Open Bug 1517028 Opened 2 years ago Updated 4 months ago

Crash [@ mozilla::HTMLEditRules::ReturnInHeader] or [@ mozilla::HTMLEditor::HandleInsertParagraphInHeadingElement ]

Categories

(Core :: DOM: Editor, defect, P3)

defect

Tracking

()

Tracking Status
firefox66 --- affected

People

(Reporter: jkratzer, Unassigned)

References

(Blocks 1 open bug)

Details

(Keywords: crash, testcase)

Crash Data

Attachments

(1 file)

Attached file testcase.html
Testcase found while fuzzing mozilla-central rev 83d06ab87e74.

rax = 0x00007fbfbb96ac46   rdx = 0x0000000000000003
rcx = 0x0000563151b4d948   rbx = 0x00007fbfad4b4000
rsi = 0x00007fbfae070f80   rdi = 0x00007fbfae070f80
rbp = 0x00007ffe302db360   rsp = 0x00007ffe302db250
r8 = 0x0000000000000000    r9 = 0x00000000000000c8
r10 = 0x00007ffe302dadd8   r11 = 0x0000000000000004
r12 = 0x00007fbfad4be280   r13 = 0x0000000080560001
r14 = 0x00007fbfae071080   r15 = 0x00007fbfae070f80
rip = 0x00007fbfb87a9672
OS|Linux|0.0.0 Linux 4.15.0-43-generic #46-Ubuntu SMP Thu Dec 6 14:45:28 UTC 2018 x86_64
CPU|amd64|family 6 model 78 stepping 3|1
GPU|||
Crash|SIGSEGV /SEGV_MAPERR|0x0|0
0|0|libxul.so|mozilla::HTMLEditRules::ReturnInHeader(mozilla::dom::Element&, nsINode&, int)|hg:hg.mozilla.org/mozilla-central:editor/libeditor/HTMLEditRules.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|7663|0x0
0|1|libxul.so|mozilla::HTMLEditRules::WillInsertParagraphSeparator()|hg:hg.mozilla.org/mozilla-central:editor/libeditor/HTMLEditRules.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|1812|0xe
0|2|libxul.so|mozilla::HTMLEditRules::WillDoAction(mozilla::EditSubActionInfo&, bool*, bool*)|hg:hg.mozilla.org/mozilla-central:editor/libeditor/HTMLEditRules.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|682|0x8
0|3|libxul.so|mozilla::HTMLEditor::InsertParagraphSeparatorAsSubAction()|hg:hg.mozilla.org/mozilla-central:editor/libeditor/HTMLEditor.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|1087|0x6
0|4|libxul.so|mozilla::HTMLEditor::InsertParagraphSeparatorAsAction()|hg:hg.mozilla.org/mozilla-central:editor/libeditor/HTMLEditor.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|1064|0x8
0|5|libxul.so|<name omitted>|hg:hg.mozilla.org/mozilla-central:editor/libeditor/EditorCommands.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|1098|0x5
0|6|libxul.so|nsControllerCommandTable::DoCommand(char const*, nsISupports*)|hg:hg.mozilla.org/mozilla-central:dom/commandhandler/nsControllerCommandTable.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|140|0xc
0|7|libxul.so|nsBaseCommandController::DoCommand(char const*)|hg:hg.mozilla.org/mozilla-central:dom/commandhandler/nsBaseCommandController.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|123|0x9
0|8|libxul.so|nsCommandManager::DoCommand(char const*, nsICommandParams*, mozIDOMWindowProxy*)|hg:hg.mozilla.org/mozilla-central:dom/commandhandler/nsCommandManager.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|199|0x9
0|9|libxul.so|nsHTMLDocument::ExecCommand(nsTSubstring<char16_t> const&, bool, nsTSubstring<char16_t> const&, nsIPrincipal&, mozilla::ErrorResult&)|hg:hg.mozilla.org/mozilla-central:dom/html/nsHTMLDocument.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|2813|0xb
0|10|libxul.so|mozilla::dom::HTMLDocument_Binding::execCommand(JSContext*, JS::Handle<JSObject*>, nsHTMLDocument*, JSJitMethodCallArgs const&)|s3:gecko-generated-sources:4b782966054acb7b963adef67bacb5e94fb27bdf71bcb9e8ddd370daf6755c5d2901d3ac2b178621d3b2913ef9cda44f6a319b2975c5327b6f83d2a5912bbe06/dom/bindings/HTMLDocumentBinding.cpp:|619|0x8
0|11|libxul.so|bool mozilla::dom::binding_detail::GenericMethod<mozilla::dom::binding_detail::NormalThisPolicy, mozilla::dom::binding_detail::ThrowExceptions>(JSContext*, unsigned int, JS::Value*)|hg:hg.mozilla.org/mozilla-central:dom/bindings/BindingUtils.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|3062|0x5
0|12|libxul.so|js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct)|hg:hg.mozilla.org/mozilla-central:js/src/vm/Interpreter.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|443|0x6
0|13|libxul.so|Interpret(JSContext*, js::RunState&)|hg:hg.mozilla.org/mozilla-central:js/src/vm/Interpreter.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|594|0x8
0|14|libxul.so|js::RunScript(JSContext*, js::RunState&)|hg:hg.mozilla.org/mozilla-central:js/src/vm/Interpreter.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|423|0xb
0|15|libxul.so|js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct)|hg:hg.mozilla.org/mozilla-central:js/src/vm/Interpreter.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|563|0x8
0|16|libxul.so|<name omitted>|hg:hg.mozilla.org/mozilla-central:js/src/vm/Interpreter.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|606|0x8
0|17|libxul.so|JS::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::HandleValueArray const&, JS::MutableHandle<JS::Value>)|hg:hg.mozilla.org/mozilla-central:js/src/jsapi.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|2649|0xb
0|18|libxul.so|mozilla::dom::EventListener::HandleEvent(JSContext*, JS::Handle<JS::Value>, mozilla::dom::Event&, mozilla::ErrorResult&)|s3:gecko-generated-sources:b504f583ed3111ab416617cd63caa012e7478d0516eb5d3bc3cd43cef007715c1a91854c0528b0ec8e85f6341ccebf73a1b2c32556687ebaf4023e3c38ff4197/dom/bindings/EventListenerBinding.cpp:|52|0xb
0|19|libxul.so|mozilla::EventListenerManager::HandleEventSubType(mozilla::EventListenerManager::Listener*, mozilla::dom::Event*, mozilla::dom::EventTarget*)|s3:gecko-generated-sources:f3d9c01258576daaac3afc4fb3b283652e7f1168abb5287eff6775451ebd0ab6a0e4c8d88d3a67f7147042501bc091c6dfed25b4b8ccf4e4f420897b8d0ba906/dist/include/mozilla/dom/EventListenerBinding.h:|66|0xe
0|20|libxul.so|mozilla::EventListenerManager::HandleEventInternal(nsPresContext*, mozilla::WidgetEvent*, mozilla::dom::Event**, mozilla::dom::EventTarget*, nsEventStatus*, bool)|hg:hg.mozilla.org/mozilla-central:dom/events/EventListenerManager.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|1238|0x12
0|21|libxul.so|mozilla::EventTargetChainItem::HandleEvent(mozilla::EventChainPostVisitor&, mozilla::ELMCreationDetector&)|hg:hg.mozilla.org/mozilla-central:dom/events/EventListenerManager.h:83d06ab87e742c2eb63bce720741c0a222d20f36|350|0xe
0|22|libxul.so|mozilla::EventTargetChainItem::HandleEventTargetChain(nsTArray<mozilla::EventTargetChainItem>&, mozilla::EventChainPostVisitor&, mozilla::EventDispatchingCallback*, mozilla::ELMCreationDetector&)|hg:hg.mozilla.org/mozilla-central:dom/events/EventDispatcher.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|552|0xf
0|23|libxul.so|mozilla::EventDispatcher::Dispatch(nsISupports*, nsPresContext*, mozilla::WidgetEvent*, mozilla::dom::Event*, nsEventStatus*, mozilla::EventDispatchingCallback*, nsTArray<mozilla::dom::EventTarget*>*)|hg:hg.mozilla.org/mozilla-central:dom/events/EventDispatcher.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|1042|0xc
0|24|libxul.so|mozilla::EventDispatcher::DispatchDOMEvent(nsISupports*, mozilla::WidgetEvent*, mozilla::dom::Event*, nsPresContext*, nsEventStatus*)|hg:hg.mozilla.org/mozilla-central:dom/events/EventDispatcher.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|0|0x8
