Closed
Bug 348126
Opened 18 years ago
Closed 17 years ago
Crash [@ nsImageFrame::SourceRectToDest] on reload and removing table-caption styles
Categories
(Core :: Layout: Tables, defect)
Core
Layout: Tables
Tracking
()
VERIFIED
FIXED
People
(Reporter: martijn.martijn, Assigned: MatsPalmgren_bugz)
References
Details
(4 keywords, Whiteboard: [sg:critical] regression from bug 309322)
Crash Data
Attachments
(1 file, 3 obsolete files)
897 bytes,
text/html
|
Details |
See upcoming testcase, which crashes on reload in current trunk build. This regressed between 2005-12-03 and 2005-12-04, probably a regression from bug 309322. I guess there is a security issue here.
Reporter | ||
Comment 1•18 years ago
|
||
Reporter | ||
Comment 2•18 years ago
|
||
Argh! I forgot about the fish.
Reporter | ||
Comment 3•18 years ago
|
||
Attachment #232985 -
Attachment is obsolete: true
Reporter | ||
Comment 4•18 years ago
|
||
Attachment #232986 -
Attachment is obsolete: true
Attachment #232987 -
Attachment is obsolete: true
Comment 5•18 years ago
|
||
I can reproduce on Mac trunk (debug build). On load: ###!!! ASSERTION: unexpected child list: 'PR_FALSE', file /Users/admin/trunk/mozilla/layout/tables/nsTableOuterFrame.cpp, line 243 ###!!! ASSERTION: invalid previous frame: '!aPrevFrame', file /Users/admin/trunk/mozilla/layout/tables/nsTableOuterFrame.cpp, line 266 ###!!! ASSERTION: unexpected child list: 'PR_FALSE', file /Users/admin/trunk/mozilla/layout/tables/nsTableOuterFrame.cpp, line 243 ###!!! ASSERTION: illegal next frame in incremental reflow.: 'PR_FALSE', file /Users/admin/trunk/mozilla/layout/tables/nsTableOuterFrame.cpp, line 1393 On reload, with the patch for bug 334514: ###!!! ASSERTION: Some frame destructors were not called.: 'mFrameCount == 0', file /Users/admin/trunk/mozilla/layout/base/nsPresShell.cpp, line 629 (One nice thing about using the patch for bug 334514 is that you can reload and see whether the assertion fires, rather than reloading an seeing whether Firefox crashes, if you take out the animated GIFs.) Crash trying to read memory at 0xdadadaf6. Dup of bug 337476?
fixed by the checkin for bug bug 341858
Status: NEW → RESOLVED
Closed: 18 years ago
Resolution: --- → FIXED
Updated•17 years ago
|
Flags: wanted1.8.1.x+
Flags: wanted1.8.0.x+
Flags: blocking1.8.1.4?
Flags: blocking1.8.0.12?
Whiteboard: [sg:critical] → [sg:critical] regression from bug 309322
Updated•17 years ago
|
Flags: blocking1.8.1.4?
Flags: blocking1.8.1.4+
Flags: blocking1.8.0.12?
Flags: blocking1.8.0.12+
Updated•17 years ago
|
Status: RESOLVED → REOPENED
Resolution: FIXED → ---
Updated•17 years ago
|
Assignee: nobody → mats.palmgren
Status: REOPENED → NEW
Updated•17 years ago
|
Status: NEW → RESOLVED
Closed: 18 years ago → 17 years ago
Resolution: --- → FIXED
Comment 8•17 years ago
|
||
Moving to 1.8.1.5 following bug 309322
Flags: blocking1.8.1.5+
Flags: blocking1.8.1.4+
Flags: blocking1.8.0.13+
Flags: blocking1.8.0.12+
Comment 9•17 years ago
|
||
Moving to 1.8.1.6 following bug 309322
Flags: blocking1.8.1.5+ → blocking1.8.1.6+
Updated•17 years ago
|
Flags: blocking1.8.0.13+ → blocking1.8.0.14?
Comment 11•17 years ago
|
||
Verified fix on Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US; rv:1.8.1.8) Gecko/20071004 Firefox/2.0.0.8: Firefox 2.0.0.8 ID:2007100415. Testcase doesnt crash on reload.
Status: RESOLVED → VERIFIED
Keywords: fixed1.8.1.8 → verified1.8.1.8
Updated•17 years ago
|
Group: security
Updated•17 years ago
|
Flags: in-testsuite?
Updated•17 years ago
|
Flags: blocking1.8.0.14? → blocking1.8.0.15?
Updated•16 years ago
|
Flags: blocking1.8.0.15? → blocking1.8.0.15+
Comment 12•15 years ago
|
||
crash test landed http://hg.mozilla.org/mozilla-central/rev/3d0c408c687c
Flags: in-testsuite? → in-testsuite+
Updated•13 years ago
|
Crash Signature: [@ nsImageFrame::SourceRectToDest]
You need to log in
before you can comment on or make changes to this bug.
Description
•