Closed Bug 45510 Opened 26 years ago Closed 26 years ago

Crash during drag when tooltip tries to pop up [@ PresShell::HandlePostedDOMEvents]

Categories

(Core :: Layout, defect, P3)

x86
Windows NT
defect

Tracking

()

VERIFIED FIXED

People

(Reporter: roc, Assigned: attinasi)

References

Details

(Keywords: crash, topcrash, Whiteboard: [nsbeta2+] FIX IN HAND)

Crash Data

Attachments

(2 files)

Dragging a link from one window to another, Mozilla crashes with the following stack trace: PresShell::HandlePostedDOMEvents() line 3186 + 37 bytes PresShell::ProcessReflowCommands(int 0) line 4200 PresShell::FlushPendingNotifications(PresShell * const 0x0350b6f0) line 3224 PresShell::AppendReflowCommand(PresShell * const 0x0350b6f0, nsIReflowCommand * 0x043bb800) line 2449 nsFrame::CreateAndPostReflowCommand(nsIPresShell * 0x0350b6f0, nsIFrame * 0x01f08e4c, nsIReflowCommand::ReflowType ReflowDirty, nsIFrame * 0x00000000, nsIAtom * 0x00000000, nsIAtom * 0x00000000) line 3370 nsContainerFrame::ReflowDirtyChild(nsContainerFrame * const 0x01f08e10, nsIPresShell * 0x0350b6f0, nsIFrame * 0x01f08e4c) line 313 + 21 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x01f08e84, nsBoxLayoutState & {...}, nsIBox * 0x01f08f14) line 460 + 28 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x01f08f14, nsBoxLayoutState & {...}, nsIBox * 0x01f09164) line 454 + 23 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x01f09164, nsBoxLayoutState & {...}, nsIBox * 0x01f09164) line 454 + 23 bytes nsBoxFrame::ReflowDirtyChild(nsBoxFrame * const 0x01f0912c, nsIPresShell * 0x0350b6f0, nsIFrame * 0x038f73e4) line 645 + 51 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x038f741c, nsBoxLayoutState & {...}, nsIBox * 0x038f74e0) line 460 + 28 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x038f74e0, nsBoxLayoutState & {...}, nsIBox * 0x038f75f8) line 454 + 23 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x038f75f8, nsBoxLayoutState & {...}, nsIBox * 0x038f7988) line 454 + 23 bytes nsBox::MarkStyleChange(nsBox * const 0x038f7988, nsBoxLayoutState & {...}) line 313 + 23 bytes nsCSSFrameConstructor::StyleChangeReflow(nsIPresContext * 0x0350a210, nsIFrame * 0x038f7950, nsIAtom * 0x00000000) line 9718 nsCSSFrameConstructor::ProcessRestyledFrames(nsCSSFrameConstructor * const 0x0350ba50, nsStyleChangeList & {...}, nsIPresContext * 0x0350a210) line 9848 nsCSSFrameConstructor::AttributeChanged(nsCSSFrameConstructor * const 0x0350ba50, nsIPresContext * 0x0350a210, nsIContent * 0x0424bc50, int 0, nsIAtom * 0x0153ad50, int 2) line 10161 StyleSetImpl::AttributeChanged(StyleSetImpl * const 0x0350bb10, nsIPresContext * 0x0350a210, nsIContent * 0x0424bc50, int 0, nsIAtom * 0x0153ad50, int -1) line 1143 PresShell::AttributeChanged(PresShell * const 0x0350b6f8, nsIDocument * 0x03509df0, nsIContent * 0x0424bc50, int 0, nsIAtom * 0x0153ad50, int -1) line 3295 + 57 bytes nsXULDocument::AttributeChanged(nsXULDocument * const 0x03509df0, nsIContent * 0x0424bc50, int 0, nsIAtom * 0x0153ad50, int -1) line 1674 nsXULElement::SetAttribute(nsXULElement * const 0x0424bc50, int 0, nsIAtom * 0x0153ad50, const nsString & {...}, int 1) line 2855 nsXULElement::SetAttribute(nsXULElement * const 0x0424bc5c, const nsString & {...}, const nsString & {...