Closed Bug 325738 Opened 19 years ago Closed 18 years ago

crash when closing browser [@ nsDOMConstructor::HasInstance] [@ nsDOMConstructor::Construct] [@ nsStyleSheetService::UnregisterSheet] [@ nsDOMClassInfo::MarkReachablePreservedWrappers] [@ nsHTMLFormElement::GetActionURL] [@ ClassifyWrapper]

Categories

(Core :: DOM: Core & HTML, defect)

x86
Windows 2000
defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 325279

People

(Reporter: Peter6, Unassigned)

References

Details

(Keywords: crash, regression)

Crash Data

Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.9a1) Gecko/20060203 Firefox/1.6a1 ID:2006020304

random crash when closing browser
this prossibly started after the 20060202 build (hard to tell because we had a number of notorious crashers fixed between 20060202 and 20060203)
TB14693336G

Incident ID: 14693336
Stack Signature	0x00000001 5c022b51
Product ID	FirefoxTrunk
Build ID	2006020206
Trigger Time	2006-02-03 00:49:07.0
Platform	Win32
Operating System	Windows NT 5.0 build 2195
Module	
URL visited	
User Comments	crah on exit
Since Last Crash	18358 sec
Total Uptime	19409 sec
Trigger Reason	Access violation
Source File, Line No.	N/A
Stack Trace 	
0x00000001
nsDOMConstructor::HasInstance  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 4773]
nsDOMConstructor::HasInstance  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 4759]
nsDOMConstructor::HasInstance  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 4675]
nsEventReceiverSH::AddEventListenerHelper  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 6553]
XPC_WN_Helper_NewResolve  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/xpconnect/src/xpcwrappednativejsops.cpp, line 1041]
js_Mark  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsobj.c, line 4276]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1193]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1272]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1272]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1272]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1272]
js_MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1493]
js_GC  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1753]
js_ForceGC  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1560]

also TB14693765G (different user)

Incident ID: 14693765
Stack Signature	0x69672f65 e1bcf78d
Product ID	FirefoxTrunk
Build ID	2006020206
Trigger Time	2006-02-03 01:08:59.0
Platform	Win32
Operating System	Windows NT 5.1 build 2600
Module	
URL visited	
User Comments	
Since Last Crash	8071 sec
Total Uptime	19254 sec
Trigger Reason	Access violation
Source File, Line No.	N/A
Stack Trace 	
0x69672f65
nsDOMConstructor::HasInstance  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 4773]
nsDOMConstructor::HasInstance  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 4759]
nsDOMConstructor::HasInstance  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 4675]
nsEventReceiverSH::AddEventListenerHelper  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 6553]
XPC_WN_Helper_NewResolve  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/xpconnect/src/xpcwrappednativejsops.cpp, line 1041]
js_Mark  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsobj.c, line 4276]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1193]
js_MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1493]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1193]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1272]
js_MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1493]
js_GC  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1753]
js_ForceGC  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1560]
Severity: normal → major
Assignee: nobody → general
Severity: major → critical
Component: General → DOM
Product: Firefox → Core
QA Contact: general → ian
why would js_Mark call XPC_WN_Helper_NewResolve ?
Summary: crash when closing browser → crash when closing browser [@ nsDOMConstructor::HasInstance]
The second TB Peter mentioned was me. I narrowed the problem down on my machine by disabling extensions one by one. I have disabled "IE View 1.2.7" for about three hours now and since then not a single crash on exit (tried varios sites and opened/closed the browser approximately 30 times). All my other extensions are enabled, only this one is disabled. Before my browser had a 75% chance of crash on exit with IE View 1.2.7 enabled.
(In reply to comment #2)
> The second TB Peter mentioned was me. I narrowed the problem down on my machine
> by disabling extensions one by one. I have disabled "IE View 1.2.7" for about
> three hours now and since then not a single crash on exit (tried varios sites
> and opened/closed the browser approximately 30 times). All my other extensions
> are enabled, only this one is disabled. Before my browser had a 75% chance of
> crash on exit with IE View 1.2.7 enabled.
> 
I don't have IE View at all
I have had this off an on, and actually it just happened when I checked this thread.

EXACT sequence of events:
1. Saw that I had a new email in my Gmail inbox by looking at a Yahoo! Widget on my desktop.
2. Clicked the widget to open Firefox at my Gmail inbox page.
3. The email was a Bugzilla email for this bug after the last two replies.
4. Clicked the email to open it, then middle clicked the link to this page to open this page in another tab.
5. Read everything all the comments that had been added since I last saw. Thought to myself that I didn't recall exactly when the last time it crashed for me was, or if there was a reason why.
6. Closed Firefox (with both tabs, Gmail and this page open).

Then it crashed. I don't have Talkback setup (I'm gonna do that in a little while), but I did click for details on the default Windows bug reporting dialog that came up, and it didn't list a specific module name that crashed. It's hard to get any useful information from those dialogs which is why I'm getting talkback setup in a little while like I said.

