Closed Bug 1513019 Opened 2 years ago Closed 2 years ago

Hit MOZ_CRASH(called `Option::unwrap()` on a `None` value) at libcore/


(Core :: Graphics: WebRender, defect, P3)




Tracking Status
firefox-esr60 --- unaffected
firefox65 --- wontfix
firefox66 --- wontfix
firefox67 --- fixed
firefox68 --- fixed


(Reporter: tsmith, Assigned: gw)


(Blocks 3 open bugs)


(Keywords: assertion, crash, testcase)


(2 files)

Attached file testcase.html
Reduced with m-c:

Hit MOZ_CRASH(called `Option::unwrap()` on a `None` value) at libcore/

#0 MOZ_CrashOOL(char const*, int, char const*) src/obj-firefox/dist/include/mozilla/Assertions.h:314:3
#1 GeckoCrashOOL src/toolkit/xre/nsAppRunner.cpp:5124:3
#2 gkrust_shared::panic_hook::h80f9b4ed5c0796b3 src/toolkit/library/rust/shared/
#3 core::ops::function::Fn::call::hac0477c01f4e8ad0 src/libcore/ops/
#4 std::panicking::rust_panic_with_hook::h0e12cb2fc86d00fa /rustc/da5f414c2c0bfe5198934493f04c676e2b23ff2e/src/libstd/
#5 std::panicking::continue_panic_fmt::h141671b29fe0e27d /rustc/da5f414c2c0bfe5198934493f04c676e2b23ff2e/src/libstd/
#6 rust_begin_unwind /rustc/da5f414c2c0bfe5198934493f04c676e2b23ff2e/src/libstd/
#7 core::panicking::panic_fmt::h429a06507aba9228 /rustc/da5f414c2c0bfe5198934493f04c676e2b23ff2e/src/libcore/
#8 core::panicking::panic::haa57ffd51eb03b56 /rustc/da5f414c2c0bfe5198934493f04c676e2b23ff2e/src/libcore/
#9 _$LT$core..option..Option$LT$T$GT$$GT$::unwrap::h8f28ae9fbab073da src/libcore/
#10 webrender::picture::PicturePrimitive::add_split_plane::hf13e74b4369553cb src/gfx/wr/webrender/src/
#11 webrender::prim_store::PrimitiveStore::prepare_prim_for_render::h83e1a567fc42d62b src/gfx/wr/webrender/src/prim_store/
#12 webrender::prim_store::PrimitiveStore::prepare_primitives::h908e5c4715fcffb9 src/gfx/wr/webrender/src/prim_store/
#13 webrender::prim_store::PrimitiveStore::prepare_prim_for_render::h83e1a567fc42d62b src/gfx/wr/webrender/src/prim_store/
#14 webrender::prim_store::PrimitiveStore::prepare_primitives::h908e5c4715fcffb9 src/gfx/wr/webrender/src/prim_store/
#15 webrender::frame_builder::FrameBuilder::build_layer_screen_rects_and_cull_layers::ha1834e6f5d8a1896 src/gfx/wr/webrender/src/
#16 webrender::frame_builder::FrameBuilder::build::hf51392b57845c8fe src/gfx/wr/webrender/src/
#17 webrender::render_backend::Document::build_frame::habd8b995b33bfbc6 src/gfx/wr/webrender/src/
#18 webrender::render_backend::RenderBackend::update_document::hf81d6f0b29a2b8e1 src/gfx/wr/webrender/src/
#19 webrender::render_backend::RenderBackend::prepare_transaction::h8e33f2ac22571c2f src/gfx/wr/webrender/src/
#20 webrender::render_backend::RenderBackend::process_api_msg::h3d68a9e92dad4805 src/gfx/wr/webrender/src/
#21 webrender::render_backend::RenderBackend::run::h9745523df5a862a0 src/gfx/wr/webrender/src/
#22 webrender::renderer::Renderer::new::_$u7b$$u7b$closure$u7d$$u7d$::hb5a5e44a298f1c68 src/gfx/wr/webrender/src/
#23 std::sys_common::backtrace::__rust_begin_short_backtrace::h52306ce0db85680b src/libstd/sys_common/
#24 std::thread::Builder::spawn::_$u7b$$u7b$closure$u7d$$u7d$::_$u7b$$u7b$closure$u7d$$u7d$::hf190f06e7ae1328c src/libstd/thread/
#25 _$LT$std..panic..AssertUnwindSafe$LT$F$GT$$u20$as$u20$core..ops..function..FnOnce$LT$$LP$$RP$$GT$$GT$::call_once::h943cb4428de85bf7 src/libstd/
#26 std::panicking::try::do_call::h4ce4e739a5dd0632 (.llvm.7691925630118174454) src/libstd/
#27 __rust_maybe_catch_panic /rustc/da5f414c2c0bfe5198934493f04c676e2b23ff2e/src/libpanic_abort/
Flags: in-testsuite?
Blocks: wr-fuzz
Priority: -- → P3

This crash still happens, I just repro'd on the latest macOS nightly. It produced the report at with the useless [@ GeckoCrash] signature. I've filed bug 1544246 to add that frame to the skiplist.

Glenn, since we have a testcase (attached above), could you take a look? The GeckoCrash signature was pretty high on the list of crashes for 67 beta, although there might be multiple different crashes lumped into that.

Flags: needinfo?(gwatson)

This is a fix for crash bug

Ideally I'd get Dzmitry to take a look over this, as I don't know this code too well, but he's on PTO right now. I think what this code tries to do is use a simpler / more accurate method of plane splitting when the transform is simple (e.g. the case of stacked planes on the z-axis). However, the simple path check was also passing for transforms that were failing to produce a reasonable inverted matrix. Instead, we now only run that simple path for matrices that are pure translations.

This fixes the crash and the try run looks good. I think this should be safe to merge, but we should probably wait until Dzmitry can take a look before uplift to beta, if time permits.

Try run looks good:

Flags: needinfo?(gwatson)
Assignee: nobody → gwatson
Pushed by
Fix plane splitting with complex, axis-aligned transforms. r=emilio,kats
Closed: 2 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla68

Comment on attachment 9058185 [details]
Bug 1513019 - Fix plane splitting with complex, axis-aligned transforms.

Beta/Release Uplift Approval Request

  • Feature/Bug causing the regression: None
  • User impact if declined: Crashes when WebRender is enabled, on pages that contain transforms with very large scale values. These are fairly rare, but are one of the top crash bugs in the WebRender release experiment.
  • Is this code covered by automated tests?: Yes
  • Has the fix been verified in Nightly?: Yes
  • Needs manual test from QE?: No
  • If yes, steps to reproduce:
  • List of other uplifts needed: None
  • Risk to taking this patch: Low
  • Why is the change risky/not risky? (and alternatives if risky): It's a small patch that only affects users enrolled in WebRender, and only a code path that is hit on a small number of pages. The patch has been in nightly for a couple days now. The patch itself is very small and easy to back out if any issues are caused.
  • String changes made/needed:
Attachment #9058185 - Flags: approval-mozilla-beta?

Comment on attachment 9058185 [details]
Bug 1513019 - Fix plane splitting with complex, axis-aligned transforms.

Fix for a webrender crash, uplift approved for 67 beta 12, thanks.

Attachment #9058185 - Flags: approval-mozilla-beta? → approval-mozilla-beta+
Flags: qe-verify-
Flags: in-testsuite? → in-testsuite+
Regressions: 1557875
You need to log in before you can comment on or make changes to this bug.