Open Bug 1597215 Opened 2 months ago Updated 1 month ago

Crash in [@ mozilla::dom::WindowGlobalChild::RecvLoadURIInChild]


(Core :: DOM: Window and Location, defect, P2)




Fission Milestone M5


(Reporter: gsvelto, Unassigned)


(Blocks 1 open bug)


(Keywords: crash, testcase-wanted)

Crash Data

This bug is for crash report bp-f4eaa5dd-e700-42f2-8c90-0fe800191116.

Top 10 frames of crashing thread:

0 mozilla::dom::WindowGlobalChild::RecvLoadURIInChild dom/ipc/WindowGlobalChild.cpp:240
1 mozilla::dom::PWindowGlobalChild::OnMessageReceived ipc/ipdl/PWindowGlobalChild.cpp:675
2 mozilla::dom::PContentChild::OnMessageReceived ipc/ipdl/PContentChild.cpp:8167
3 mozilla::ipc::MessageChannel::DispatchMessage ipc/glue/MessageChannel.cpp:2208
4 mozilla::ipc::MessageChannel::RunMessage ipc/glue/MessageChannel.cpp:1972
5 mozilla::ipc::MessageChannel::MessageTask::Run ipc/glue/MessageChannel.cpp:2003
6 mozilla::SchedulerGroup::Runnable::Run xpcom/threads/SchedulerGroup.cpp:295
7 nsThread::ProcessNextEvent xpcom/threads/nsThread.cpp:1250
8 <name omitted> xpcom/threads/nsThreadUtils.cpp:486
9 mozilla::ipc::MessagePump::Run ipc/glue/MessagePump.cpp:88

This is a NULL pointer dereference happening across all three platforms with Fission enabled.

Component: DOM: Core & HTML → DOM: Window and Location
Fission Milestone: --- → M5
Priority: -- → P2