}) line 1242 + 35 bytes ElementSetAttribute(JSContext * 0x02fefde0, JSObject * 0x039a4ae0, unsigned int 2, long * 0x01edef0c, long * 0x001265d8) line 239 + 26 bytes js_Invoke(JSContext * 0x02fefde0, unsigned int 2, unsigned int 0) line 716 + 23 bytes js_Interpret(JSContext * 0x02fefde0, long * 0x00126f14) line 2520 + 15 bytes js_Invoke(JSContext * 0x02fefde0, unsigned int 1, unsigned int 2) line 732 + 13 bytes js_InternalInvoke(JSContext * 0x02fefde0, JSObject * 0x039a4ab0, long 60443424, unsigned int 0, unsigned int 1, long * 0x001270a8, long * 0x00127038) line 805 + 19 bytes JS_CallFunctionValue(JSContext * 0x02fefde0, JSObject * 0x039a4ab0, long 60443424, unsigned int 1, long * 0x001270a8, long * 0x00127038) line 2815 + 31 bytes nsJSContext::CallEventHandler(nsJSContext * const 0x02fee2f0, void * 0x039a4ab0, void * 0x039a4b20, unsigned int 1, void * 0x001270a8, int * 0x001270a4, int 0) line 847 + 33 bytes nsJSEventListener::HandleEvent(nsIDOMEvent * 0x043c4cd4) line 154 + 64 bytes nsEventListenerManager::HandleEventSubType(nsListenerStruct * 0x0424b0d0, nsIDOMEvent * 0x043c4cd4, nsIDOMEventTarget * 0x0424bd40, unsigned int 2, unsigned int 2) line 772 + 19 bytes nsEventListenerManager::HandleEvent(nsIPresContext * 0x0350a210, nsEvent * 0x043c2e40, nsIDOMEvent * * 0x001278f8, nsIDOMEventTarget * 0x0424bd40, unsigned int 2, nsEventStatus * 0x00127928) line 1551 + 39 bytes nsXULElement::HandleDOMEvent(nsXULElement * const 0x0424bd30, nsIPresContext * 0x0350a210, nsEvent * 0x043c2e40, nsIDOMEvent * * 0x001278f8, unsigned int 2, nsEventStatus * 0x00127928) line 3350 nsXULElement::HandleDOMEvent(nsXULElement * const 0x0424b690, nsIPresContext * 0x0350a210, nsEvent * 0x043c2e40, nsIDOMEvent * * 0x001278f8, unsigned int 1, nsEventStatus * 0x00127928) line 3373 + 39 bytes PresShell::HandlePostedDOMEvents() line 3187 PresShell::ProcessReflowCommands(int 0) line 4200 PresShell::FlushPendingNotifications(PresShell * const 0x0350b6f0) line 3224 PresShell::AppendReflowCommand(PresShell * const 0x0350b6f0, nsIReflowCommand * 0x043c4c70) line 2449 nsFrame::CreateAndPostReflowCommand(nsIPresShell * 0x0350b6f0, nsIFrame * 0x01f08e4c, nsIReflowCommand::ReflowType ReflowDirty, nsIFrame * 0x00000000, nsIAtom * 0x00000000, nsIAtom * 0x00000000) line 3370 nsContainerFrame::ReflowDirtyChild(nsContainerFrame * const 0x01f08e10, nsIPresShell * 0x0350b6f0, nsIFrame * 0x01f08e4c) line 313 + 21 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x01f08e84, nsBoxLayoutState & {...}, nsIBox * 0x01f08f14) line 460 + 28 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x01f08f14, nsBoxLayoutState & {...}, nsIBox * 0x01f09164) line 454 + 23 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x01f09164, nsBoxLayoutState & {...}, nsIBox * 0x01f09164) line 454 + 23 bytes nsBoxFrame::ReflowDirtyChild(nsBoxFrame * const 0x01f0912c, nsIPresShell * 0x0350b6f0, nsIFrame * 0x038f73e4) line 645 + 51 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x038f741c, nsBoxLayoutState & {...}, nsIBox * 0x038f74e0) line 460 + 28 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x038f74e0, nsBoxLayoutState & {...}, nsIBox * 0x038f75f8) line 454 + 23 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x038f75f8, nsBoxLayoutState & {...}, nsIBox * 0x038f7718) line 454 + 23 bytes nsBox::MarkStyleChange(nsBox * const 0x038f7718, nsBoxLayoutState & {...}) line 313 + 23 bytes nsCSSFrameConstructor::StyleChangeReflow(nsIPresContext * 0x0350a210, nsIFrame * 0x038f76e0, nsIAtom * 0x00000000) line 9718 nsCSSFrameConstructor::ProcessRestyledFrames(nsCSSFrameConstructor * const 0x0350ba50, nsStyleChangeList & {...}, nsIPresContext * 0x0350a210) line 9848 nsCSSFrameConstructor::AttributeChanged(nsCSSFrameConstructor * const 0x0350ba50, nsIPresContext * 0x0350a210, nsIContent * 0x0424b300, int 0, nsIAtom * 0x0153ad50, int 2) line 10161 StyleSetImpl::AttributeChanged(StyleSetImpl * const 0x0350bb10, nsIPresContext * 0x0350a210, nsIContent * 0x0424b300, int 0, nsIAtom * 0x0153ad50, int -1) line 1143 PresShell::AttributeChanged(PresShell * const 0x0350b6f8, nsIDocument * 0x03509df0, nsIContent * 0x0424b300, int 0, nsIAtom * 0x0153ad50, int -1) line 3295 + 57 bytes nsXULDocument::AttributeChanged(nsXULDocument * const 0x03509df0, nsIContent * 0x0424b300, int 0, nsIAtom * 0x0153ad50, int -1) line 1674 nsXULElement::UnsetAttribute(nsXULElement * const 0x0424b300, int 0, nsIAtom * 0x0153ad50, int 1) line 3081 nsXULElement::RemoveAttribute(nsXULElement * const 0x0424b30c, const nsString & {...