Closed Bug 836938 Opened 11 years ago Closed 6 years ago

crash in js::Vector::growStorageBy

Categories

(Core :: Gecko Profiler, defect)

x86_64
Linux
defect
Not set
critical

Tracking

()

RESOLVED WONTFIX

People

(Reporter: azakai, Unassigned)

References

(Blocks 1 open bug)

Details

(Keywords: crash)

Crash Data

This bug was filed from the Socorro interface and is 
report bp-5d722e08-0aa1-4151-a1cd-fbdff2130131 .
============================================================= 

happened when profiling a very JS-heavy demo
Hardware: All → x86_64
Summary: crash in js::Vector → crash in js::Vector::growStorageBy
Version: unspecified → Trunk
Crash Signature: [@ js::Vector<unsigned short, 32ul, js::ContextAllocPolicy>::growStorageBy(unsigned long)] → [@ js::Vector<unsigned short, 32ul, js::ContextAllocPolicy>::growStorageBy(unsigned long)] [@ js::Vector<unsigned short, int, js::ContextAllocPolicy>::growStorageBy(unsigned int)]
Seeing this on another demo now too (can't share source).
It's likely a duplicate of bug 832812.
Visiting http://productforums.google.com/d/topic/chat/5bE-mrVrP3A on the 2/10 nightly gives me a completely reproducible crash as the page loads.
Crash Signature: [@ js::Vector<unsigned short, 32ul, js::ContextAllocPolicy>::growStorageBy(unsigned long)] [@ js::Vector<unsigned short, int, js::ContextAllocPolicy>::growStorageBy(unsigned int)] → [@ js::Vector<unsigned short, 32ul, js::ContextAllocPolicy>::growStorageBy(unsigned long)] [@ js::Vector<unsigned short, int, js::ContextAllocPolicy>::growStorageBy(unsigned int)] [@ js::Vector<T>::growStorageBy]
Blocks: 1329181
Closing because no crash reported since 12 weeks.
Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.