/20110202.102810:eng/test-keys
CPU: arm
     0 CPUs

Crash reason:  SIGSEGV
Crash address: 0x58

Thread 4 (crashed)
 0  libxul.so!js::ion::AutoFlushCache::updateTop(unsigned int, unsigned int) [Ion.cpp : 1869 + 0xa]
     r4 = 0x00000004    r5 = 0x4e6af064    r6 = 0x4e81686c    r7 = 0x599a2000
     r8 = 0x55eda58c    r9 = 0x55eda58c   r10 = 0x55c8fcf4    fp = 0x4e8168c0
     sp = 0x4e816818    lr = 0x44b5079b    pc = 0x55951882
    Found by: given as instruction pointer in context
 1  libxul.so!js::ion::Assembler::patchWrite_NearCall(js::ion::CodeLocationLabel, js::ion::CodeLocationLabel) [Assembler-arm.cpp : 2277 + 0x3]
     r4 = 0x4e8168e8    r5 = 0x57ca5c00    r6 = 0x4e81686c    r7 = 0x599a2000
     r8 = 0x55eda58c    r9 = 0x55eda58c   r10 = 0x55c8fcf4    fp = 0x4e8168c0
     sp = 0x4e816828    pc = 0x559b0aaf
    Found by: call frame info
 2  libxul.so!js::ion::InvalidateAll(js::FreeOp*, JSCompartment*) [Ion.cpp : 1689 + 0x3]
     r4 = 0x4e8168e8    r5 = 0x57ca5c00    r6 = 0x4e81686c    r7 = 0x599a2000
     r8 = 0x55eda58c    r9 = 0x55eda58c   r10 = 0x55c8fcf4    fp = 0x4e8168c0
     sp = 0x4e816830    pc = 0x559559dd
    Found by: call frame info
 3  libxul.so!JSCompartment::sweep(js::FreeOp*, bool) [jscompartment.cpp : 501 + 0x7]
     r4 = 0x4e816bb8    r5 = 0x511311d8    r6 = 0x4e816ab0    r7 = 0x57ca5c00
     r8 = 0x59105d80    r9 = 0x4e816bb8   r10 = 0xa4877198    fp = 0x00000001
     sp = 0x4e816918    pc = 0x55790349
    Found by: call frame info
 4  libxul.so!IncrementalCollectSlice [jsgc.cpp : 3763 + 0x7]
     r4 = 0x51131000    r5 = 0x59105cf4    r6 = 0x4e816ab0    r7 = 0x0000003a
     r8 = 0x59105d80    r9 = 0x4e816bb8   r10 = 0xa4877198    fp = 0x0004cd82
     sp = 0x4e816a58    pc = 0x557b9ab3
    Found by: call frame info
 5  libxul.so!GCCycle [jsgc.cpp : 4452 + 0x11]
     r4 = 0x51131000    r5 = 0x00504000    r6 = 0x00000000    r7 = 0x55c86228
     r8 = 0x00000000    r9 = 0x00000000   r10 = 0x51131000    fp = 0x511311d8
     sp = 0x4e816c20    pc = 0x557baff9
    Found by: call frame info
 6  libxul.so!js::GCSlice [jsgc.cpp : 4566 + 0xd]
     r4 = 0x51131000    r5 = 0x511311d8    r6 = 0x00000005    r7 = 0x00000000
     r8 = 0x00000000    r9 = 0x00000000   r10 = 0x00002710    fp = 0x00000000
     sp = 0x4e816c50    pc = 0x557bc25d
    Found by: call frame info
 7  libxul.so!js_HandleExecutionInterrupt(JSContext*) [jscntxt.cpp : 1205 + 0x13]
     r4 = 0x581fba00    r5 = 0x51131000    r6 = 0xffffff87    r7 = 0x5787ff10
     r8 = 0x558dd4a9    r9 = 0x57897280   r10 = 0x513009a8    fp = 0x00000000
     sp = 0x4e816c80    pc = 0x5578b20b
Crash Signature: [@ js::ion::AutoFlushCache::updateTop(unsigned int, unsigned int)]
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → DUPLICATE
Whiteboard: [orange]
You need to log in before you can comment on or make changes to this bug.