}) line 1273 + 31 bytes ElementRemoveAttribute(JSContext * 0x02fefde0, JSObject * 0x039a4af0, unsigned int 1, long * 0x01edeedc, long * 0x00128614) line 280 + 19 bytes js_Invoke(JSContext * 0x02fefde0, unsigned int 1, unsigned int 0) line 716 + 23 bytes js_Interpret(JSContext * 0x02fefde0, long * 0x00128f50) line 2520 + 15 bytes js_Invoke(JSContext * 0x02fefde0, unsigned int 1, unsigned int 2) line 732 + 13 bytes js_InternalInvoke(JSContext * 0x02fefde0, JSObject * 0x039a4ab0, long 60443328, unsigned int 0, unsigned int 1, long * 0x001290e4, long * 0x00129074) line 805 + 19 bytes JS_CallFunctionValue(JSContext * 0x02fefde0, JSObject * 0x039a4ab0, long 60443328, unsigned int 1, long * 0x001290e4, long * 0x00129074) line 2815 + 31 bytes nsJSContext::CallEventHandler(nsJSContext * const 0x02fee2f0, void * 0x039a4ab0, void * 0x039a4ac0, unsigned int 1, void * 0x001290e4, int * 0x001290e0, int 0) line 847 + 33 bytes nsJSEventListener::HandleEvent(nsIDOMEvent * 0x043c3be4) line 154 + 64 bytes nsEventListenerManager::HandleEventSubType(nsListenerStruct * 0x0424b0d0, nsIDOMEvent * 0x043c3be4, nsIDOMEventTarget * 0x0424bd40, unsigned int 1, unsigned int 2) line 772 + 19 bytes nsEventListenerManager::HandleEvent(nsIPresContext * 0x0350a210, nsEvent * 0x043c4cd0, nsIDOMEvent * * 0x00129934, nsIDOMEventTarget * 0x0424bd40, unsigned int 2, nsEventStatus * 0x00129964) line 1551 + 39 bytes nsXULElement::HandleDOMEvent(nsXULElement * const 0x0424bd30, nsIPresContext * 0x0350a210, nsEvent * 0x043c4cd0, nsIDOMEvent * * 0x00129934, unsigned int 2, nsEventStatus * 0x00129964) line 3350 nsXULElement::HandleDOMEvent(nsXULElement * const 0x0424b690, nsIPresContext * 0x0350a210, nsEvent * 0x043c4cd0, nsIDOMEvent * * 0x00129934, unsigned int 1, nsEventStatus * 0x00129964) line 3373 + 39 bytes PresShell::HandlePostedDOMEvents() line 3187 PresShell::ProcessReflowCommands(int 0) line 4200 PresShell::FlushPendingNotifications(PresShell * const 0x0350b6f0) line 3224 PresShell::AppendReflowCommand(PresShell * const 0x0350b6f0, nsIReflowCommand * 0x043c3c50) line 2449 nsFrame::CreateAndPostReflowCommand(nsIPresShell * 0x0350b6f0, nsIFrame * 0x01f08e4c, nsIReflowCommand::ReflowType ReflowDirty, nsIFrame * 0x00000000, nsIAtom * 0x00000000, nsIAtom * 0x00000000) line 3370 nsContainerFrame::ReflowDirtyChild(nsContainerFrame * const 0x01f08e10, nsIPresShell * 0x0350b6f0, nsIFrame * 0x01f08e4c) line 313 + 21 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x01f08e84, nsBoxLayoutState & {...}, nsIBox * 0x01f08f14) line 460 + 28 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x01f08f14, nsBoxLayoutState & {...}, nsIBox * 0x01f09164) line 454 + 23 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x01f09164, nsBoxLayoutState & {...}, nsIBox * 0x01f09164) line 454 + 23 bytes nsBoxFrame::ReflowDirtyChild(nsBoxFrame * const 0x01f0912c, nsIPresShell * 0x0350b6f0, nsIFrame * 0x038f73e4) line 645 + 51 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x038f741c, nsBoxLayoutState & {...}, nsIBox * 0x038f74e0) line 460 + 28 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x038f74e0, nsBoxLayoutState & {...}, nsIBox * 0x038f75f8) line 454 + 23 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x038f75f8, nsBoxLayoutState & {...}, nsIBox * 0x038f7988) line 454 + 23 bytes nsBox::MarkStyleChange(nsBox * const 0x038f7988, nsBoxLayoutState & {...}) line 313 + 23 bytes nsCSSFrameConstructor::StyleChangeReflow(nsIPresContext * 0x0350a210, nsIFrame * 0x038f7950, nsIAtom * 0x00000000) line 9718 nsCSSFrameConstructor::ProcessRestyledFrames(nsCSSFrameConstructor * const 0x0350ba50, nsStyleChangeList & {...