Attempts to retrace my steps EXACTLY, click for click, as I did before failed to reproduce the crash.
The crash seems related to at least Adblock Plus 0.6.0.4 (also 0.6.0.4+)
In an attempt to create a reproducable case I managed to crash a few more times.
But it almost seems random (like the traces).
So far it crashes when I have been browsing Gmail with Adblock 0.6.0.4 installed (no filters used) with a few other tabs open (mozillazine,bugzilla,tinderboxen)
TB14738252X 
TB14738089K 
TB14738011X 
TB14737981H
TB14722943Z [@ nsStyleSheetService::UnregisterSheet]
TB14719561M [@ nsDOMClassInfo::MarkReachablePreservedWrappers]
I have had this issue and got this crash: TB14740375H.
It looks suspisiously similar and I do not run either Adblock or Adblock Plus.
Incident ID: 14738252, 14738089, 14738011
Stack Signature	ClassifyWrapper facefd9d
Product ID	FirefoxTrunk
Build ID	2006020306
Trigger Time	2006-02-04 03:49:13.0
Platform	Win32
Operating System	Windows NT 5.0 build 2195
Module	firefox.exe + (001434c6)
URL visited	
User Comments	
Since Last Crash	403 sec
Total Uptime	34496 sec
Trigger Reason	Access violation
Source File, Line No.	c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 5126
Stack Trace 	
ClassifyWrapper  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 5126]
ClassifyWrapper  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 5106]
nsDOMClassInfo::MarkReachablePreservedWrappers  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 5053]
nsElementSH::PostCreate  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 6742]
XPC_WN_Helper_NewResolve  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/xpconnect/src/xpcwrappednativejsops.cpp, line 1041]
js_Mark  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsobj.c, line 4276]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1193]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1280]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1280]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1280]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1280]
js_MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1493]
js_GC  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1754]
js_ForceGC  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1560]
*** Bug 325982 has been marked as a duplicate of this bug. ***
From bug 325982:

Firefox will randomly crash on close (usualy on the first close after starting
the PC), producing this report:

Incident ID: TB14757485
Stack Signature nsHTMLFormElement::GetActionURL 43d3e940
Product ID      FirefoxTrunk
Build ID        2006020306
Trigger Time    2006-02-04 14:02:33.0
Platform        Win32
Operating System        Windows NT 5.1 build 2600
Module  firefox.exe + (00300078)
URL visited     close
User Comments   crash on close. TBID: monks
Since Last Crash        1315 sec
Total Uptime    1315 sec
Trigger Reason  Access violation
Source File, Line No.  
c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/content/html/content/src/nsHTMLFormElement.cpp,
line 1390
Stack Trace     
nsHTMLFormElement::GetActionURL 
[c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/content/html/content/src/nsHTMLFormElement.cpp,
line 1390]
nsDOMClassInfo::BeginGCMark 
[c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp,
line 5149]
nsDOMClassInfo::MarkReachablePreservedWrappers 
[c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp,
line 5042]
nsDOMGCParticipantSH::Mark 
[c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp,
line 6731]
XPC_WN_Helper_Mark 
[c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/xpconnect/src/xpcwrappednativejsops.cpp,
line 1030]
js_Mark  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsobj.c,
line 4276]
MarkGCThing 
[c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line
1193]
MarkGCThing 
[c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line
1280]
MarkGCThing 
[c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line
1280]
js_MarkGCThing 
[c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line
1493]
js_GC  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c,
line 1754]
js_ForceGC 
[c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line
1560]
Keywords: crash
Summary: crash when closing browser [@ nsDOMConstructor::HasInstance] → crash when closing browser [@ nsDOMConstructor::HasInstance] [@ nsDOMConstructor::Construct] [@ nsStyleSheetService::UnregisterSheet] [@ nsDOMClassInfo::MarkReachablePreservedWrappers] [@ nsHTMLFormElement::GetActionURL] [@ ClassifyWrapper]
Flags: blocking1.9a1?
Brendan, any chance your [sg]patch (the arghhhh one) on 20060203 caused this ?
(In reply to comment #11)
> Brendan, any chance your [sg]patch (the arghhhh one) on 20060203 caused this ?

No, that patch (see http://tinderbox.mozilla.org/bonsai/cvsview2.cgi?diff_mode=context&whitespace_mode=show&subdir=mozilla/js/src&command=DIFF_FRAMESET&file=jsapi.c&rev1=3.238&rev2=3.239&root=/cvsroot) removed a js_EnterLocalRootScope call that lacked a matching js_LeaveLocalRootScope call.  It fixed bad leak bugs.  That's all.

The "Arghhhhhh." change was fixing the previous change (rev 238 of jsapi.c among others), which did remove local rooting in favor of a single temp value rooter.  Could that change, made over 13 hours earlier, have caused this bug?  Anyone able to test the builds?

