Closed
Bug 1507587
Opened 7 years ago
Closed 7 years ago
AddressSanitizer: attempting to call malloc_usable_size() for pointer which is not owned: 0x11a796a0aa38 via [@ mozilla::dom::ContentBlockingLog::AddSizeOfExcludingThis]
Categories
(Core :: DOM: Core & HTML, defect)
Tracking
()
RESOLVED
DUPLICATE
of bug 1508527
| Tracking | Status | |
|---|---|---|
| firefox65 | --- | fixed |
People
(Reporter: decoder, Unassigned)
Details
(Keywords: crash, regression, Whiteboard: [adv-main65-])
Attachments
(1 file)
|
5.84 KB,
text/plain
|
Details |
The attached crash information was submitted via the ASan Nightly Reporter on mozilla-central-asan-nightly revision 65.0a1-20181112220107-https://hg.mozilla.org/mozilla-central/rev/05331fb8f5338974b913217bc67815df25a32e86.
For detailed crash information, see attachment.
| Reporter | ||
Comment 1•7 years ago
|
||
| Reporter | ||
Comment 2•7 years ago
|
||
Randell, this was submitted by your ASan Nightly instance at Thu, 15 Nov 2018 14:53:25 +0000. Any idea what was going on? This looks like a corrupted pointer of some sort.
Flags: needinfo?(rjesup)
Comment 3•7 years ago
|
||
Ehsan, any ideas? It looked like you worked on this memory reporter recently. I think the most common cause of this is passing stack allocated memory to the mallocSizeOf method.
Group: core-security → dom-core-security
Flags: needinfo?(ehsan)
Comment 4•7 years ago
|
||
Nothing specific, though it had been under memory pressure earlier (and I may have doing about:memory on it - I had previously done Minimize twice with no problem.) It was a content process that had been using ~6GB/4.5 resident (thanks, WashingtonPost.com) before I killed that tab at fault. Resident memory had dropped to ~1.5G; total was still 5G (last time I looked before it crashed; it may have gone lower over time).
mccr8's idea seems plausible
Flags: needinfo?(rjesup)
Comment 5•7 years ago
|
||
I think my patch in bug 1508527 fixes this. Another patch of mind ended up hitting this on CI today so I fixed the bug before seeing this ping. :-)
Status: NEW → RESOLVED
Closed: 7 years ago
Flags: needinfo?(ehsan)
Resolution: --- → DUPLICATE
Comment 6•6 years ago
|
||
Fixed in 65 in bug 1508527.
Updated•6 years ago
|
Whiteboard: [adv-main65-]
| Assignee | ||
Updated•6 years ago
|
Component: DOM → DOM: Core & HTML
Updated•5 years ago
|
Group: dom-core-security
You need to log in
before you can comment on or make changes to this bug.
Description
•