BaselineCompiler: Crash [@ JSObject::defaultValue]

RESOLVED FIXED

Status

()

defect
--
critical
RESOLVED FIXED
6 years ago
6 years ago

People

(Reporter: gkw, Assigned: jandem)

Tracking

(Blocks 2 bugs, {crash, regression, testcase})

Other Branch
x86
All
Points:
---
Dependency tree / graph

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: [jsbugmon:update], crash signature)

Attachments

(2 attachments)

(Reporter)

Description

6 years ago
Posted file stack
(function () {
    const x = [] = {};
    (function () {
        print(x)
    })()
})()

crashes js debug and opt shell on ionmonkey changeset 2445c6378f36 without any CLI arguments at JSObject::defaultValue
Whiteboard: [jsbugmon:update] → [jsbugmon:]
JSBugMon: Cannot process bug: Unable to automatically reproduce, please track manually.
(Reporter)

Comment 2

6 years ago
I tested this on 32-bit Linux.
OS: Mac OS X → Linux
Hardware: x86_64 → x86
Yep, confirmed. It doesn't reproduce on 64 bit that's why JSBugMon failed.
Whiteboard: [jsbugmon:] → [jsbugmon:update]
(Reporter)

Comment 4

6 years ago
Reproduces on 32-bit Mac.
OS: Linux → All
(Reporter)

Comment 5

6 years ago
autoBisect shows this is probably related to the following changeset:

The first bad revision is:
changeset:   121322:f21ddc17c570
user:        Brian Hackett
date:        Thu Feb 07 13:03:12 2013 -0700
summary:     Bug 839080 - Compile object initializer opcodes, r=djvj.

Brian, is bug 839080 a likely regressor?
Blocks: 839080
Crash Signature: [@ JSObject::defaultValue]
Flags: needinfo?(bhackett1024)
Keywords: regression
(Assignee)

Comment 6

6 years ago
Posted patch PatchSplinter Review
Between ops, values on top of the stack can be in R0 or R1 and SETALIASEDVAR shouldn't use these registers.
Assignee: general → jdemooij
Status: NEW → ASSIGNED
Attachment #716465 - Flags: review?(bhackett1024)
(Assignee)

Updated

6 years ago
Flags: needinfo?(bhackett1024)
Attachment #716465 - Flags: review?(bhackett1024) → review+
(Assignee)

Comment 7

6 years ago
https://hg.mozilla.org/projects/ionmonkey/rev/de894e57ecb2
Status: ASSIGNED → RESOLVED
Last Resolved: 6 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.