Closed
Bug 842970
Opened 11 years ago
Closed 11 years ago
Intermittent test_bug640321.html | application crashed [@ js::ion::CodeGenerator::emitArrayPush(js::ion::LInstruction*, js::ion::MArrayPush const*, js::ion::Register, js::ion::ConstantOrRegister, js::ion::Register, js::ion::Register)]
Categories
(Core :: JavaScript Engine, defect)
Tracking
()
RESOLVED
WORKSFORME
People
(Reporter: RyanVM, Unassigned)
Details
(Keywords: crash, intermittent-failure)
Crash Data
https://tbpl.mozilla.org/php/getParsedLog.php?id=19885732&tree=Mozilla-Inbound Android 4.0 Panda mozilla-inbound opt test mochitest-8 on 2013-02-19 12:50:17 PST for push a865bbcdc06d slave: panda-0648 5750 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | The height should be increased by -10pixels 5751 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | testResizer(0.5, 1, 0, 0, 0, 0) 5752 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | Sanity check the length 5753 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | Sanity check the height 5754 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | The width should be increased by 0 pixels 5755 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | The height should be increased by 0pixels 5756 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | testResizer(0.5, 1, 0, 10, 0, 10) 5757 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | Sanity check the length 5758 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | Sanity check the height INFO | automation.py | Application ran for: 0:01:24.810987 INFO | automation.py | Reading PID log: /tmp/tmpOFNMhTpidlog getting files in '/mnt/sdcard/tests/profile/minidumps/' Downloading symbols from: http://ftp.mozilla.org/pub/mozilla.org/mobile/tinderbox-builds/mozilla-inbound-android/1361302113/fennec-22.0a1.en-US.android-arm.crashreporter-symbols.zip PROCESS-CRASH | /tests/editor/libeditor/html/tests/test_bug640321.html | application crashed [@ js::ion::CodeGenerator::emitArrayPush(js::ion::LInstruction*, js::ion::MArrayPush const*, js::ion::Register, js::ion::ConstantOrRegister, js::ion::Register, js::ion::Register)] Crash dump filename: /tmp/tmprqdSpf/1a73f05f-5676-e826-062ea985-0c34d6b6.dmp Operating system: Android 0.0.0 Linux 3.2.0+ #2 SMP PREEMPT Thu Nov 29 08:06:57 EST 2012 armv7l pandaboard/pandaboard/pandaboard:4.0.4/IMM76I/5:eng/test-keys CPU: arm 0 CPUs Crash reason: SIGSEGV Crash address: 0x2 Thread 11 (crashed) 0 libxul.so!js::ion::CodeGenerator::emitArrayPush(js::ion::LInstruction*, js::ion::MArrayPush const*, js::ion::Register, js::ion::ConstantOrRegister, js::ion::Register, js::ion::Register) [LifoAlloc.h:a865bbcdc06d : 74 + 0x0] r4 = 0x00000002 r5 = 0x00000001 r6 = 0x5d5feb88 r7 = 0x6aebe3d0 r8 = 0x6d5f3180 r9 = 0x66ffeb80 r10 = 0x5d5fe850 fp = 0x00000008 sp = 0x5d5fe7f8 lr = 0x63e04de3 pc = 0x64005dee Found by: given as instruction pointer in context 1 libmozglue.so!arena_dalloc [jemalloc.c : 4590 + 0x7] sp = 0x5d5fe818 pc = 0x5bc5e8bb Found by: stack scanning 2 libxul.so!JSObject::getChildProperty(JSContext*, JS::Handle<JSObject*>, JS::Handle<js::Shape*>, js::StackShape&) [Shape.cpp:a865bbcdc06d : 368 + 0x9] sp = 0x5d5fe848 pc = 0x63e75529 Found by: stack scanning 3 libxul.so!JSObject::addPropertyInternal(JSContext*, JS::Handle<JSObject*>, JS::Handle<int>, int (*)(JSContext*, JS::Handle<JSObject*>, JS::Handle<int>, JS::MutableHandle<JS::Value>), int (*)(JSContext*, JS::Handle<JSObject*>, JS::Handle<int>, int, JS::MutableHandle<JS::Value>), unsigned int, unsigned int, unsigned int, int, js::Shape**, bool) [Shape.cpp:a865bbcdc06d : 538 + 0x3] sp = 0x5d5fe888 pc = 0x63e764bf Found by: stack scanning 4 libxul.so!JS_EnumerateStub(JSContext*, JS::Handle<JSObject*>) [jsapi.cpp:a865bbcdc06d : 3111 + 0x3] sp = 0x5d5fe89c pc = 0x63d917e9 Found by: stack scanning 5 libxul.so!JSObject::updateSlotsForSpan(JSContext*, JS::Handle<JSObject*>, unsigned int, unsigned int) [jsobj.cpp:a865bbcdc06d : 2303 + 0xb] sp = 0x5d5fe8d0 pc = 0x63e04c3b Found by: stack scanning 6 libmozglue.so!arena_malloc [jemalloc.c : 4170 + 0x9] sp = 0x5d5fe8d8 pc = 0x5bc5f42f Found by: stack scanning 7 libxul.so!JSObject::putProperty(JSContext*, JS::Handle<JSObject*>, JS::Handle<int>, int (*)(JSContext*, JS::Handle<JSObject*>, JS::Handle<int>, JS::MutableHandle<JS::Value>), int (*)(JSContext*, JS::Handle<JSObject*>, JS::Handle<int>, int, JS::MutableHandle<JS::Value>), unsigned int, unsigned int, unsigned int, int) [Shape.cpp:a865bbcdc06d : 611 + 0x25] sp = 0x5d5fe910 pc = 0x63e76f09 Found by: stack scanning 8 libxul.so!int js::baseops::LookupProperty<(js::AllowGC)1>(JSContext*, js::MaybeRooted<JSObject*, (js::AllowGC)1>::HandleType, js::MaybeRooted<int, (js::AllowGC)1>::HandleType, js::MaybeRooted<JSObject*, (js::AllowGC)1>::MutableHandleType, js::MaybeRooted<js::Shape*, (js::AllowGC)1>::MutableHandleType) [jsobj.cpp:a865bbcdc06d : 3474 + 0x5] sp = 0x5d5fe958 pc = 0x63e0335f Found by: stack scanning
Comment 1•11 years ago
|
||
Resolving WFM keyword:intermittent-failure bugs last modified >3 months ago, whose whiteboard contains none of: {random,disabled,marked,fuzzy,todo,fails,failing,annotated,time-bomb,leave open} There will inevitably be some false positives; for that (and the bugspam) I apologise. Filter on orangewfm.
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → WORKSFORME
You need to log in
before you can comment on or make changes to this bug.
Description
•