Status: Accepted
Owner: [email protected]
CC: [email protected], [email protected], [email protected], [email protected]
Labels: Type-Bug Priority-Medium

New issue 2949 by [email protected]: cctest/test-heap-profiler/TrackHeapAllocations crashes on V8 Linux - nosnap - debug
http://code.google.com/p/v8/issues/detail?id=2949

The test started crashing after r17301.

#0 0x083f5eb6 in v8::internal::HeapObject::map_word (this=0x175b81bd) at ../src/objects-inl.h:1225 #1 0x083f5e9a in v8::internal::HeapObject::map (this=0x175b81bd) at ../src/objects-inl.h:1204 #2 0x086a4bbc in v8::internal::GcSafeMapOfCodeSpaceObject (object=0xf72448c1) at ../src/frames.cc:1430 #3 0x086a4bdc in v8::internal::GcSafeSizeOfCodeSpaceObject (object=0xf72448c1) at ../src/frames.cc:1435 #4 0x086a4de4 in v8::internal::InnerPointerToCodeCache::GcSafeFindCodeForInnerPointer (this=0xa1cc398, inner_pointer=0xf7245e2c "\213u\374\211E\364hm\v\"<j") at ../src/frames.cc:1483 #5 0x086a4eee in v8::internal::InnerPointerToCodeCache::GetCacheEntry (this=0xa1cc398, inner_pointer=0xf7245e2c "\213u\374\211E\364hm\v\"<j") at ../src/frames.cc:1502 #6 0x083f8acc in v8::internal::StackFrame::GetContainingCode (isolate=0xa1c0f30,
    pc=0xf7245e2c "\213u\374\211E\364hm\v\"<j") at ../src/frames-inl.h:135
#7 0x086a1c8e in v8::internal::StackFrame::ComputeType (iterator=0xffffc2a8, state=0xffffc228) at ../src/frames.cc:456 #8 0x086a1d3c in v8::internal::StackFrame::GetCallerState (this=0xffffc2f4, state=0xffffc228) at ../src/frames.cc:473 #9 0x086a0cf7 in v8::internal::StackFrameIterator::Advance (this=0xffffc2a8) at ../src/frames.cc:110 #10 0x086a0fe2 in v8::internal::JavaScriptFrameIterator::Advance (this=0xffffc2a4) at ../src/frames.cc:177 #11 0x086a1108 in v8::internal::StackTraceFrameIterator::Advance (this=0xffffc2a4) at ../src/frames.cc:200 #12 0x085b2e00 in v8::internal::AllocationTracker::NewObjectEvent (this=0xa1ec2b8, addr=0xf72448c0 "\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027"..., size=704) at ../src/allocation-tracker.cc:183 #13 0x086c8689 in v8::internal::HeapSnapshotsCollection::NewObjectEvent (this=0xa1d8870, addr=0xf72448c0 "\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027"..., size=704) at ../src/heap-snapshot-generator.cc:832 #14 0x086c3ba7 in v8::internal::HeapProfiler::NewObjectEvent (this=0xa1d8850, addr=0xf72448c0 "\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027\274\201[\027"..., size=704) at ../src/heap-profiler.cc:143 #15 0x0852249b in v8::internal::PagedSpace::AllocateRaw (this=0xa1da740, size_in_bytes=704,
    event=v8::internal::PagedSpace::NEW_OBJECT) at ../src/spaces-inl.h:302
#16 0x086e9758 in v8::internal::Heap::CreateCode (this=0xa1c0f38, desc=..., flags=4294836224, self_reference=...,
    immovable=false, crankshafted=false) at ../src/heap.cc:4162
#17 0x08690934 in v8::internal::Factory::NewCode (this=0xa1c0f30, desc=..., flags=4294836224, self_ref=...,
    immovable=false, crankshafted=false) at ../src/factory.cc:1019
#18 0x08a1abe8 in v8::internal::CodeGenerator::MakeCodeEpilogue (masm=0xffffc5e4, flags=4294836224, info=0xffffc76c)
    at ../src/codegen.cc:116