}, nsIPresContext * 0x0350a210) line 9848 nsCSSFrameConstructor::AttributeChanged(nsCSSFrameConstructor * const 0x0350ba50, nsIPresContext * 0x0350a210, nsIContent * 0x0424bc50, int 0, nsIAtom * 0x0153ad50, int 2) line 10161 StyleSetImpl::AttributeChanged(StyleSetImpl * const 0x0350bb10, nsIPresContext * 0x0350a210, nsIContent * 0x0424bc50, int 0, nsIAtom * 0x0153ad50, int -1) line 1143 PresShell::AttributeChanged(PresShell * const 0x0350b6f8, nsIDocument * 0x03509df0, nsIContent * 0x0424bc50, int 0, nsIAtom * 0x0153ad50, int -1) line 3295 + 57 bytes nsXULDocument::AttributeChanged(nsXULDocument * const 0x03509df0, nsIContent * 0x0424bc50, int 0, nsIAtom * 0x0153ad50, int -1) line 1674 nsXULElement::UnsetAttribute(nsXULElement * const 0x0424bc50, int 0, nsIAtom * 0x0153ad50, int 1) line 3081 nsXULElement::RemoveAttribute(nsXULElement * const 0x0424bc5c, const nsString & {...}) line 1273 + 31 bytes ElementRemoveAttribute(JSContext * 0x02fefde0, JSObject * 0x039a4ae0, unsigned int 1, long * 0x01edeeb0, long * 0x0012a650) line 280 + 19 bytes js_Invoke(JSContext * 0x02fefde0, unsigned int 1, unsigned int 0) line 716 + 23 bytes js_Interpret(JSContext * 0x02fefde0, long * 0x0012af8c) line 2520 + 15 bytes js_Invoke(JSContext * 0x02fefde0, unsigned int 1, unsigned int 2) line 732 + 13 bytes js_InternalInvoke(JSContext * 0x02fefde0, JSObject * 0x039a4ab0, long 60443328, unsigned int 0, unsigned int 1, long * 0x0012b120, long * 0x0012b0b0) line 805 + 19 bytes JS_CallFunctionValue(JSContext * 0x02fefde0, JSObject * 0x039a4ab0, long 60443328, unsigned int 1, long * 0x0012b120, long * 0x0012b0b0) line 2815 + 31 bytes nsJSContext::CallEventHandler(nsJSContext * const 0x02fee2f0, void * 0x039a4ab0, void * 0x039a4ac0, unsigned int 1, void * 0x0012b120, int * 0x0012b11c, int 0) line 847 + 33 bytes nsJSEventListener::HandleEvent(nsIDOMEvent * 0x043c32e4) line 154 + 64 bytes nsEventListenerManager::HandleEventSubType(nsListenerStruct * 0x0424b0d0, nsIDOMEvent * 0x043c32e4, nsIDOMEventTarget * 0x0424bd40, unsigned int 1, unsigned int 2) line 772 + 19 bytes nsEventListenerManager::HandleEvent(nsIPresContext * 0x0350a210, nsEvent * 0x043c4cd0, nsIDOMEvent * * 0x0012b970, nsIDOMEventTarget * 0x0424bd40, unsigned int 2, nsEventStatus * 0x0012b9a0) line 1551 + 39 bytes nsXULElement::HandleDOMEvent(nsXULElement * const 0x0424bd30, nsIPresContext * 0x0350a210, nsEvent * 0x043c4cd0, nsIDOMEvent * * 0x0012b970, unsigned int 2, nsEventStatus * 0x0012b9a0) line 3350 nsXULElement::HandleDOMEvent(nsXULElement * const 0x0424b690, nsIPresContext * 0x0350a210, nsEvent * 0x043c4cd0, nsIDOMEvent * * 0x0012b970, unsigned int 1, nsEventStatus * 0x0012b9a0) line 3373 + 39 bytes PresShell::HandlePostedDOMEvents() line 3187 PresShell::ProcessReflowCommands(int 0) line 4200 PresShell::FlushPendingNotifications(PresShell * const 0x0350b6f0) line 3224 PresShell::AppendReflowCommand(PresShell * const 0x0350b6f0, nsIReflowCommand * 0x043c5a30) line 2449 nsFrame::CreateAndPostReflowCommand(nsIPresShell * 0x0350b6f0, nsIFrame * 0x01f08e4c, nsIReflowCommand::ReflowType ReflowDirty, nsIFrame * 0x00000000, nsIAtom * 0x00000000, nsIAtom * 0x00000000) line 3370 nsContainerFrame::ReflowDirtyChild(nsContainerFrame * const 0x01f08e10, nsIPresShell * 0x0350b6f0, nsIFrame * 0x01f08e4c) line 313 + 21 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x01f08e84, nsBoxLayoutState & {...}, nsIBox * 0x01f08f14) line 460 + 28 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x01f08f14, nsBoxLayoutState & {...}, nsIBox * 0x01f09164) line 454 + 23 bytes nsBox::RelayoutDirtyChild(nsBox * const 0x01f09164, nsBoxLayoutState & {...}, nsIBox * 0x00000000) line 454 + 23 bytes nsBox::MarkDirtyChildren(nsBox * const 0x01f09164, nsBoxLayoutState & {...