[Webkit-unassigned] [Bug 159352] New: [GTK] Uninitialized memory use ConservativeRoots
bugzilla-daemon at webkit.org
bugzilla-daemon at webkit.org
Fri Jul 1 07:49:34 PDT 2016
https://bugs.webkit.org/show_bug.cgi?id=159352
Bug ID: 159352
Summary: [GTK] Uninitialized memory use ConservativeRoots
Classification: Unclassified
Product: WebKit
Version: Other
Hardware: PC
OS: Linux
Status: NEW
Severity: Normal
Priority: P2
Component: JavaScriptCore
Assignee: webkit-unassigned at lists.webkit.org
Reporter: mcatanzaro at igalia.com
I found this in a user's valgrind log:
==597== Conditional jump or move depends on uninitialised value(s)
==597== at 0x088268f5: _ZN3JSC17ConservativeRoots14genericAddSpanINS_17CompositeMarkHookEEEvPvS3_RT_ (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x0882604c: _ZN3JSC17ConservativeRoots3addEPvS1_RNS_17JITStubRoutineSetERNS_12CodeBlockSetE (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x0884a3f9: _ZN3JSC14MachineThreads23gatherConservativeRootsERNS_17ConservativeRootsERNS_17JITStubRoutineSetERNS_12CodeBlockSetEPvS7_RA1_13__jmp_buf_tag (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x0882b2d0: _ZN3JSC4Heap16gatherStackRootsERNS_17ConservativeRootsEPvS3_RA1_13__jmp_buf_tag (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x088420b2: _ZN3JSC4Heap9markRootsEdPvS1_RA1_13__jmp_buf_tag (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x088450d5: _ZN3JSC4Heap11collectImplENS_13HeapOperationEPvS2_RA1_13__jmp_buf_tag (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x08845387: _ZN3JSC4Heap7collectENS_13HeapOperationE (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x08829559: _ZN3JSC18GCActivityCallback6doWorkEv (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x088470e1: _ZN3JSC9HeapTimer12timerDidFireEv (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x08847118: ??? (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x0bbcbc89: g_main_context_dispatch (in /usr/lib/libglib-2.0.so.0.4800.1)
==597== by 0x0bbcc03f: ??? (in /usr/lib/libglib-2.0.so.0.4800.1)
==597==
==597== Use of uninitialised value of size 8
==597== at 0x08826ac6: _ZN3JSC17ConservativeRoots14genericAddSpanINS_17CompositeMarkHookEEEvPvS3_RT_ (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x0882604c: _ZN3JSC17ConservativeRoots3addEPvS1_RNS_17JITStubRoutineSetERNS_12CodeBlockSetE (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x0884a3f9: _ZN3JSC14MachineThreads23gatherConservativeRootsERNS_17ConservativeRootsERNS_17JITStubRoutineSetERNS_12CodeBlockSetEPvS7_RA1_13__jmp_buf_tag (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x0882b2d0: _ZN3JSC4Heap16gatherStackRootsERNS_17ConservativeRootsEPvS3_RA1_13__jmp_buf_tag (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x088420b2: _ZN3JSC4Heap9markRootsEdPvS1_RA1_13__jmp_buf_tag (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x088450d5: _ZN3JSC4Heap11collectImplENS_13HeapOperationEPvS2_RA1_13__jmp_buf_tag (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x08845387: _ZN3JSC4Heap7collectENS_13HeapOperationE (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x08829559: _ZN3JSC18GCActivityCallback6doWorkEv (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x088470e1: _ZN3JSC9HeapTimer12timerDidFireEv (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x08847118: ??? (in /usr/lib/libjavascriptcoregtk-4.0.so.18.3.11)
==597== by 0x0bbcbc89: g_main_context_dispatch (in /usr/lib/libglib-2.0.so.0.4800.1)
==597== by 0x0bbcc03f: ??? (in /usr/lib/libglib-2.0.so.0.4800.1)
--
You are receiving this mail because:
You are the assignee for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.webkit.org/pipermail/webkit-unassigned/attachments/20160701/ce436168/attachment.html>
More information about the webkit-unassigned
mailing list