Use-after-poison [@ mozilla::FontFamilyList::FontFamilyList] with unicode-bidi: bidi-override

RESOLVED FIXED in Firefox 35

Status

()

defect
--
critical
RESOLVED FIXED
5 years ago
3 years ago

People

(Reporter: jruderman, Assigned: heycam)

Tracking

(Blocks 1 bug, 4 keywords)

Trunk
mozilla35
x86_64
All
Points:
---
Dependency tree / graph
Bug Flags:
in-testsuite ?

Firefox Tracking Flags

(firefox35 fixed, firefox-esr31 unaffected)

Details

(Whiteboard: [adv-main35+], crash signature)

Attachments

(5 attachments)

No description provided.
Posted file stack (lldb)
Posted file stack (ASan)
In nsLayoutUtils::GetFontMetricsForStyleContext:
3414      nsFont font = aStyleContext->StyleFont()->mFont;

aStyleContext looks fine, the StyleFont() points to a destroyed object,
i.e. memory still allocated but poisoned in the pres shell arena.

Maybe the same underlying problem as bug 1070759?
Component: Layout: Text → CSS Parsing and Computation
OS: Mac OS X → All
Might be different.  With this bug, if I enable the more expensive style struct destruction checking http://hg.mozilla.org/mozilla-central/file/5e704397529b/layout/style/nsStyleContext.cpp#l89 then it triggers for me:

style struct 0x625000771300 found on style context 0x62500077b7b8
  in file:///tmp/test2.html
Assertion failure: false (destroying Font style struct still present in style context tree), at ./nsStyleStructList.h:44

but not in bug 1070759.

So it's likely this bug is a regression for bug 931668.
Using the restyle logging patches from bug 979133 and bug 1072724 I get this output.  Pretty sure we shouldn't be swapping structs for the same-style continuations.
Assignee: nobody → cam
Status: NEW → ASSIGNED
Looks like this is a change I was going to have in bug 931668, but when splitting up my patch queue it ended up in the bug 979133 patch (see bug 979133 comment 15's mention of copyFromContinuations).
Posted patch patchSplinter Review
Attachment #8494997 - Flags: review?(dbaron)
Attachment #8494997 - Flags: review?(dbaron) → review+
https://hg.mozilla.org/mozilla-central/rev/64136343bb4b
Status: ASSIGNED → RESOLVED
Closed: 5 years ago
Flags: in-testsuite?
Resolution: --- → FIXED
Target Milestone: --- → mozilla35
Whiteboard: [adv-main35+]
Group: core-security → core-security-release
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.