Closed Bug 1523589 Opened 7 years ago Closed 5 years ago

Invalid write address in webrender::display_list_flattener::DisplayListFlattener::flatten_item

Categories

(Core :: Graphics: WebRender, defect, P3)

Unspecified
Windows 10
defect

Tracking

()

RESOLVED WORKSFORME
Tracking Status
firefox67 --- affected
firefox68 --- affected

People

(Reporter: nical, Unassigned)

References

Details

Crash Data

A very "un-rusty" bunch of invalid writes with addresses like 0x74b3, 0x2473, 0x02, 0x03, etc. Low volume.

I see some similar signatures on nightly - https://bit.ly/2GSTfNI.

Crash Signature: [@ webrender::display_list_flattener::DisplayListFlattener::flatten_item ] → [@ webrender::display_list_flattener::DisplayListFlattener::flatten_item ] [@ core::option::expect_failed | std::collections::hash::map::{{impl}}::index<T> | webrender::display_list_flattener::DisplayListFlattener::flatten_item]

Adding another recent signature in nightly - all youtube URLs, and all Win 10.

Crash Signature: [@ webrender::display_list_flattener::DisplayListFlattener::flatten_item ] [@ core::option::expect_failed | std::collections::hash::map::{{impl}}::index<T> | webrender::display_list_flattener::DisplayListFlattener::flatten_item] → [@ webrender::display_list_flattener::DisplayListFlattener::flatten_item ] [@ core::option::expect_failed | std::collections::hash::map::{{impl}}::index<T> | webrender::display_list_flattener::DisplayListFlattener::flatten_item] [@ core::option::expect_…
OS: Unspecified → Windows 10

Adding another recent signature in nightly - all youtube URLs, and all Win 10.

This new signature looks more easily actionable and likely the result of a different problem so I moved it to bug 1551201.

Crash Signature: [@ webrender::display_list_flattener::DisplayListFlattener::flatten_item ] [@ core::option::expect_failed | std::collections::hash::map::{{impl}}::index<T> | webrender::display_list_flattener::DisplayListFlattener::flatten_item] [@ core::option::expect_… → [@ webrender::display_list_flattener::DisplayListFlattener::flatten_item ]
Type: enhancement → defect

Closing because no crashes reported for 12 weeks.

Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → WORKSFORME
You need to log in before you can comment on or make changes to this bug.