Closed
Bug 808164
Opened 12 years ago
Closed 12 years ago
Crash [@ libxul.so!js::ion::AutoFlushCache::updateTop]
Categories
(Core :: JavaScript Engine, defect)
Tracking
()
RESOLVED
DUPLICATE
of bug 792873
People
(Reporter: rnewman, Unassigned)
Details
Crash Data
https://tbpl.mozilla.org/php/getParsedLog.php?id=16699800&tree=Firefox Android Tegra 250 mozilla-central opt test mochitest-2 [testfailed] using revision: mozilla-central/5a29e32cc48b PROCESS-CRASH | automation.py | application crashed (minidump found) Crash dump filename: /tmp/tmpM7DSCO/09e05b95-17c0-9ee6-5ab239ee-4024a8a6.dmp Operating system: Android 0.0.0 Linux 2.6.32.9-00002-gd8084dc-dirty #1 SMP PREEMPT Wed Feb 2 11:32:06 PST 2011 armv7l nvidia/harmony/harmony/harmony:2.2/FRF91/20110202.102810:eng/test-keys CPU: arm 0 CPUs Crash reason: SIGSEGV Crash address: 0x58 Thread 4 (crashed) 0 libxul.so!js::ion::AutoFlushCache::updateTop(unsigned int, unsigned int) [Ion.cpp : 1869 + 0xa] r4 = 0x00000004 r5 = 0x4e6af064 r6 = 0x4e81686c r7 = 0x599a2000 r8 = 0x55eda58c r9 = 0x55eda58c r10 = 0x55c8fcf4 fp = 0x4e8168c0 sp = 0x4e816818 lr = 0x44b5079b pc = 0x55951882 Found by: given as instruction pointer in context 1 libxul.so!js::ion::Assembler::patchWrite_NearCall(js::ion::CodeLocationLabel, js::ion::CodeLocationLabel) [Assembler-arm.cpp : 2277 + 0x3] r4 = 0x4e8168e8 r5 = 0x57ca5c00 r6 = 0x4e81686c r7 = 0x599a2000 r8 = 0x55eda58c r9 = 0x55eda58c r10 = 0x55c8fcf4 fp = 0x4e8168c0 sp = 0x4e816828 pc = 0x559b0aaf Found by: call frame info 2 libxul.so!js::ion::InvalidateAll(js::FreeOp*, JSCompartment*) [Ion.cpp : 1689 + 0x3] r4 = 0x4e8168e8 r5 = 0x57ca5c00 r6 = 0x4e81686c r7 = 0x599a2000 r8 = 0x55eda58c r9 = 0x55eda58c r10 = 0x55c8fcf4 fp = 0x4e8168c0 sp = 0x4e816830 pc = 0x559559dd Found by: call frame info 3 libxul.so!JSCompartment::sweep(js::FreeOp*, bool) [jscompartment.cpp : 501 + 0x7] r4 = 0x4e816bb8 r5 = 0x511311d8 r6 = 0x4e816ab0 r7 = 0x57ca5c00 r8 = 0x59105d80 r9 = 0x4e816bb8 r10 = 0xa4877198 fp = 0x00000001 sp = 0x4e816918 pc = 0x55790349 Found by: call frame info 4 libxul.so!IncrementalCollectSlice [jsgc.cpp : 3763 + 0x7] r4 = 0x51131000 r5 = 0x59105cf4 r6 = 0x4e816ab0 r7 = 0x0000003a r8 = 0x59105d80 r9 = 0x4e816bb8 r10 = 0xa4877198 fp = 0x0004cd82 sp = 0x4e816a58 pc = 0x557b9ab3 Found by: call frame info 5 libxul.so!GCCycle [jsgc.cpp : 4452 + 0x11] r4 = 0x51131000 r5 = 0x00504000 r6 = 0x00000000 r7 = 0x55c86228 r8 = 0x00000000 r9 = 0x00000000 r10 = 0x51131000 fp = 0x511311d8 sp = 0x4e816c20 pc = 0x557baff9 Found by: call frame info 6 libxul.so!js::GCSlice [jsgc.cpp : 4566 + 0xd] r4 = 0x51131000 r5 = 0x511311d8 r6 = 0x00000005 r7 = 0x00000000 r8 = 0x00000000 r9 = 0x00000000 r10 = 0x00002710 fp = 0x00000000 sp = 0x4e816c50 pc = 0x557bc25d Found by: call frame info 7 libxul.so!js_HandleExecutionInterrupt(JSContext*) [jscntxt.cpp : 1205 + 0x13] r4 = 0x581fba00 r5 = 0x51131000 r6 = 0xffffff87 r7 = 0x5787ff10 r8 = 0x558dd4a9 r9 = 0x57897280 r10 = 0x513009a8 fp = 0x00000000 sp = 0x4e816c80 pc = 0x5578b20b
Updated•12 years ago
|
Crash Signature: [@ js::ion::AutoFlushCache::updateTop(unsigned int, unsigned int)]
Updated•12 years ago
|
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → DUPLICATE
Updated•12 years ago
|
Whiteboard: [orange]
You need to log in
before you can comment on or make changes to this bug.
Description
•