This bug is for crash report bp-ca403338-e0c7-48c0-b440-3a39d0190815.

Top 10 frames of crashing thread:

0 xul.dll nsContainerFrame::GetSpokenMarkerText layout/generic/nsContainerFrame.cpp:1742
1 xul.dll mozilla::a11y::ENameValueFlag mozilla::a11y::HTMLListBulletAccessible::Name accessible/html/HTMLListAccessible.cpp:131
2 xul.dll void mozilla::a11y::HTMLListBulletAccessible::AppendTextTo accessible/html/HTMLListAccessible.cpp:147
3 xul.dll mozilla::a11y::nsAccUtils::TextLength accessible/base/nsAccUtils.cpp:388
4 xul.dll mozilla::a11y::HyperTextAccessible::GetChildOffset accessible/generic/HyperTextAccessible.cpp:1906
5 xul.dll mozilla::a11y::NotificationController::QueueMutationEvent accessible/base/NotificationController.cpp:207
6 xul.dll mozilla::a11y::TreeMutation::AfterInsertion accessible/base/EventTree.cpp:69
7 xul.dll mozilla::a11y::DocAccessible::ProcessContentInserted accessible/generic/DocAccessible.cpp:1883
8 xul.dll void mozilla::a11y::NotificationController::WillRefresh accessible/base/NotificationController.cpp:741
9 xul.dll void nsRefreshDriver::Tick layout/base/nsRefreshDriver.cpp:1937

This is most likely fallout from landing of bug 1105868. Mats, is this a case of just checking the markerpseudo and marker variables to not be null?

See comment #0 last paragraph.

Marco, if you can figure out to make a crashtest for this would be great.

(This basically addresses the review comments that I missed in
bug 1105868 part 4. My bad.)

Pushed by
Use nsLayoutUtils::GetMarkerFrame() more to avoid manual null-checks.  r=emilio
(In reply to Mats Palmgren (:mats) from comment #3)

Marco, if you can figure out to make a crashtest for this would be great.

Asa encountered this, the above is his crash. Asa, what site were you on, and which AT did you have running, when you encountered this crash?

I can reliably crash at this URL

Accessibility Instantiator UNKNOWN|

