Closed Bug 1540732 Opened 6 years ago Closed 6 years ago

Assertion failure: ManagesState(aState) (Unexpected state), at /builds/worker/workspace/build/src/dom/events/EventStateManager.cpp:5246

Categories

(Core :: Layout, defect)

defect
Not set
normal

Tracking

()

RESOLVED FIXED
mozilla68
Tracking Status
firefox-esr60 --- wontfix
firefox66 --- wontfix
firefox67 --- wontfix
firefox68 --- fixed

People

(Reporter: jkratzer, Assigned: emilio)

References

(Blocks 1 open bug)

Details

(Keywords: assertion, testcase, Whiteboard: [fuzzblocker])

Attachments

(2 files)

Attached file testcase.html

Testcase found while fuzzing mozilla-central rev a5a5ddfb5178.

Assertion failure: ManagesState(aState) (Unexpected state), at /builds/worker/workspace/build/src/dom/events/EventStateManager.cpp:5246

rax = 0x000055faacce1e20 rdx = 0x0000000000000000
rcx = 0x00007fd674db74f0 rbx = 0x00007ffec97069c0
rsi = 0x00007fd67fe498b0 rdi = 0x00007fd67fe48680
rbp = 0x00007ffec97068f0 rsp = 0x00007ffec9706880
r8 = 0x00007fd67fe498b0 r9 = 0x00007fd680fa6740
r10 = 0x0000000000000000 r11 = 0x0000000000000000
r12 = 0x00007ffec9706900 r13 = 0xffffffff80000000
r14 = 0x0000000000000001 r15 = 0x00007ffec9706998
rip = 0x00007fd670d16f0e
OS|Linux|0.0.0 Linux 4.18.0-16-generic #17~18.04.1-Ubuntu SMP Tue Feb 12 13:35:51 UTC 2019 x86_64
CPU|amd64|family 6 model 94 stepping 3|1
GPU|||
Crash|SIGSEGV /SEGV_MAPERR|0x0|0
0|0|libxul.so|mozilla::EventStateManager::SetContentState(nsIContent*, mozilla::EventStates)|hg:hg.mozilla.org/mozilla-central:dom/events/EventStateManager.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|5246|0x0
0|1|libxul.so|mozilla::dom::InspectorUtils::RemoveContentState(mozilla::dom::GlobalObject&, mozilla::dom::Element&, unsigned long, bool, mozilla::ErrorResult&)|hg:hg.mozilla.org/mozilla-central:layout/inspector/InspectorUtils.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|570|0x15
0|2|libxul.so|mozilla::dom::InspectorUtils_Binding::removeContentState|s3:gecko-generated-sources:7d3786651653ff7f55968f7e821fd96b972e2bfe9eacad3f01187a31cba71629e5c54da6c0355dfbe7007cabf358728c2d8540cf424252457ffc41a13752965b/dom/bindings/InspectorUtilsBinding.cpp:|3988|0x18
0|3|libxul.so|CallJSNative(JSContext*, bool ()(JSContext, unsigned int, JS::Value*), JS::CallArgs const&)|hg:hg.mozilla.org/mozilla-central:js/src/vm/Interpreter.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|442|0x6
0|4|libxul.so|js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct)|hg:hg.mozilla.org/mozilla-central:js/src/vm/Interpreter.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|534|0x12
0|5|libxul.so|InternalCall|hg:hg.mozilla.org/mozilla-central:js/src/vm/Interpreter.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|589|0xd
0|6|libxul.so|Interpret|hg:hg.mozilla.org/mozilla-central:js/src/vm/Interpreter.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|593|0xf
0|7|libxul.so|js::RunScript(JSContext*, js::RunState&)|hg:hg.mozilla.org/mozilla-central:js/src/vm/Interpreter.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|422|0xb
0|8|libxul.so|js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct)|hg:hg.mozilla.org/mozilla-central:js/src/vm/Interpreter.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|562|0xf
0|9|libxul.so|InternalCall|hg:hg.mozilla.org/mozilla-central:js/src/vm/Interpreter.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|589|0xd
0|10|libxul.so|js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>)|hg:hg.mozilla.org/mozilla-central:js/src/vm/Interpreter.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|605|0x5
0|11|libxul.so|JS::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::HandleValueArray const&, JS::MutableHandle<JS::Value>)|hg:hg.mozilla.org/mozilla-central:js/src/jsapi.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|2621|0x1c
0|12|libxul.so|mozilla::dom::EventListener::HandleEvent(JSContext*, JS::Handle<JS::Value>, mozilla::dom::Event&, mozilla::ErrorResult&)|s3:gecko-generated-sources:e009e0a620f59be9f7222e1a55363534d06e5c1dbc04f6806a7e22fdd1b3605bc718f84fa3d329b26bd6e80e748ec27e8716e82c4ac608b3311299526e72dde5/dom/bindings/EventListenerBinding.cpp:|52|0x5
