wr_dp_new_clip_region tries to make a slice using a nullptr

RESOLVED FIXED in Firefox 55

Status

()

P3
normal
RESOLVED FIXED
2 years ago
2 years ago

People

(Reporter: kats, Assigned: kats)

Tracking

55 Branch
mozilla55
Points:
---

Firefox Tracking Flags

(firefox55 fixed)

Details

(Whiteboard: [gfx-noted])

Attachments

(1 attachment, 1 obsolete attachment)

See bug 1357734 comment 13 for backstory. Any call to DisplayListBuilder::BuildClipRegion(rect, mask) will pass nullptr as the complex clip list pointer down to rust code, which passes that nullptr directly into slice::from_raw_parts [1], which is not allowed per the from_raw_parts documentation.

This is potentially the cause of bug 1357734, although I'm not sure about that yet.

[1] http://searchfox.org/mozilla-central/rev/baf47b352e873d4516d7656186d6d7c7447d3873/gfx/webrender_bindings/src/bindings.rs#1119
https://treeherder.mozilla.org/#/jobs?repo=try&revision=f8d00a9b28d34952d9df5a45f51ccc195d812ef7

^ I wrote the patches based on master originally and pushed to try. I had to rebase onto graphics which was slightly nontrivial. I think it makes more sense to land on graphics.
Comment hidden (mozreview-request)
Comment hidden (mozreview-request)
Whoops, screwed that up. New patches coming.
Comment hidden (mozreview-request)
Comment hidden (mozreview-request)
Comment hidden (mozreview-request)
Attachment #8861532 - Attachment is obsolete: true
Attachment #8861532 - Flags: review?(rhunt)

Comment 10

2 years ago
mozreview-review
Comment on attachment 8861531 [details]
Bug 1359462 - Ensure we don't pass a nullptr to slice::from_raw_parts.

https://reviewboard.mozilla.org/r/133506/#review136404

Thanks!
Attachment #8861531 - Flags: review?(rhunt) → review+

Comment 11

2 years ago
Pushed by kgupta@mozilla.com:
https://hg.mozilla.org/projects/graphics/rev/5fe20b166827
Ensure we don't pass a nullptr to slice::from_raw_parts. r=rhunt
Status: NEW → RESOLVED
Last Resolved: 2 years ago
Resolution: --- → FIXED
https://hg.mozilla.org/mozilla-central/rev/5fe20b166827
status-firefox55: --- → fixed
Target Milestone: --- → mozilla55
You need to log in before you can comment on or make changes to this bug.