}) line 292 nsPopupSetFrame::AppendFrames(nsPopupSetFrame * const 0x01f0912c, nsIPresContext * 0x0350a210, nsIPresShell & {...}, nsIAtom * 0x00000000, nsIFrame * 0x038f73e4) line 421 + 20 bytes FrameManager::AppendFrames(FrameManager * const 0x0350cdc0, nsIPresContext * 0x0350a210, nsIPresShell & {...}, nsIFrame * 0x01f0912c, nsIAtom * 0x00000000, nsIFrame * 0x038f73e4) line 684 nsCSSFrameConstructor::AppendFrames(nsIPresContext * 0x0350a210, nsIPresShell * 0x0350b6f0, nsIFrameManager * 0x0350cdc0, nsIContent * 0x036aa650, nsIFrame * 0x01f0912c, nsIFrame * 0x038f73e4) line 8120 + 30 bytes nsCSSFrameConstructor::ContentInserted(nsCSSFrameConstructor * const 0x0350ba50, nsIPresContext * 0x0350a210, nsIContent * 0x036aa650, nsIContent * 0x036aa540, int 0, nsILayoutHistoryState * 0x03cd6af0) line 8907 + 51 bytes nsCSSFrameConstructor::RecreateFramesForContent(nsIPresContext * 0x0350a210, nsIContent * 0x036aa540) line 11163 + 40 bytes nsCSSFrameConstructor::AttributeChanged(nsCSSFrameConstructor * const 0x0350ba50, nsIPresContext * 0x0350a210, nsIContent * 0x036aa540, int 0, nsIAtom * 0x01538680, int 2) line 10163 + 16 bytes StyleSetImpl::AttributeChanged(StyleSetImpl * const 0x0350bb10, nsIPresContext * 0x0350a210, nsIContent * 0x036aa540, int 0, nsIAtom * 0x01538680, int -1) line 1143 PresShell::AttributeChanged(PresShell * const 0x0350b6f8, nsIDocument * 0x03509df0, nsIContent * 0x036aa540, int 0, nsIAtom * 0x01538680, int -1) line 3295 + 57 bytes nsXULDocument::AttributeChanged(nsXULDocument * const 0x03509df0, nsIContent * 0x036aa540, int 0, nsIAtom * 0x01538680, int -1) line 1674 nsXULElement::SetAttribute(nsXULElement * const 0x036aa540, int 0, nsIAtom * 0x01538680, const nsString & {...}, int 1) line 2855 nsPopupSetFrame::MarkAsGenerated(nsIContent * 0x036aa540) line 525 + 41 bytes nsPopupSetFrame::CreatePopup(nsPopupSetFrame * const 0x01f091a8, nsIContent * 0x036b8630, nsIContent * 0x036aa540, int 269, int 230, const nsString & {...}, const nsString & {...}, const nsString & {...}) line 456 nsPopupSetBoxObject::CreatePopup(nsPopupSetBoxObject * const 0x03d4afc0, nsIDOMElement * 0x036b863c, nsIDOMElement * 0x036aa54c, int 269, int 230, const unsigned short * 0x0012cccc, const unsigned short * 0x0012cb50, const unsigned short * 0x0012caa4) line 139 + 127 bytes XULPopupListenerImpl::LaunchPopup(int 269, int 230) line 567 XULPopupListenerImpl::sTooltipCallback(nsITimer * 0x043b3590, void * 0x036b8420) line 617 nsTimer::Fire() line 194 + 17 bytes FireTimeout(HWND__ * 0x00000000, unsigned int 275, unsigned int 22124, unsigned long 1803894973) line 78 USER32! 77e7185c() OLE32! 77b8f920() nsDragService::StartInvokingDragSession(nsDragService * const 0x026e6590, IDataObject * 0x043b2670, unsigned int 7) line 140 + 25 bytes nsDragService::InvokeDragSession(nsDragService * const 0x026e6590, nsIDOMNode * 0x03f735e0, nsISupportsArray * 0x043b2d60, nsIScriptableRegion * 0x00000000, unsigned int 7) line 109 XPTC_InvokeByIndex(nsISupports * 0x026e6590, unsigned int 3, unsigned int 4, nsXPTCVariant * 0x0012d248) line 139 nsXPCWrappedNativeClass::CallWrappedMethod(JSContext * 0x02fefde0, nsXPCWrappedNative * 0x042661e0, const XPCNativeMemberDescriptor * 0x04266444, nsXPCWrappedNativeClass::CallMode CALL_METHOD, unsigned int 4, long * 0x01edee70, long * 0x0012d3f8) line 914 + 43 bytes WrappedNative_CallMethod(JSContext * 0x02fefde0, JSObject * 0x039a5220, unsigned int 4, long * 0x01edee70, long * 0x0012d3f8) line 200 + 34 bytes js_Invoke(JSContext * 0x02fefde0, unsigned int 4, unsigned int 0) line 716 + 23 bytes js_Interpret(JSContext * 0x02fefde0, long * 0x0012dd34) line 2520 + 15 bytes js_Invoke(JSContext * 0x02fefde0, unsigned int 1, unsigned int 2) line 732 + 13 bytes js_InternalInvoke(JSContext * 0x02fefde0, JSObject * 0x01f00020, long 60593456, unsigned int 0, unsigned int 1, long * 0x0012dec8, long * 0x0012de58) line 805 + 19 bytes JS_CallFunctionValue(JSContext * 0x02fefde0, JSObject * 0x01f00020, long 60593456, unsigned int 1, long * 0x0012dec8, long * 0x0012de58) line 2815 + 31 bytes nsJSContext::CallEventHandler(nsJSContext * const 0x02fee2f0, void * 0x01f00020, void * 0x039c9530, unsigned int 1, void * 0x0012dec8, int * 0x0012dec4, int 0) line 847 + 33 bytes nsJSEventListener::HandleEvent(nsIDOMEvent * 0x043b5fb4) line 154 + 64 bytes nsEventListenerManager::HandleEventSubType(nsListenerStruct * 0x036b88f0, nsIDOMEvent * 0x043b5fb4, nsIDOMEventTarget * 0x036b8b70, unsigned int 16, unsigned int 2) line 772 + 19 bytes nsEventListenerManager::HandleEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, nsIDOMEventTarget * 0x036b8b70, unsigned int 2, nsEventStatus * 0x0012f24c) line 1487 + 39 bytes nsXULElement::HandleDOMEvent(nsXULElement * const 0x036b8b60, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 3350 nsXULElement::HandleDOMEvent(nsXULElement * const 0x036b8790, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 3373 + 39 bytes nsXULElement::HandleDOMEvent(nsXULElement * const 0x036b8630, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 3373 + 39 bytes nsXULElement::HandleChromeEvent(nsXULElement * const 0x036b864c, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 4301 + 39 bytes GlobalWindowImpl::HandleDOMEvent(GlobalWindowImpl * const 0x03871040, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 432 nsDocument::HandleDOMEvent(nsDocument * const 0x03e9eb40, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 3003 nsGenericElement::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1402 + 39 bytes nsHTMLHtmlElement::HandleDOMEvent(nsHTMLHtmlElement * const 0x03e8a668, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 187 nsGenericElement::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1395 + 39 bytes nsHTMLBodyElement::HandleDOMEvent(nsHTMLBodyElement * const 0x03dca268, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 901 nsGenericElement::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1395 + 39 bytes nsHTMLTableElement::HandleDOMEvent(nsHTMLTableElement * const 0x03ecaa58, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1382 nsGenericElement::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1395 + 39 bytes nsHTMLTableSectionElement::HandleDOMEvent(nsHTMLTableSectionElement * const 0x03eca848, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 367 nsGenericElement::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1395 + 39 bytes nsHTMLTableRowElement::HandleDOMEvent(nsHTMLTableRowElement * const 0x03eca7d8, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 735 nsGenericElement::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1395 + 39 bytes nsHTMLTableCellElement::HandleDOMEvent(nsHTMLTableCellElement * const 0x03ee48bc, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 556 nsGenericElement::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1395 + 39 bytes nsHTMLTableElement::HandleDOMEvent(nsHTMLTableElement * const 0x03f624b8, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1382 nsGenericElement::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1395 + 39 bytes nsHTMLTableSectionElement::HandleDOMEvent(nsHTMLTableSectionElement * const 0x03f623d8, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 367 nsGenericElement::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1395 + 39 bytes nsHTMLTableRowElement::HandleDOMEvent(nsHTMLTableRowElement * const 0x03f62368, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 735 nsGenericElement::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1395 + 39 