Closed Bug 1521469 Opened 8 months ago Closed 8 months ago

Crash in mozalloc_abort | Abort | NS_DebugBreak | nsDebugImpl::Abort | XPTC__InvokebyIndex

Categories

(Core :: DOM: Security, defect, P1, critical)

Unspecified
Windows 10
defect

Tracking

()

RESOLVED FIXED
mozilla66
Tracking Status
firefox-esr60 --- unaffected
firefox64 --- unaffected
firefox65 --- unaffected
firefox66 --- fixed

People

(Reporter: gsvelto, Assigned: jkt)

References

(Blocks 1 open bug)

Details

(Keywords: crash, regression, Whiteboard: [domsecurity-active])

Crash Data

Attachments

(1 file)

This bug is for crash report bp-985204d4-e43c-4916-a72a-8cfa80190121.

Top 10 frames of crashing thread:

0 mozglue.dll mozalloc_abort memory/mozalloc/mozalloc_abort.cpp:33
1 xul.dll static void Abort xpcom/base/nsDebugImpl.cpp:438
2 xul.dll NS_DebugBreak xpcom/base/nsDebugImpl.cpp:423
3 xul.dll nsDebugImpl::Abort xpcom/base/nsDebugImpl.cpp:133
4 xul.dll XPTC__InvokebyIndex xpcom/reflect/xptcall/md/win32/xptcinvoke_asm_x86_64.asm:97
5  @0x1f7bfd8a3df 
6 xul.dll trunc 
7 xul.dll trunc 
8 xul.dll trunc 
9 xul.dll static bool XPCWrappedNative::CallMethod js/xpconnect/src/XPCWrappedNative.cpp:1153

Hard to say what's going on here since this seem to originate from JS code. There's no useful user comments either.

This seems to have started in the 20190118094042 build.

Pushlog from the previous build is https://hg.mozilla.org/mozilla-central/pushloghtml?fromchange=1db2248f4415&tochange=3aa256c255f6

Looking at the raw dump I could find this string in the stacks:

[Child 1 Main Thread] ###!!! ABORT: file WebNavigationChild.js, line 112

This must be bug 1520862.

Component: General → DOM: Security
Flags: needinfo?(jkt)

I added a patch which should help us debug where this is happening and add more detail. I think we should leave the crash in as it's concerning.

Assignee: nobody → jkt
Flags: needinfo?(jkt)
Priority: -- → P1
Whiteboard: [domsecurity-active]
Keywords: regression
Blocks: 1521876
Status: NEW → ASSIGNED
Pushed by jkingston@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/ac8dff6980b7
Change loadURI crash to only happen in a debug build. r=gsvelto,ckerschb
Status: ASSIGNED → RESOLVED
Closed: 8 months ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla66
You need to log in before you can comment on or make changes to this bug.