0|13|libxul.so|void mozilla::dom::EventListener::HandleEvent<mozilla::dom::EventTarget*>(mozilla::dom::EventTarget* const&, mozilla::dom::Event&, mozilla::ErrorResult&, char const*, mozilla::dom::CallbackObject::ExceptionHandling, JS::Realm*)|s3:gecko-generated-sources:f3d9c01258576daaac3afc4fb3b283652e7f1168abb5287eff6775451ebd0ab6a0e4c8d88d3a67f7147042501bc091c6dfed25b4b8ccf4e4f420897b8d0ba906/dist/include/mozilla/dom/EventListenerBinding.h:|66|0x1c
0|14|libxul.so|mozilla::EventListenerManager::HandleEventSubType(mozilla::EventListenerManager::Listener*, mozilla::dom::Event*, mozilla::dom::EventTarget*)|hg:hg.mozilla.org/mozilla-central:dom/events/EventListenerManager.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|1040|0x1e
0|15|libxul.so|mozilla::EventListenerManager::HandleEventInternal(nsPresContext*, mozilla::WidgetEvent*, mozilla::dom::Event**, mozilla::dom::EventTarget*, nsEventStatus*, bool)|hg:hg.mozilla.org/mozilla-central:dom/events/EventListenerManager.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|1240|0x19
0|16|libxul.so|mozilla::EventTargetChainItem::HandleEvent(mozilla::EventChainPostVisitor&, mozilla::ELMCreationDetector&)|hg:hg.mozilla.org/mozilla-central:dom/events/EventListenerManager.h:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|356|0x6
0|17|libxul.so|mozilla::EventTargetChainItem::HandleEventTargetChain(nsTArray<mozilla::EventTargetChainItem>&, mozilla::EventChainPostVisitor&, mozilla::EventDispatchingCallback*, mozilla::ELMCreationDetector&)|hg:hg.mozilla.org/mozilla-central:dom/events/EventDispatcher.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|553|0x12
0|18|libxul.so|mozilla::EventDispatcher::Dispatch(nsISupports*, nsPresContext*, mozilla::WidgetEvent*, mozilla::dom::Event*, nsEventStatus*, mozilla::EventDispatchingCallback*, nsTArray<mozilla::dom::EventTarget*>)|hg:hg.mozilla.org/mozilla-central:dom/events/EventDispatcher.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|1049|0x1a
0|19|libxul.so|nsDocumentViewer::LoadComplete(nsresult)|hg:hg.mozilla.org/mozilla-central:layout/base/nsDocumentViewer.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|1102|0x25
0|20|libxul.so|nsDocShell::EndPageLoad(nsIWebProgress
, nsIChannel*, nsresult)|hg:hg.mozilla.org/mozilla-central:docshell/base/nsDocShell.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|6596|0x18
0|21|libxul.so|nsDocShell::OnStateChange(nsIWebProgress*, nsIRequest*, unsigned int, nsresult)|hg:hg.mozilla.org/mozilla-central:docshell/base/nsDocShell.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|6397|0x18
0|22|libxul.so|nsDocLoader::DoFireOnStateChange(nsIWebProgress*, nsIRequest*, int&, nsresult)|hg:hg.mozilla.org/mozilla-central:uriloader/base/nsDocLoader.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|1313|0x2b
0|23|libxul.so|nsDocLoader::doStopDocumentLoad(nsIRequest*, nsresult)|hg:hg.mozilla.org/mozilla-central:uriloader/base/nsDocLoader.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|872|0x22
0|24|libxul.so|nsDocLoader::DocLoaderIsEmpty(bool)|hg:hg.mozilla.org/mozilla-central:uriloader/base/nsDocLoader.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|710|0x15
0|25|libxul.so|nsDocLoader::OnStopRequest(nsIRequest*, nsresult)|hg:hg.mozilla.org/mozilla-central:uriloader/base/nsDocLoader.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|598|0x16
0|26|libxul.so|mozilla::net::nsLoadGroup::RemoveRequest(nsIRequest*, nsISupports*, nsresult)|hg:hg.mozilla.org/mozilla-central:netwerk/base/nsLoadGroup.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|568|0x17
0|27|libxul.so|mozilla::dom::Document::DoUnblockOnload()|hg:hg.mozilla.org/mozilla-central:dom/base/Document.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|7762|0x20
0|28|libxul.so|mozilla::dom::Document::UnblockOnload(bool)|hg:hg.mozilla.org/mozilla-central:dom/base/Document.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|7694|0x8
0|29|libxul.so|mozilla::dom::Document::DispatchContentLoadedEvents()|hg:hg.mozilla.org/mozilla-central:dom/base/Document.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|4818|0xd