/be
For what I van tell the crash [@ _PR_MD_ATOMIC_DECREMENT] (see bug 322414) really changed into this one.
But with Talkback being as pathetic as is it takes a lot of time to figure it out.
I have the following builds:
firefox-1.6a1.en-US.win32_20060202_0724pst
firefox-1.6a1.en-US.win32_20060202_1201pst
firefox-1.6a1.en-US.win32_20060202_1346pst
firefox-1.6a1.en-US.win32_20060202_1519pst
firefox-1.6a1.en-US.win32_20060202_2152pst
firefox-1.6a1.en-US.win32_20060203_0238pst
firefox-1.6a1.en-US.win32_20060203_0434pst
firefox-1.6a1.en-US.win32_20060203_0659pst
firefox-1.6a1.en-US.win32_20060203_1208pst
firefox-1.6a1.en-US.win32_20060203_1340pst
firefox-1.6a1.en-US.win32_20060204_0208pst
So i should be able to nail the regressionwindow fir this one fairly well.
right, what i've been able to track:

between 
 20060201 2246 pst and
 20060202 1155 pst
the builds were useless/freezing due to the incomplete patch for bug 325269

Unfortunately bug 322414 (fix for crash at _PR_MD_ATOMIC_DECREMENT and) which was responsible for a huge amount of crash on exits was also fixed during this period.

before  20060201 2246 pst it was mostly _PR_MD_ATOMIC_DECREMENT
after 20060202 1155 pst it was mostly this bug

crawling through talkback data i did however find older builds (e.g. 20060129)
with a "similar" stack (at least the last 5-6 lines were).

Maybe this regressed earlier but was covered by bug 325269 ?
It did regress after 20051230 though.
Looks a lot like bug 325279 to me...  Can someone actually reproduce this with a debug build?  If so, do any assertions fire in the process?
Depends on: 325279
Talkback report says "crash on open", but I meant "crash on close" but my eyes crossed... looks to be the same bug.

Incident ID: TB15215810
Stack Signature	0x00000000 d3241192
Product ID	FirefoxTrunk
Build ID	2006021306
Trigger Time	2006-02-15 11:18:16.0
Platform	Win32
Operating System	Windows NT 5.1 build 2600
Module	
URL visited	
User Comments	Crash on start. TBID: monks
Since Last Crash	17328 sec
Total Uptime	17328 sec
Trigger Reason	Access violation
Source File, Line No.	N/A
Stack Trace 	
0x00000000
ClassifyWrapper  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 5106]
nsDOMClassInfo::BeginGCMark  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 5149]
nsDOMClassInfo::MarkReachablePreservedWrappers  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 5042]
nsDOMGCParticipantSH::Mark  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 6731]
XPC_WN_Helper_Mark  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/xpconnect/src/xpcwrappednativejsops.cpp, line 1030]
js_Mark  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsobj.c, line 4304]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1197]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1284]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1284]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1284]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1284]
js_MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1497]
js_GC  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1758]
js_ForceGC  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1564]
Another...

Incident ID: TB14921369
Stack Signature	0x02935ec8 08779a98
Product ID	FirefoxTrunk
Build ID	2006020606
Trigger Time	2006-02-08 11:52:21.0
Platform	Win32
Operating System	Windows NT 5.1 build 2600
Module	
URL visited	close
User Comments	Crashed on close. TBID: monks
Since Last Crash	26977 sec
Total Uptime	26977 sec
Trigger Reason	Access violation
Source File, Line No.	N/A
Stack Trace 	
0x02935ec8
nsDOMClassInfo::BeginGCMark  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 5149]
nsDOMClassInfo::MarkReachablePreservedWrappers  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 5042]
nsDOMGCParticipantSH::Mark  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/dom/src/base/nsDOMClassInfo.cpp, line 6731]
XPC_WN_Helper_Mark  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/xpconnect/src/xpcwrappednativejsops.cpp, line 1030]
js_Mark  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsobj.c, line 4276]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1193]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1280]
MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1280]
js_MarkGCThing  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1493]
js_GC  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1754]
js_ForceGC  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsgc.c, line 1560]
Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.9a1) Gecko/20060217 Firefox/1.6a1 ID:2006021723

This is fixed for me after bug 325279 landed
Dup of bug 325279 per comment 15 and comment 18.

Peter, it would be good if you could find a way to reproduce and detect the leak (that combined with bug 325279 caused this crash) and notify the right people (possibly an extension author).

*** This bug has been marked as a duplicate of 325279 ***
Status: NEW → RESOLVED
Closed: 18 years ago
No longer depends on: 325279
Flags: blocking1.9a1?
Resolution: --- → DUPLICATE
Crash Signature: [@ nsDOMConstructor::HasInstance] [@ nsDOMConstructor::Construct] [@ nsStyleSheetService::UnregisterSheet] [@ nsDOMClassInfo::MarkReachablePreservedWrappers] [@ nsHTMLFormElement::GetActionURL] [@ ClassifyWrapper]
Component: DOM → DOM: Core & HTML
You need to log in before you can comment on or make changes to this bug.