Closed Bug 133177 Opened 24 years ago Closed 7 years ago

Closing broken inspector crashes [@ nsMenuBarListener::Blur ] with deleted mMenuBarFrame

Categories

(Core :: XUL, defect, P5)

x86
Windows 2000
defect

Tracking

()

RESOLVED WONTFIX

People

(Reporter: timeless, Unassigned)

Details

(Keywords: crash)

Crash Data

cvs build, debug, no wallet, yes calendar (modified + personal classic theme), classic theme loaded navigator, loaded chrome://messenger/content in navigator (got bad result), loaded inspector [tasks>tools>inspector] (got bad result), closed inspector, crash. tail of console: Error reading file jar:resource:///chrome/classic.jar!/skin/classic/communicator/bookmarks/locatio n-hov.gif Error reading file jar:resource:///chrome/classic.jar!/skin/classic/communicator/bookmarks/locatio n-hov.gif WEBSHELL+ = 10 Error reading file jar:resource:///chrome/calendar.jar!/content/calendar/calendarOverlay.xul *** Failed to load overlay chrome://calendar/content/calendarOverlay.xul ###!!! ASSERTION: initial containing block already created: 'nsnull == mInitialContainingBlock', file f:\build\mozilla\layout\html\style\src \nsCSSFrameConstructor.cpp, line 8721 ###!!! ASSERTION: Popup set is already defined! Only 1 allowed.: '!mPopupSetFrame', file f:\build\mozilla\layout\xul\base\src\nsRootBoxFrame .cpp, line 293 ###!!! ASSERTION: node in map twice: '(node->mContent != aNode->mContent) || ((node->mContent == nsnull) && (node->mStyle != aNode->mStyle)) ', file f:\build\mozilla\layout\html\base\src\nsFrameManager.cpp, line 2453 ###!!! ASSERTION: node in map twice: '(node->mContent != aNode->mContent) || ((node->mContent == nsnull) && (node->mStyle != aNode->mStyle)) ', file f:\build\mozilla\layout\html\base\src\nsFrameManager.cpp, line 2453 ###!!! ASSERTION: node in map twice: '(node->mContent != aNode->mContent) || ((node->mContent == nsnull) && (node->mStyle != aNode->mStyle)) ', file f:\build\mozilla\layout\html\base\src\nsFrameManager.cpp, line 2453 ###!!! ASSERTION: node in map twice: '(node->mContent != aNode->mContent) || ((node->mContent == nsnull) && (node->mStyle != aNode->mStyle)) ', file f:\build\mozilla\layout\html\base\src\nsFrameManager.cpp, line 2453 ###!!! ASSERTION: node in map twice: '(node->mContent != aNode->mContent) || ((node->mContent == nsnull) && (node->mStyle != aNode->mStyle)) ', file f:\build\mozilla\layout\html\base\src\nsFrameManager.cpp, line 2453 Warning add child failed!! ###!!! ASSERTION: Bug 119310, perhaps overlayinfo referenced a overlay that doesn't exist: 'mPlaceHolderRequest', file f:\build\mozilla\cont ent\xul\document\src\nsXULDocument.cpp, line 5943 WEBSHELL+ = 11 WEBSHELL+ = 12 WEBSHELL+ = 13 WEBSHELL- = 12 ###!!! ASSERTION: root element not in document: 'doc != nsnull', file f:\build\mozilla\content\xul\templates\src\nsXULContentBuilder.cpp, li ne 1554 WARNING: NS_ENSURE_TRUE(globalObject) failed, file f:\build\mozilla\xpfe\appshell\src\nsWebShellWindow.cpp, line 1066 stack: nsMenuBarListener::Blur(nsMenuBarListener * const 0x06208ec4, nsIDOMEvent * 0x022ed118) line 334 + 15 bytes nsEventListenerManager::HandleEvent(nsEventListenerManager * const 0x060e3998, nsIPresContext * 0x060e1908, nsEvent * 0x0012ec98, nsIDOMEvent * * 0x0012e7a8, nsIDOMEventTarget * 0x060db7d4, unsigned int 7, nsEventStatus * 0x0012ecc0) line 1708 + 41 bytes nsXULDocument::HandleDOMEvent(nsXULDocument * const 0x060db7a8, nsIPresContext * 0x060e1908, nsEvent * 0x0012ec98, nsIDOMEvent * * 0x0012e7a8, unsigned int 1, nsEventStatus * 0x0012ecc0) line 2452 nsEventStateManager::PreHandleEvent(nsEventStateManager * const 0x02e259f0, nsIPresContext * 0x016da788, nsEvent * 0x0012efd0, nsIFrame * 0x02fdba98, nsEventStatus * 0x0012ee50, nsIView * 0x01808e88) line 444 PresShell::HandleEventInternal(nsEvent * 0x0012efd0, nsIView * 0x01808e88, unsigned int 1, nsEventStatus * 0x0012ee50) line 6075 + 43 bytes PresShell::HandleEvent(PresShell * const 0x01813964, nsIView * 0x01808e88, nsGUIEvent * 0x0012efd0, nsEventStatus * 0x0012ee50, int 1, int & 1) line 6004 + 25 bytes nsViewManager::HandleEvent(nsView * 0x01808e88, nsGUIEvent * 0x0012efd0, int 0) line 2064 nsView::HandleEvent(nsViewManager * 0x01808c48, nsGUIEvent * 0x0012efd0, int 0) line 306 