Closed Bug 1350568 Opened 5 years ago Closed 5 years ago
Crash in Abort | corrupted actor state | mozalloc
_abort | NS _Debug Break | mozilla::ipc::Logic Error | mozilla::net::PStun Addrs Request Parent::Send On Stun Addrs Available
Bug 1350568 - don't dispatch IPC call to StunAddrsRequestChild after content process IPC channel goes away.
59 bytes, text/x-review-board-request
This bug was filed from the Socorro interface and is report bp-03133273-5f54-45d7-8d45-3ea152170324. ============================================================= There is 1 crash in nightly 55 with buildid 20170324030205. In analyzing the backtrace, the regression may have been introduced by patch  to fix bug 1345511.  https://hg.mozilla.org/mozilla-central/rev?node=af9901df3d48f0c683551331507c3c0810e9fc8f
It would appear so, yes. I'll have to find an IPC expert to help me understand what is happening.
It looks to me like there are two lines which can cause this: http://searchfox.org/mozilla-central/source/__GENERATED__/ipc/ipdl/PStunAddrsRequest.cpp#34 Or http://searchfox.org/mozilla-central/source/__GENERATED__/ipc/ipdl/PStunAddrsRequest.cpp#37
Which then points back to here: http://searchfox.org/mozilla-central/source/__GENERATED__/ipc/ipdl/PStunAddrsRequestParent.cpp#57
It is definitely the second, based on this info from the crash report: AdapterVendorID: 0x8086, AdapterDeviceID: 0x0102, AdapterSubsysID: 20178086, AdapterDriverVersion: 22.214.171.12459 FP(D00-L1000-W00001000-T000) DWrite? DWrite+ xpcom_runtime_abort(###!!! ABORT: corrupted actor state: file c:/builds/moz2_slave/m-cen-w32-ntly-000000000000000/build/src/ipc/glue/ProtocolUtils.cpp, line 311) I just don't know what the possible causes are for corrupted actor state. The PStunAddrsRequestParent.cpp file is auto generated from the ipdl file.
From looking at this: http://searchfox.org/mozilla-central/search?q=symbol:F_%3CT_mozilla%3A%3Anet%3A%3APStunAddrsRequestParent%3E_0&redirect=false I'm guessing that the auto generated code assumes each actor can only be used for a single request/response pair once and then has to die. So I would guess it's either: - something tries to re-use an actor, which appears to be not legit - or callbacks are received before the request came in from the client
Crash Signature: [@ Abort | corrupted actor state | mozalloc_abort | NS_DebugBreak | mozilla::ipc::LogicError | mozilla::net::PStunAddrsRequestParent::SendOnStunAddrsAvailable] → [@ Abort | corrupted actor state | mozalloc_abort | NS_DebugBreak | mozilla::ipc::LogicError | mozilla::net::PStunAddrsRequestParent::SendOnStunAddrsAvailable] [@ Abort | __delete__()d actor | mozalloc_abort | Abort | NS_DebugBreak | mozilla::net::PStunA…
Flags: needinfo?(mfroman) → needinfo?(wmccloskey)
I see two problems: 1. The ActorDestroy method doesn't do anything: http://searchfox.org/mozilla-central/rev/7419b368156a6efa24777b21b0e5706be89a9c2f/media/mtransport/ipc/StunAddrsRequestParent.cpp#43 For refcounted actors, it's necessary to set a flag or something that remembers that we're not allowed to send IPC messages anymore. Then you need to check that flag here: http://searchfox.org/mozilla-central/rev/7419b368156a6efa24777b21b0e5706be89a9c2f/media/mtransport/ipc/StunAddrsRequestParent.cpp#68 and avoid sending the message. 2. I don't see anything that keeps |this| alive between the time these runnable are dispatched and when it runs: http://searchfox.org/mozilla-central/rev/7419b368156a6efa24777b21b0e5706be89a9c2f/media/mtransport/ipc/StunAddrsRequestParent.cpp#56 http://searchfox.org/mozilla-central/rev/7419b368156a6efa24777b21b0e5706be89a9c2f/media/mtransport/ipc/StunAddrsRequestParent.cpp#56 I'm not familiar with WrapRunnable though. Maybe it does the right thing? I suspect #2 is causing this crash, but #1 should also be fixed.
Bill, thank you so much for the feedback! I'd guessed at #1 based on a example from DNSRequestParent.cpp, but I had not considered #2. Thank you.
Comment on attachment 8853993 [details] Bug 1350568 - don't dispatch IPC call to StunAddrsRequestChild after content process IPC channel goes away. https://reviewboard.mozilla.org/r/125996/#review128548
Attachment #8853993 - Flags: review?(rjesup) → review+
Pushed by firstname.lastname@example.org: https://hg.mozilla.org/integration/autoland/rev/777453c1b91a don't dispatch IPC call to StunAddrsRequestChild after content process IPC channel goes away. r=jesup
You need to log in before you can comment on or make changes to this bug.