bytes nsHTMLTableCellElement::HandleDOMEvent(nsHTMLTableCellElement * const 0x03f6208c, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 556 nsGenericElement::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1395 + 39 bytes nsHTMLSpanElement::HandleDOMEvent(nsHTMLSpanElement * const 0x03f738d8, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 171 nsGenericElement::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1395 + 39 bytes nsHTMLFontElement::HandleDOMEvent(nsHTMLFontElement * const 0x03f73878, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 387 nsGenericElement::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1395 + 39 bytes nsGenericHTMLElement::HandleDOMEventForAnchors(nsIContent * 0x03f7379c, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 1097 + 31 bytes nsHTMLAnchorElement::HandleDOMEvent(nsHTMLAnchorElement * const 0x03f7379c, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 2, nsEventStatus * 0x0012f24c) line 413 nsGenericDOMDataNode::HandleDOMEvent(nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x0012f18c, unsigned int 1, nsEventStatus * 0x0012f24c) line 800 + 39 bytes nsTextNode::HandleDOMEvent(nsTextNode * const 0x03f735e8, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f208, nsIDOMEvent * * 0x00000000, unsigned int 1, nsEventStatus * 0x0012f24c) line 255 nsEventStateManager::GenerateDragGesture(nsIPresContext * 0x03e97e00, nsGUIEvent * 0x0012f8a8) line 751 nsEventStateManager::PreHandleEvent(nsEventStateManager * const 0x03e4e768, nsIPresContext * 0x03e97e00, nsEvent * 0x0012f8a8, nsIFrame * 0x039dc8e4, nsEventStatus * 0x0012f798, nsIView * 0x03ea37a0) line 295 PresShell::HandleEventInternal(nsEvent * 0x0012f8a8, nsIView * 0x03ea37a0, nsEventStatus * 0x0012f798) line 3901 + 43 bytes PresShell::HandleEvent(PresShell * const 0x03dc6914, nsIView * 0x03ea37a0, nsGUIEvent * 0x0012f8a8, nsEventStatus * 0x0012f798, int & 1) line 3842 + 23 bytes nsView::HandleEvent(nsView * const 0x03ea37a0, nsGUIEvent * 0x0012f8a8, unsigned int 8, nsEventStatus * 0x0012f798, int & 1) line 782 nsView::HandleEvent(nsView * const 0x03ea3f60, nsGUIEvent * 0x0012f8a8, unsigned int 8, nsEventStatus * 0x0012f798, int & 1) line 755 nsView::HandleEvent(nsView * const 0x03dc74b0, nsGUIEvent * 0x0012f8a8, unsigned int 28, nsEventStatus * 0x0012f798, int & 1) line 755 nsViewManager2::DispatchEvent(nsViewManager2 * const 0x03dc4160, nsGUIEvent * 0x0012f8a8, nsEventStatus * 0x0012f798) line 1389 HandleEvent(nsGUIEvent * 0x0012f8a8) line 69 nsWindow::DispatchEvent(nsWindow * const 0x03ea3e34, nsGUIEvent * 0x0012f8a8, nsEventStatus & nsEventStatus_eIgnore) line 560 + 10 bytes nsWindow::DispatchWindowEvent(nsGUIEvent * 0x0012f8a8) line 581 nsWindow::DispatchMouseEvent(unsigned int 300, nsPoint * 0x00000000) line 3694 + 21 bytes ChildWindow::DispatchMouseEvent(unsigned int 300, nsPoint * 0x00000000) line 3901 nsWindow::ProcessMessage(unsigned int 512, unsigned int 1, long 14024969, long * 0x0012fc24) line 2787 + 24 bytes nsWindow::WindowProc(HWND__ * 0x71090478, unsigned int 512, unsigned int 1, long 14024969) line 829 + 27 bytes USER32! 77e71820() 00d60109()
It looks like the following is happening: -- Drag event fires, starting drag session -- Tooltip timer goes off during drag session, starting tooltip launch -- Tooltip launch sets "generated" attribute on something, triggers reflow of tooltip, handled synchronously because we're in a drag -- Before executing the reflow, we call PresShell::HandlePostedDOMEvents -- There is an event to be handled (NS_SCROLLPORT_OVERFLOW) -- Event triggers a script handler -- Script handler removes "collapsed" attribute from something, triggering a reflow, handled synchronously because we're in a drag -- Before executing the reflow, we call PresShell::HandlePostedDOMEvents -- We try to handle the same event that's already being handled further up the stack! -- All hell breaks loose The obvious thing to do would be to remove the nsDOMEventRequest node from the list of event requests before processing it (and likewise for the nsAttributeChangeRequest nodes in HandlePostedAttributeChanges). I think it might be better, however, to not reenter FlushPendingNotifications. I will try a patch.
I don't have a surefire testcase for this, because it depends on timing. However, if I open up two Mozilla windows and repeatedly try to drag a link from one window to another, I always crash after a few tries.
Preventing reentry into FlushPendingNotifications seems hard. Instead I changed HandlePostedDOMEvents and HandlePostedAttributeChanges to keep their pending change lists properly formatted for possible reentry. With these changes, the crashes are gone; I can safely drag links all over the place (with tooltips popping up left and right).
BTW, I think I also fixed a possible memory leak in HandlePostedAttributeChanges; the nsAttributeChangeRequest node has an nsAutoString field "value" which wasn't being destroyed, which would leak if the nsAutoString had overflowed and required heap allocation.
Severity: normal → critical
Keywords: approval, crash, patch, review
Adding keyword 'topcrash' in the talkback system.
Keywords: topcrash
Distribution of Clayton's bugs: please triage these and share the joy...
Assignee: clayton → attinasi
This looks like it might be the same issue that is reported in bug 45361 - the stack has the same top anyway.
nsbeta2 stopper?
Keywords: nsbeta2
Considering this is a top talkback issue it should be a beta2 blocker - crash is bad. I think we need to get the correct eyes on the patch and see if it is an acceptable fix, low risk etc. Hopefully it is since this crash is reportedly somewhat common. CC'ing evaughan in hopes that he will review the patch since he wrote the original method impl.
Updated summary
Summary: Crash during drag when tooltip tries to pop up → Crash during drag when tooltip tries to pop up[Crashes at PresShell::HandlePostedDOMEvents()]
Putting on [nsbeta2+] radar for beta2 fix.
Summary: Crash during drag when tooltip tries to pop up[Crashes at PresShell::HandlePostedDOMEvents()] → Crash during drag when tooltip tries to pop up [@ PresShell::HandlePostedDOMEvents]
Whiteboard: [nsbeta2+]
I could not reproduce the crash, however the related bug 45361 does crash for me and the patch fixes that one (I have updated that bug). I think the patch is good, but I'd like somebody mroe familiar with the code to review it too (evaughan has been asked). Is there a more specific way to get this crash to happen? I tried dragging links from various pages into another Mozill awindow but it just worked (it works with the patch too, BTW).
I was using a build with Ben's old "tooltip on every link" code. The crashes would occur when a tooltip tried to pop up during a drag operation. Ben's code was removed because people didn't like it, and maybe that's making it hard for you to reproduce this bug. Try pages which have TITLEs on the links. Alternatively, check in the patch as a fix to bug 45361 and mark this bug WORKSFORME. I don't mind either way :-).
*** Bug 45505 has been marked as a duplicate of this bug. ***
I can still reproduce this even without the tooltips, it just takes longer.
Keywords: review
Status: NEW → ASSIGNED
Whiteboard: [nsbeta2+] → [nsbeta2+] FIX IN HAND
Patch checked in - thanks Robert!
Status: ASSIGNED → RESOLVED
Closed: 26 years ago
Resolution: --- → FIXED
Verified fixed in the July 24th builds (2000072408).
Status: RESOLVED → VERIFIED
Crash Signature: [@ PresShell::HandlePostedDOMEvents]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: