Closed Bug 842970 Opened 11 years ago Closed 11 years ago

Intermittent test_bug640321.html | application crashed [@ js::ion::CodeGenerator::emitArrayPush(js::ion::LInstruction*, js::ion::MArrayPush const*, js::ion::Register, js::ion::ConstantOrRegister, js::ion::Register, js::ion::Register)]

Categories

(Core :: JavaScript Engine, defect)

ARM
Android
defect
Not set
normal

Tracking

()

RESOLVED WORKSFORME

People

(Reporter: RyanVM, Unassigned)

Details

(Keywords: crash, intermittent-failure)

Crash Data

https://tbpl.mozilla.org/php/getParsedLog.php?id=19885732&tree=Mozilla-Inbound

Android 4.0 Panda mozilla-inbound opt test mochitest-8 on 2013-02-19 12:50:17 PST for push a865bbcdc06d
slave: panda-0648

5750 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | The height should be increased by -10pixels
5751 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | testResizer(0.5, 1, 0, 0, 0, 0)
5752 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | Sanity check the length
5753 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | Sanity check the height
5754 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | The width should be increased by 0 pixels
5755 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | The height should be increased by 0pixels
5756 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | testResizer(0.5, 1, 0, 10, 0, 10)
5757 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | Sanity check the length
5758 INFO TEST-PASS | /tests/editor/libeditor/html/tests/test_bug640321.html | Sanity check the height
INFO | automation.py | Application ran for: 0:01:24.810987
INFO | automation.py | Reading PID log: /tmp/tmpOFNMhTpidlog
getting files in '/mnt/sdcard/tests/profile/minidumps/'
Downloading symbols from: http://ftp.mozilla.org/pub/mozilla.org/mobile/tinderbox-builds/mozilla-inbound-android/1361302113/fennec-22.0a1.en-US.android-arm.crashreporter-symbols.zip
PROCESS-CRASH | /tests/editor/libeditor/html/tests/test_bug640321.html | application crashed [@ js::ion::CodeGenerator::emitArrayPush(js::ion::LInstruction*, js::ion::MArrayPush const*, js::ion::Register, js::ion::ConstantOrRegister, js::ion::Register, js::ion::Register)]
Crash dump filename: /tmp/tmprqdSpf/1a73f05f-5676-e826-062ea985-0c34d6b6.dmp
Operating system: Android
                  0.0.0 Linux 3.2.0+ #2 SMP PREEMPT Thu Nov 29 08:06:57 EST 2012 armv7l pandaboard/pandaboard/pandaboard:4.0.4/IMM76I/5:eng/test-keys
CPU: arm
     0 CPUs

Crash reason:  SIGSEGV
Crash address: 0x2

Thread 11 (crashed)
 0  libxul.so!js::ion::CodeGenerator::emitArrayPush(js::ion::LInstruction*, js::ion::MArrayPush const*, js::ion::Register, js::ion::ConstantOrRegister, js::ion::Register, js::ion::Register) [LifoAlloc.h:a865bbcdc06d : 74 + 0x0]
     r4 = 0x00000002    r5 = 0x00000001    r6 = 0x5d5feb88    r7 = 0x6aebe3d0
     r8 = 0x6d5f3180    r9 = 0x66ffeb80   r10 = 0x5d5fe850    fp = 0x00000008
     sp = 0x5d5fe7f8    lr = 0x63e04de3    pc = 0x64005dee
    Found by: given as instruction pointer in context
 1  libmozglue.so!arena_dalloc [jemalloc.c : 4590 + 0x7]
     sp = 0x5d5fe818    pc = 0x5bc5e8bb
    Found by: stack scanning
 2  libxul.so!JSObject::getChildProperty(JSContext*, JS::Handle<JSObject*>, JS::Handle<js::Shape*>, js::StackShape&) [Shape.cpp:a865bbcdc06d : 368 + 0x9]
     sp = 0x5d5fe848    pc = 0x63e75529
    Found by: stack scanning
 3  libxul.so!JSObject::addPropertyInternal(JSContext*, JS::Handle<JSObject*>, JS::Handle<int>, int (*)(JSContext*, JS::Handle<JSObject*>, JS::Handle<int>, JS::MutableHandle<JS::Value>), int (*)(JSContext*, JS::Handle<JSObject*>, JS::Handle<int>, int, JS::MutableHandle<JS::Value>), unsigned int, unsigned int, unsigned int, int, js::Shape**, bool) [Shape.cpp:a865bbcdc06d : 538 + 0x3]
     sp = 0x5d5fe888    pc = 0x63e764bf
    Found by: stack scanning
 4  libxul.so!JS_EnumerateStub(JSContext*, JS::Handle<JSObject*>) [jsapi.cpp:a865bbcdc06d : 3111 + 0x3]
     sp = 0x5d5fe89c    pc = 0x63d917e9
    Found by: stack scanning
 5  libxul.so!JSObject::updateSlotsForSpan(JSContext*, JS::Handle<JSObject*>, unsigned int, unsigned int) [jsobj.cpp:a865bbcdc06d : 2303 + 0xb]
     sp = 0x5d5fe8d0    pc = 0x63e04c3b
    Found by: stack scanning
 6  libmozglue.so!arena_malloc [jemalloc.c : 4170 + 0x9]
     sp = 0x5d5fe8d8    pc = 0x5bc5f42f
    Found by: stack scanning
 7  libxul.so!JSObject::putProperty(JSContext*, JS::Handle<JSObject*>, JS::Handle<int>, int (*)(JSContext*, JS::Handle<JSObject*>, JS::Handle<int>, JS::MutableHandle<JS::Value>), int (*)(JSContext*, JS::Handle<JSObject*>, JS::Handle<int>, int, JS::MutableHandle<JS::Value>), unsigned int, unsigned int, unsigned int, int) [Shape.cpp:a865bbcdc06d : 611 + 0x25]
     sp = 0x5d5fe910    pc = 0x63e76f09
    Found by: stack scanning
 8  libxul.so!int js::baseops::LookupProperty<(js::AllowGC)1>(JSContext*, js::MaybeRooted<JSObject*, (js::AllowGC)1>::HandleType, js::MaybeRooted<int, (js::AllowGC)1>::HandleType, js::MaybeRooted<JSObject*, (js::AllowGC)1>::MutableHandleType, js::MaybeRooted<js::Shape*, (js::AllowGC)1>::MutableHandleType) [jsobj.cpp:a865bbcdc06d : 3474 + 0x5]
     sp = 0x5d5fe958    pc = 0x63e0335f
    Found by: stack scanning
Resolving WFM keyword:intermittent-failure bugs last modified >3 months ago, whose whiteboard contains none of:
{random,disabled,marked,fuzzy,todo,fails,failing,annotated,time-bomb,leave open}

There will inevitably be some false positives; for that (and the bugspam) I apologise. Filter on orangewfm.
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → WORKSFORME
You need to log in before you can comment on or make changes to this bug.