Closed Bug 1628120 Opened 1 year ago Closed 1 year ago

Intermittent GECKO(11228) | SUMMARY: AddressSanitizer: heap-use-after-free z:\build\build\src\xpcom\threads\SchedulerGroup.cpp:86 in mozilla::SchedulerGroup::LabeledDispatch

Categories

(Core :: DOM: Navigation, defect, P1)

defect

Tracking

()

RESOLVED FIXED
mozilla77
Tracking Status
firefox-esr68 --- unaffected
firefox74 --- unaffected
firefox75 --- unaffected
firefox76 --- unaffected
firefox77 + fixed

People

(Reporter: intermittent-bug-filer, Assigned: farre)

References

(Regression)

Details

(4 keywords, Whiteboard: [post-critsmash-triage])

Crash Data

Attachments

(1 file)

Filed by: rmaries [at] mozilla.com
Parsed log: https://treeherder.mozilla.org/logviewer.html#?job_id=296677860&repo=autoland
Full log: https://firefox-ci-tc.services.mozilla.com/api/queue/v1/task/UeqS2swmTZGAwjpYbZv1Fg/runs/0/artifacts/public/logs/live_backing.log


[task 2020-04-07T21:05:06.725Z] 21:05:06 INFO - TEST-START | security/manager/ssl/tests/mochitest/mixedcontent/test_cssBefore1.html
[task 2020-04-07T21:05:06.735Z] 21:05:06 INFO - GECKO(11228) | hostRecordType: 0
[task 2020-04-07T21:05:06.842Z] 21:05:06 INFO - GECKO(11228) | hostRecordType: 0
[task 2020-04-07T21:05:07.033Z] 21:05:07 INFO - GECKO(11228) | hostRecordType: 0
[task 2020-04-07T21:05:07.236Z] 21:05:07 INFO - GECKO(11228) | JavaScript error: https://example.com/tests/SimpleTest/SimpleTest.js, line 66: SecurityError: Permission denied to access property "TestRunner" on cross-origin object
[task 2020-04-07T21:05:07.275Z] 21:05:07 INFO - GECKO(11228) | =================================================================
[task 2020-04-07T21:05:07.275Z] 21:05:07 ERROR - GECKO(11228) | ==2020==ERROR: AddressSanitizer: heap-use-after-free on address 0x12d28003e4e0 at pc 0x7ffb5da6c5f6 bp 0x00ddedafde60 sp 0x00ddedafdea8
[task 2020-04-07T21:05:07.275Z] 21:05:07 INFO - GECKO(11228) | WRITE of size 8 at 0x12d28003e4e0 thread T36
[task 2020-04-07T21:05:07.319Z] 21:05:07 INFO - GECKO(11228) | ==2020==WARNING: Failed to use and restart external symbolizer!
[task 2020-04-07T21:05:07.622Z] 21:05:07 INFO - GECKO(11228) | JavaScript error: https://example.com/tests/SimpleTest/SimpleTest.js, line 66: SecurityError: Permission denied to access property "TestRunner" on cross-origin object
[task 2020-04-07T21:05:08.173Z] 21:05:08 INFO - GECKO(11228) | #35 0x7ffbac5e3033 in BaseThreadInitThunk+0x13 (C:\Windows\System32\KERNEL32.DLL+0x180013033)
[task 2020-04-07T21:05:08.175Z] 21:05:08 INFO - GECKO(11228) | #36 0x7ffbae9b1460 in RtlUserThreadStart+0x20 (C:\Windows\SYSTEM32\ntdll.dll+0x180071460)
[task 2020-04-07T21:05:08.175Z] 21:05:08 INFO - GECKO(11228) | SUMMARY: AddressSanitizer: heap-use-after-free z:\build\build\src\xpcom\threads\SchedulerGroup.cpp:86 in mozilla::SchedulerGroup::LabeledDispatch
[task 2020-04-07T21:05:08.175Z] 21:05:08 INFO - GECKO(11228) | Shadow bytes around the buggy address:
[task 2020-04-07T21:05:08.176Z] 21:05:08 INFO - GECKO(11228) | 0x0510d0007c40: fa fa fa fa fa fa fa fa fd fd fd fd fd fd fd fd
[task 2020-04-07T21:05:08.176Z] 21:05:08 INFO - GECKO(11228) | 0x0510d0007c50: fd fd fd fd fd fd fd fd fd fd fd fd fa fa fa fa

Based on the stack traces in the log, I think this belongs somewhere in DOM.

Component: Security: PSM → DOM: Core & HTML
Priority: P5 → --
Group: core-security

Looks like a regression from bug 1620594. Can you please take a look, Andreas? Thanks.

[Tracking Requested - why for this release]: sec-high regression

Group: core-security → dom-core-security
Component: DOM: Core & HTML → DOM: Navigation
Flags: needinfo?(afarre)
Regressed by: 1620594
Priority: -- → P1
Duplicate of this bug: 1628781
Duplicate of this bug: 1628623
Duplicate of this bug: 1628935
Assignee: nobody → afarre
Flags: needinfo?(afarre)
Duplicate of this bug: 1629207
Group: dom-core-security → core-security-release
Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla77
Duplicate of this bug: 1630296
Duplicate of this bug: 1628780
Crash Signature: [@ mozilla::PerformanceCounterState::RunnableWillRun(mozilla::PerformanceCounter*, mozilla::TimeStamp, bool)]
Flags: qe-verify-
Whiteboard: [post-critsmash-triage]
Duplicate of this bug: 1629073
Crash Signature: [@ mozilla::PerformanceCounterState::RunnableWillRun(mozilla::PerformanceCounter*, mozilla::TimeStamp, bool)] → [@ mozilla::PerformanceCounterState::RunnableWillRun(mozilla::PerformanceCounter*, mozilla::TimeStamp, bool)] [@ RefPtr<mozilla::PerformanceCounter>::assign_with_AddRef(mozilla::PerformanceCounter*)]
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.