nsViewManager::DispatchEvent(nsViewManager * const 0x01808c48, nsGUIEvent * 0x0012efd0, nsEventStatus * 0x0012ef40) line 1870 + 23 bytes HandleEvent(nsGUIEvent * 0x0012efd0) line 83 nsWindow::DispatchEvent(nsWindow * const 0x018135bc, nsGUIEvent * 0x0012efd0, nsEventStatus & nsEventStatus_eIgnore) line 865 + 10 bytes nsWindow::DispatchWindowEvent(nsGUIEvent * 0x0012efd0) line 886 nsWindow::DispatchFocus(unsigned int 105, int 1) line 4902 + 15 bytes nsWindow::ProcessMessage(unsigned int 7, unsigned int 5249374, long 0, long * 0x0012f3a0) line 3733 + 23 bytes nsWindow::WindowProc(HWND__ * 0x0056196e, unsigned int 7, unsigned int 5249374, long 0) line 1130 + 27 bytes USER32! 77e12e98() USER32! 77e139a3() USER32! 77e1395f() NTDLL! 77fa032f() GlobalWindowImpl::Focus(GlobalWindowImpl * const 0x0170cfdc) line 2198 + 25 bytes nsWebShellWindow::HandleEvent(nsGUIEvent * 0x0012f644) line 592 nsWindow::DispatchEvent(nsWindow * const 0x016c4c8c, nsGUIEvent * 0x0012f644, nsEventStatus & nsEventStatus_eIgnore) line 865 + 10 bytes nsWindow::DispatchWindowEvent(nsGUIEvent * 0x0012f644) line 886 nsWindow::DispatchFocus(unsigned int 105, int 1) line 4902 + 15 bytes nsWindow::ProcessMessage(unsigned int 7, unsigned int 6167194, long 0, long * 0x0012fa14) line 3733 + 23 bytes nsWindow::WindowProc(HWND__ * 0x0050195e, unsigned int 7, unsigned int 6167194, long 0) line 1130 + 27 bytes USER32! 77e12e98() USER32! 77e139a3() USER32! 77e1395f() NTDLL! 77fa032f() USER32! 77e14ef0() USER32! 77e12e98() USER32! 77e16a72() USER32! 77e16aee() nsWindow::WindowProc(HWND__ * 0x0050195e, unsigned int 6, unsigned int 1, long 6167194) line 1137 + 31 bytes USER32! 77e12e98() USER32! 77e139a3() USER32! 77e1395f() NTDLL! 77fa032f() nsWindow::~nsWindow() line 691 nsWindow::`scalar deleting destructor'() + 15 bytes nsWindow::Release(nsWindow * const 0x060cd854) line 557 + 174 bytes nsCOMPtr<nsISupports>::~nsCOMPtr<nsISupports>() line 733 nsWindow::WindowProc(HWND__ * 0x005e1a9a, unsigned int 274, unsigned int 61536, long 0) line 1137 + 42 bytes USER32! 77e12e98() USER32! 77e130e0() USER32! 77e15824() nsAppShellService::Run(nsAppShellService * const 0x016c5698) line 309 main1(int 3, char * * 0x003043a0, nsISupports * 0x00000000) line 1350 + 32 bytes main(int 3, char * * 0x003043a0) line 1698 + 37 bytes mainCRTStartup() line 338 + 17 bytes KERNEL32! 77e97d08() - mMenuBarFrame 0x061ffa2c |+ nsBoxFrame {...} |+ nsIMenuParent {...} | mRefCnt 3722304989 | _mOwningThread 0xdddddddd |+ mMenuBarListener 0xdddddddd |+ mKeyboardNavigator 0xdddddddd | mIsActive -572662307 |+ mCurrentMenu 0xdddddddd |+ mTarget 0xdddddddd \+ mPresContext 0xdddddddd nsMenuBarListener::Blur(nsIDOMEvent* aEvent) { if (!mMenuBarFrame->IsOpen() && mMenuBarFrame->IsActive()) { // ^ crash dereferencing mMenuBarFrame ...
i'll skip the standard waffle given the reporter. :) trying to kill old UNCOs - is this crash reproducible or likely to be a problem? if not, maybe you'd like to mark this WFM? thanks.
it's probably still a valid bug, eventually someone will run across this again and i'll point them to my output. if you're interested in working on this bug, it should be as simple as hunting for all delete/free's of mMenuBarFrame and making sure that it is zero'd or that its parent is destroyed after it is deleted/freed
Keywords: crash
WFM using a 20031220 Linux CVS build.
unable to confirm
Assignee: saari → nobody
QA Contact: shrir → xptoolkit.xul
Summary: Closing broken inspector crashes @nsMenuBarListener::Blur with deleted mMenuBarFrame → Closing broken inspector crashes [ @ nsMenuBarListener::Blur ] with deleted mMenuBarFrame
Status: UNCONFIRMED → NEW
Ever confirmed: true
Priority: -- → P5
Component: XP Toolkit/Widgets: XUL → XUL
QA Contact: xptoolkit.xul → xptoolkit.widgets
Summary: Closing broken inspector crashes [ @ nsMenuBarListener::Blur ] with deleted mMenuBarFrame → Closing broken inspector crashes [@ nsMenuBarListener::Blur ] with deleted mMenuBarFrame
Crash Signature: [@ nsMenuBarListener::Blur ]
There are 2 crashes over the past 4 weeks in nsMenuBarListener::Blur. Is this the same crash? Last comments imply the original crash disappeared.
Closing because no crashes reported since 12 weeks
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.