#19 0x086a8c1b in v8::internal::FullCodeGenerator::MakeCode (info=0xffffc76c) at ../src/full-codegen.cc:338 #20 0x08637900 in v8::internal::GenerateCode (info=0xffffc76c) at ../src/compiler.cc:562 #21 0x0863797c in v8::internal::MakeCode (info=0xffffc76c) at ../src/compiler.cc:571 #22 0x086393f3 in v8::internal::Compiler::CompileLazy (info=0xffffc76c) at ../src/compiler.cc:1016 #23 0x08804b17 in v8::internal::CompileLazyHelper (info=0xffffc76c, flag=v8::internal::KEEP_EXCEPTION)
    at ../src/objects.cc:9522
#24 0x0880590e in v8::internal::JSFunction::CompileLazy (function=..., flag=v8::internal::KEEP_EXCEPTION)
    at ../src/objects.cc:9685
#25 0x08884566 in v8::internal::__RT_impl_Runtime_LazyCompile (args=..., isolate=0xa1c0f30) at ../src/runtime.cc:8331 #26 0x08884435 in v8::internal::Runtime_LazyCompile (args_length=1, args_object=0xffffc894, isolate=0xa1c0f30)
    at ../src/runtime.cc:8316
#27 0xf720a236 in ?? ()
#28 0xf72233fd in ?? ()
#29 0xf7223259 in ?? ()
#30 0xf720a0aa in ?? ()
#31 0x08678852 in v8::internal::Invoke (is_construct=false, function=..., receiver=..., argc=1, args=0xffffca4c,
    has_pending_exception=0xffffca2f) at ../src/execution.cc:119
#32 0x08678b9e in v8::internal::Execution::Call (isolate=0xa1c0f30, callable=..., receiver=..., argc=1, argv=0xffffca4c, pending_exception=0xffffca2f, convert_receiver=false) at ../src/execution.cc:183 #33 0x0861a28c in v8::internal::BinaryOpStub::Result (this=0xffffca74, left=..., right=..., isolate=0xa1c0f30)
    at ../src/code-stubs.cc:250
#34 0x08775208 in v8::internal::BinaryOpIC::Transition (this=0xffffcb64, left=..., right=...) at ../src/ic.cc:2295 #35 0x08775696 in v8::internal::__RT_impl_BinaryOpIC_Miss (args=..., isolate=0xa1c0f30) at ../src/ic.cc:2347 #36 0x087755c3 in v8::internal::BinaryOpIC_Miss (args_length=2, args_object=0xffffcbf0, isolate=0xa1c0f30)
    at ../src/ic.cc:2342
#37 0xf720a236 in ?? ()
#38 0xf721291c in ?? ()
#39 0xf7246021 in ?? ()
#40 0xf7245e2c in ?? ()
#41 0xf7223259 in ?? ()
#42 0xf720a0aa in ?? ()
#43 0x08678852 in v8::internal::Invoke (is_construct=false, function=..., receiver=..., argc=0, args=0x0,
    has_pending_exception=0xffffce0e) at ../src/execution.cc:119
#44 0x08678b9e in v8::internal::Execution::Call (isolate=0xa1c0f30, callable=..., receiver=..., argc=0, argv=0x0, pending_exception=0xffffce0e, convert_receiver=false) at ../src/execution.cc:183
#45 0x085c106d in v8::Script::Run (this=0xa1e7edc) at ../src/api.cc:1825
#46 0x085359d7 in CompileRun (
source=0x94ef880 "var topFunctions = [];\nvar global = this;\nfunction generateFunctions(width, depth) {\n var script = [];\n for (var i = 0; i < width; i++) {\n for (var j = 0; j < depth; j++) {\n script.push('fun"...)
    at ../test/cctest/cctest.h:308
#47 0x085411aa in TestTrackHeapAllocations () at ../test/cctest/test-heap-profiler.cc:2159 #48 0x083f6f76 in CcTest::Run (this=0xa1a95c0 <register_test_TrackHeapAllocations>) at ../test/cctest/cctest.cc:79 #49 0x083f7409 in main (argc=2, argv=0xffffcff4) at ../test/cctest/cctest.cc:167



--
You received this message because this project is configured to send all issue notifications to this address.
You may adjust your notification preferences at:
https://code.google.com/hosting/settings

--
--
v8-dev mailing list
[email protected]
http://groups.google.com/group/v8-dev
--- You received this message because you are subscribed to the Google Groups "v8-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/groups/opt_out.

Reply via email to