0|30|libxul.so|mozilla::detail::RunnableMethodImpl<mozilla::dom::Document*, void (mozilla::dom::Document::)(), true, (mozilla::RunnableKind)0>::Run()|hg:hg.mozilla.org/mozilla-central:xpcom/threads/nsThreadUtils.h:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|1122|0x13
0|31|libxul.so|mozilla::SchedulerGroup::Runnable::Run()|hg:hg.mozilla.org/mozilla-central:xpcom/threads/SchedulerGroup.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|295|0x15
0|32|libxul.so|nsThread::ProcessNextEvent(bool, bool
)|hg:hg.mozilla.org/mozilla-central:xpcom/threads/nsThread.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|1180|0x15
0|33|libxul.so|NS_ProcessNextEvent(nsIThread*, bool)|hg:hg.mozilla.org/mozilla-central:xpcom/threads/nsThreadUtils.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|482|0x11
0|34|libxul.so|mozilla::ipc::MessagePump::Run(base::MessagePump::Delegate*)|hg:hg.mozilla.org/mozilla-central:ipc/glue/MessagePump.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|88|0xa
0|35|libxul.so|MessageLoop::RunInternal()|hg:hg.mozilla.org/mozilla-central:ipc/chromium/src/base/message_loop.cc:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|315|0x17
0|36|libxul.so|MessageLoop::Run()|hg:hg.mozilla.org/mozilla-central:ipc/chromium/src/base/message_loop.cc:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|308|0x8
0|37|libxul.so|nsBaseAppShell::Run()|hg:hg.mozilla.org/mozilla-central:widget/nsBaseAppShell.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|137|0xd
0|38|libxul.so|XRE_RunAppShell()|hg:hg.mozilla.org/mozilla-central:toolkit/xre/nsEmbedFunctions.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|924|0x11
0|39|libxul.so|mozilla::ipc::MessagePumpForChildProcess::Run(base::MessagePump::Delegate*)|hg:hg.mozilla.org/mozilla-central:ipc/glue/MessagePump.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|238|0x5
0|40|libxul.so|MessageLoop::RunInternal()|hg:hg.mozilla.org/mozilla-central:ipc/chromium/src/base/message_loop.cc:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|315|0x17
0|41|libxul.so|MessageLoop::Run()|hg:hg.mozilla.org/mozilla-central:ipc/chromium/src/base/message_loop.cc:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|308|0x8
0|42|libxul.so|XRE_InitChildProcess(int, char**, XREChildData const*)|hg:hg.mozilla.org/mozilla-central:toolkit/xre/nsEmbedFunctions.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|762|0xc
0|43|firefox-bin|content_process_main(mozilla::Bootstrap*, int, char**)|hg:hg.mozilla.org/mozilla-central:ipc/contentproc/plugin-container.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|56|0x14
0|44|firefox-bin|main|hg:hg.mozilla.org/mozilla-central:browser/app/nsBrowserApp.cpp:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|263|0x11
0|45|libc-2.27.so||||0x21b97
0|46|firefox-bin|MOZ_ReportCrash|hg:hg.mozilla.org/mozilla-central:mfbt/Assertions.h:a5a5ddfb5178f8a2b30d186d3cf478da38f324ba|184|0x5

Flags: in-testsuite?
Whiteboard: [fuzzblocker]

Moving to Core::Layout as I don't think Devtools is well positioned to fix this. But please let me know if this should go to another component.

Component: Inspector: Layout → Layout
Product: DevTools → Core

Patrick, feel free to ni? me in inspectorutils fuzzer bugs. (ni? just to ensure you see it)

Assignee: nobody → emilio
Flags: needinfo?(pbrosset)

Same as bug 1538732, but I didn't know this api existed at all.

Curious, why are we fuzzing internal APIs?

(In reply to Olli Pettay [:smaug] from comment #4)

Curious, why are we fuzzing internal APIs?

Because a bunch of them trigger a lot of special code in the style system, like EnsureSafeToHandOutCSSRules and such.

Pushed by ealvarez@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/52d0c2bfe4ac Validate input in InspectorUtils.removeContentState as well. r=smaug
Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla68

Thank you Emilio.

Flags: needinfo?(pbrosset)
Flags: in-testsuite? → in-testsuite+
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: