Closed Bug 112265 Opened 24 years ago Closed 24 years ago

Crash with a simple XUL document - M096 & Trunk [@ nsTreeLayout::LazyRowCreator]

Categories

(Core :: XUL, defect)

x86
All
defect
Not set
critical

Tracking

()

VERIFIED FIXED
mozilla0.9.7

People

(Reporter: dolmen, Assigned: tingley)

References

()

Details

(Keywords: crash, topcrash)

Crash Data

Attachments

(2 files)

From Bugzilla Helper: User-Agent: Mozilla/5.0 (Windows; U; WinNT4.0; en-US; rv:0.9.6) Gecko/20011120 BuildID: 2001112009 (Mozilla Release 0.9.6) Reproducible: Always Steps to Reproduce: 1. Load the attached file. Actual Results: Crash. Expected Results: I don't know, as it is not a valid XUL file, but not a crash. It seems related to the fact the <listitem> is not expected inside a <treeitem> element. It may be a security problem.
Attached file A testcase —
Avoid to load the attachment directly from Mozilla. :)
confirming with win2k build 20011127.. reporter: i must load the attachment with mozilla to confirm your bug :-) stack trace: nsTreeLayout::LazyRowCreator(nsTreeLayout * const 0x0520df58, nsBoxLayoutState & {...}, nsXULTreeGroupFrame * 0x05322f64) line 402 + 18 bytes nsTreeLayout::LazyRowCreator(nsTreeLayout * const 0x0520df58, nsBoxLayoutState & {...}, nsXULTreeGroupFrame * 0x051eb728) line 386 nsXULTreeOuterGroupFrame::ReflowFinished(nsXULTreeOuterGroupFrame * const 0x051eb7e8, nsIPresShell * 0x04034fa8, int * 0x0012f518) line 1358 PresShell::HandlePostedReflowCallbacks() line 4959 PresShell::ProcessReflowCommands(int 0) line 6189 PresShell::FlushPendingNotifications(PresShell * const 0x04034fa8, int 0) line 5053 nsXULDocument::FlushPendingNotifications(nsXULDocument * const 0x051ff210, int 1, int 0) line 2341 nsXBLResourceLoader::NotifyBoundElements() line 281 nsXBLResourceLoader::StyleSheetLoaded(nsXBLResourceLoader * const 0x050d7a08, nsICSSStyleSheet * 0x0510c538, int 1) line 207 CSSLoaderImpl::InsertSheetInDoc(nsICSSStyleSheet * 0x0510c538, int 2, nsIContent * 0x00000000, int 1, nsICSSLoaderObserver * 0x050d7a08) line 1181 InsertPendingSheet(void * 0x0531da40, void * 0x052772e8) line 742 nsVoidArray::EnumerateForwards(int (void *, void *)* 0x020415b0 InsertPendingSheet(void *, void *), void * 0x052772e8) line 652 + 21 bytes CSSLoaderImpl::Cleanup(URLKey & {...}, SheetLoadData * 0x04ef5d48) line 806 CSSLoaderImpl::SheetComplete(nsICSSStyleSheet * 0x00000000, SheetLoadData * 0x04ef5d48) line 899 CSSLoaderImpl::ParseSheet(nsIUnicharInputStream * 0x04ea2c80, SheetLoadData * 0x04ef5d48, int & 1, nsICSSStyleSheet * & 0x0510c538) line 934 CSSLoaderImpl::DidLoadStyle(nsIStreamLoader * 0x03fb71b8, nsString * 0x051e66a0, SheetLoadData * 0x04ef5d48, unsigned int 0) line 969 + 27 bytes SheetLoadData::OnStreamComplete(SheetLoadData * const 0x04ef5d48, nsIStreamLoader * 0x03fb71b8, nsISupports * 0x00000000, unsigned int 0, unsigned int 7343, const char * 0x051f9028) line 726 nsStreamLoader::OnStopRequest(nsStreamLoader * const 0x03fb71bc, nsIRequest * 0x050d2860, nsISupports * 0x00000000, unsigned int 0) line 137 nsJARChannel::OnStopRequest(nsJARChannel * const 0x050d2864, nsIRequest * 0x051ea37c, nsISupports * 0x00000000, unsigned int 0) line 611 + 49 bytes nsOnStopRequestEvent::HandleEvent() line 177 nsARequestObserverEvent::HandlePLEvent(PLEvent * 0x0516ca2c) line 80 PL_HandleEvent(PLEvent * 0x0516ca2c) line 590 + 10 bytes PL_ProcessPendingEvents(PLEventQueue * 0x00edd498) line 520 + 9 bytes _md_EventReceiverProc(HWND__ * 0x0017011e, unsigned int 49434, unsigned int 0, long 15586456) line 1071 + 9 bytes USER32! 77e02e98() USER32! 77e030e0() USER32! 77e05824() nsAppShellService::Run(nsAppShellService * const 0x00eead78) line 303 main1(int 2, char * * 0x003527a8, nsISupports * 0x00000000) line 1304 + 32 bytes main(int 2, char * * 0x003527a8) line 1630 + 37 bytes mainCRTStartup() line 338 + 17 bytes KERNEL32! 77e87d08()
Status: UNCONFIRMED → NEW
Ever confirmed: true
Keywords: crash
Target Milestone: --- → Future
Attached patch proposed fix — — Splinter Review
This is due to QIs to nsIXULTreeSlice not checking for a null pointer. There are three separate spots where checks need to be added in order for this to not crash.
cc'ing evaughan, since this appears to be his code.
Keywords: patch, review
*** Bug 112736 has been marked as a duplicate of this bug. ***
*** Bug 108916 has been marked as a duplicate of this bug. ***
Since bug 108916 has been marked a dupe of this bug, and since that bug concerned Linux, the platform of this bug should be changed to "All".
updating OS, summary, and nominating.
Keywords: mozilla0.9.7
OS: Windows NT → All
Summary: Crash with a simple XUL document → Crash with a simple XUL document [@nsTreeLayout::LazyRowCreator]
Adding topcrash keyword and M096 & Trunk to summary. This has been a topcrasher for Mozilla 0.9.6 and recent MozillaTrunk builds. Here's a recent stacktrace from a MozillaTrunk crash on Windows 2000: nsTreeLayout::LazyRowCreator [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsTreeLayout.cpp, line 404] nsXULTreeOuterGroupFrame::ReflowFinished [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsXULTreeOuterGroupFrame.cpp, line 1358] PresShell::HandlePostedReflowCallbacks [d:\builds\seamonkey\mozilla\layout\html\base\src\nsPresShell.cpp, line 4959] PresShell::ProcessReflowCommands [d:\builds\seamonkey\mozilla\layout\html\base\src\nsPresShell.cpp, line 6197] PresShell::FlushPendingNotifications [d:\builds\seamonkey\mozilla\layout\html\base\src\nsPresShell.cpp, line 5053] nsXULTreeOuterGroupFrame::InternalPositionChanged [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsXULTreeOuterGroupFrame.cpp, line 747] nsXULTreeOuterGroupFrame::EnsureRowIsVisible [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsXULTreeOuterGroupFrame.cpp, line 1227] nsXULTreeOuterGroupFrame::VisibilityChanged [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsXULTreeOuterGroupFrame.cpp, line 624] nsGfxScrollFrameInner::SetScrollbarVisibility [d:\builds\seamonkey\mozilla\layout\html\base\src\nsGfxScrollFrame.cpp, line 1490] nsGfxScrollFrameInner::AddRemoveScrollbar [d:\builds\seamonkey\mozilla\layout\html\base\src\nsGfxScrollFrame.cpp, line 989] nsGfxScrollFrameInner::RemoveVerticalScrollbar [d:\builds\seamonkey\mozilla\layout\html\base\src\nsGfxScrollFrame.cpp, line 952] nsGfxScrollFrameInner::Layout [d:\builds\seamonkey\mozilla\layout\html\base\src\nsGfxScrollFrame.cpp, line 1153] nsGfxScrollFrame::DoLayout [d:\builds\seamonkey\mozilla\layout\html\base\src\nsGfxScrollFrame.cpp, line 1037] nsBox::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBox.cpp, line 1002] nsSprocketLayout::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsSprocketLayout.cpp, line 525] nsContainerBox::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsContainerBox.cpp, line 611] nsBoxFrame::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBoxFrame.cpp, line 1126] nsBox::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBox.cpp, line 1002] nsStackLayout::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsStackLayout.cpp, line 331] nsGridLayout2::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\grid\nsGridLayout2.cpp, line 74] nsContainerBox::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsContainerBox.cpp, line 611] nsBoxFrame::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBoxFrame.cpp, line 1126] nsXULTreeFrame::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsXULTreeFrame.cpp, line 128] nsBox::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBox.cpp, line 1002] nsSprocketLayout::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsSprocketLayout.cpp, line 525] nsContainerBox::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsContainerBox.cpp, line 611] nsBoxFrame::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBoxFrame.cpp, line 1126] nsBox::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBox.cpp, line 1002] nsStackLayout::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsStackLayout.cpp, line 331] nsContainerBox::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsContainerBox.cpp, line 