0|25|libxul.so|nsINode::DispatchEvent(mozilla::dom::Event&, mozilla::dom::CallerType, mozilla::ErrorResult&)|hg:hg.mozilla.org/mozilla-central:dom/base/nsINode.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|1029|0x10
0|26|libxul.so|nsContentUtils::DispatchEvent(nsIDocument*, nsISupports*, nsTSubstring<char16_t> const&, mozilla::CanBubble, mozilla::Cancelable, mozilla::Composed, mozilla::Trusted, bool*, mozilla::ChromeOnlyDispatch)|hg:hg.mozilla.org/mozilla-central:dom/base/nsContentUtils.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|4063|0xf
0|27|libxul.so|nsContentUtils::DispatchTrustedEvent(nsIDocument*, nsISupports*, nsTSubstring<char16_t> const&, mozilla::CanBubble, mozilla::Cancelable, mozilla::Composed, bool*)|hg:hg.mozilla.org/mozilla-central:dom/base/nsContentUtils.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|4033|0x10
0|28|libxul.so|nsIDocument::DispatchContentLoadedEvents()|hg:hg.mozilla.org/mozilla-central:dom/base/nsDocument.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|4729|0x25
0|29|libxul.so|mozilla::detail::RunnableMethodImpl<nsIDocument*, void (nsIDocument::*)(), true, (mozilla::RunnableKind)0>::Run()|hg:hg.mozilla.org/mozilla-central:xpcom/threads/nsThreadUtils.h:83d06ab87e742c2eb63bce720741c0a222d20f36|1106|0x17
0|30|libxul.so|mozilla::SchedulerGroup::Runnable::Run()|hg:hg.mozilla.org/mozilla-central:xpcom/threads/SchedulerGroup.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|299|0x6
0|31|libxul.so|nsThread::ProcessNextEvent(bool, bool*)|hg:hg.mozilla.org/mozilla-central:xpcom/threads/nsThread.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|1157|0x6
0|32|libxul.so|NS_ProcessNextEvent(nsIThread*, bool)|hg:hg.mozilla.org/mozilla-central:xpcom/threads/nsThreadUtils.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|468|0xd
0|33|libxul.so|mozilla::ipc::MessagePump::Run(base::MessagePump::Delegate*)|hg:hg.mozilla.org/mozilla-central:ipc/glue/MessagePump.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|88|0xb
0|34|libxul.so|MessageLoop::Run()|hg:hg.mozilla.org/mozilla-central:ipc/chromium/src/base/message_loop.cc:83d06ab87e742c2eb63bce720741c0a222d20f36|314|0x8
0|35|libxul.so|nsBaseAppShell::Run()|hg:hg.mozilla.org/mozilla-central:widget/nsBaseAppShell.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|137|0x8
0|36|libxul.so|XRE_RunAppShell()|hg:hg.mozilla.org/mozilla-central:toolkit/xre/nsEmbedFunctions.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|915|0x6
0|37|libxul.so|MessageLoop::Run()|hg:hg.mozilla.org/mozilla-central:ipc/chromium/src/base/message_loop.cc:83d06ab87e742c2eb63bce720741c0a222d20f36|314|0x8
0|38|libxul.so|XRE_InitChildProcess(int, char**, XREChildData const*)|hg:hg.mozilla.org/mozilla-central:toolkit/xre/nsEmbedFunctions.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|753|0x5
0|39|firefox-bin|main|hg:hg.mozilla.org/mozilla-central:ipc/contentproc/plugin-container.cpp:83d06ab87e742c2eb63bce720741c0a222d20f36|49|0x16
0|40|libc-2.27.so||||0x21b97
0|41|firefox-bin||||0x7aa0
0|42|firefox-bin||||0x78bc
0|43|ld-2.27.so||||0x10733
0|44|libdl-2.27.so||||0x202d80
0|45|libpthread-2.27.so||||0x219bb0
0|46|firefox-bin||||0x78bc
0|47|firefox-bin|_start|||0x29
Flags: in-testsuite?
Crash Signature: [@ mozilla::HTMLEditRules::ReturnInHeader ]
P3 as MOZ_DIAGNOSTIC_ASSERT
Priority: -- → P3
Crash Signature: [@ mozilla::HTMLEditRules::ReturnInHeader ] → [@ mozilla::HTMLEditRules::ReturnInHeader ] [@ mozilla::HTMLEditor::HandleInsertParagraphInHeadingElement ]
Summary: Crash [@ mozilla::HTMLEditRules::ReturnInHeader] → Crash [@ mozilla::HTMLEditRules::ReturnInHeader] or [@ mozilla::HTMLEditor::HandleInsertParagraphInHeadingElement ]
See Also: → 1655508
You need to log in before you can comment on or make changes to this bug.