611] nsBoxFrame::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBoxFrame.cpp, line 1126] nsDeckFrame::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsDeckFrame.cpp, line 401] nsBox::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBox.cpp, line 1002] nsSprocketLayout::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsSprocketLayout.cpp, line 525] nsContainerBox::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsContainerBox.cpp, line 611] nsBoxFrame::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBoxFrame.cpp, line 1126] nsBox::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBox.cpp, line 1002] nsSprocketLayout::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsSprocketLayout.cpp, line 525] nsContainerBox::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsContainerBox.cpp, line 611] nsBoxFrame::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBoxFrame.cpp, line 1126] nsBox::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBox.cpp, line 1002] nsStackLayout::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsStackLayout.cpp, line 331] nsContainerBox::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsContainerBox.cpp, line 611] nsBoxFrame::DoLayout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBoxFrame.cpp, line 1126] nsBox::Layout [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBox.cpp, line 1002] nsBoxFrame::Reflow [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsBoxFrame.cpp, line 928] nsRootBoxFrame::Reflow [d:\builds\seamonkey\mozilla\layout\xul\base\src\nsRootBoxFrame.cpp, line 241] nsContainerFrame::ReflowChild [d:\builds\seamonkey\mozilla\layout\html\base\src\nsContainerFrame.cpp, line 737] ViewportFrame::Reflow [d:\builds\seamonkey\mozilla\layout\html\base\src\nsViewportFrame.cpp, line 576] PresShell::ResizeReflow [d:\builds\seamonkey\mozilla\layout\html\base\src\nsPresShell.cpp, line 2854] PresShell::ResizeReflow [d:\builds\seamonkey\mozilla\layout\html\base\src\nsPresShell.cpp, line 5942] nsViewManager::SetWindowDimensions [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 544] nsViewManager::DispatchEvent [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 1776] HandleEvent [d:\builds\seamonkey\mozilla\view\src\nsView.cpp, line 84] nsWindow::DispatchEvent [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 849] nsWindow::DispatchWindowEvent [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 866] nsWindow::OnResize [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 4292] nsWindow::ProcessMessage [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 3595] nsWindow::WindowProc [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 1114] USER32.DLL + 0x2e98 (0x77de2e98) USER32.DLL + 0x39a3 (0x77de39a3) USER32.DLL + 0x5cdb (0x77de5cdb) ntdll.dll + 0x2032f (0x77fa032f) DocumentViewerImpl::SetBounds [d:\builds\seamonkey\mozilla\content\base\src\nsDocumentViewer.cpp, line 1529] Here are some user comments if anyone wants to try to reproduce: MozillaTrunk: (38706924) Comments: Browsing folders on local drive to confirm bug #112736 (38706865) Comments: While browsing folders on local drive to confirm the Bugzilla bug #112736 (38689067) Comments: Open file:/// open some directories by clicking on folder icons change directory by doubleclicking. crash (38636562) Comments: while opening folder on file:///d:... (38633923) Comments: 1. Type e.g. "file:///home" in the URL bar2. Change direcrories double clicking on folder icons3. After a few such steps Mozilla creshes.(This has been happenig from Linux nightly 20011120 approximately.) Mozilla 0.9.6: (38791205) Comments: I tried to navigate to that directory from /. There were about 2000 entries in that directory most ly html files and a couple of .gifs (38756799) Comments: clicked on a directory icon (38734808) Comments: reading ANT documentation (38725192) Comments: just trying to load it along with its XSLT stylesheet (38717452) Comments: I was browsing a directory called exim.html and clicked on the directory itself. (38705344) Comments: Browsing my local filesystem (38680436) Comments: Pasted url (file://foo/bar) into location bar and browsed files on my computer (38666092) Comments: double click on expanded folder then again doble clicked on (now colapsed) same folder...and crash (38644583) Comments: browing local harddrive (38642673) Comments: crashes when trying to look at folders locally for which I do not have permission it did this on a nfs so I tried locally to see if same problem. (38642571) Comments: I use mozilla to browse my hard drive and I wanted to see what happens when I try to look at a nfs for which I do not have permission brower crashes. (38621629) Comments: I was trying to open an html file found within a directory on my hard disk. I was at c:/ I tried to open the subdirectory and mozilla crashed. (38614758) Comments: 1. open mozilla2. open file:/home/user/ in browser window3. click through directory tree by single-clicking on directory icons and thereby opening subview of this directory4. when arrived at target directory double-click on directory icon and (38614758) Comments: thereby try to open the view of this directory in a single windowCRASH (38614587) Comments: double click to directory icon in directory view in browser windowcaused crash (38578983) Comments: Opening a local directory by double-clicking (38536393) URL: Customer Application Form - WIX&APE.doc | (38536393) Comments: hmmm... looking at a file:// directory listing. (38527578) Comments: I was browsing my hard disk at the same time as listening to Realplayer 6. It was opening the windows folder a bit slowly so I started clicking and right-clicking randomly where the files should appear. Then it crashed. - Thanks. (38463281) Comments: double-clicked at directory folder in local dir listing (38431887) Comments: Double left clicked on folder to open subdirectory (38430221) Comments: Communicator crashed while trying to access a directory within a directory in a user account. E.g /home/user/dir/dir/ (38402735) Comments: Double clicked on a folder when in folder file://C: (38376836) Comments: I was browsing my filesystem using Mozilla-0.9.6 then it crashed ...Mozilla-0.9.5 was more stable ....
Keywords: topcrash
Summary: Crash with a simple XUL document [@nsTreeLayout::LazyRowCreator] → Crash with a simple XUL document - M096 & Trunk [@ nsTreeLayout::LazyRowCreator]
Why is the Target Milestone still set at "Future"? If we have a good patch are we going to try to get this into Mozilla 0.9.7?
Comment on attachment 60516 [details] [diff] [review] proposed fix sr=hyatt
Attachment #60516 - Flags: superreview+
go go go
Assignee: hyatt → tingley
accepting and pulling in. hewitt, any chance you can review this?
Status: NEW → ASSIGNED
Target Milestone: Future → mozilla0.9.7
Comment on attachment 60516 [details] [diff] [review] proposed fix I think hewitt would agree with my r= :-). Let's get this in for 0.9.7. /be
Attachment #60516 - Flags: review+
As hyatt said, go strong, check in ASAP. /be
Blocks: 114455
Keywords: mozilla0.9.7+
I'm checking this in as soon as my tree updates.
Fix checked in. Thanks for the quick reviews.
Status: ASSIGNED → RESOLVED
Closed: 24 years ago
Resolution: --- → FIXED
No longer blocks: 114455
With Mozilla 1.0RC1 (build 2002041711) on WinNT4, the browser freeze when viewing my original testcase (no crash). Reopening bug as the testcase is a kind of Deny of Service. BTW, is there a keyword for this category of bugs?
Status: RESOLVED → REOPENED
Resolution: FIXED → ---
This is something entirely different than the previously reported crash. Reclosing this bug and will file a bug for the currently observed hang (which is an infinite series of overflow|underflow reflow events).
Status: REOPENED → RESOLVED
Closed: 24 years ago → 24 years ago
Resolution: --- → FIXED
filed bug 139602 (marking verified; nsTreeLayout.cpp is no more)
.
Status: RESOLVED → VERIFIED
Component: XP Toolkit/Widgets: XUL → XUL
QA Contact: jrgmorrison → xptoolkit.widgets
Crash Signature: [@ nsTreeLayout::LazyRowCreator]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: