Closed Bug 1638791 Opened 6 years ago Closed 5 years ago

Crash in [@ arena_t::DallocSmall | Allocator<T>::free | nsXPCWrappedJS::~nsXPCWrappedJS]

Categories

(Core :: XPConnect, defect, P3)

Unspecified
Windows 10
defect

Tracking

()

RESOLVED WORKSFORME
Tracking Status
firefox-esr68 --- unaffected
firefox76 --- unaffected
firefox77 --- wontfix
firefox78 --- wontfix
firefox79 --- affected

People

(Reporter: gsvelto, Unassigned)

Details

(Keywords: crash)

Crash Data

This bug is for crash report bp-fe749c34-2dde-4325-b833-024860200516.

Top 10 frames of crashing thread:

0 mozglue.dll arena_t::DallocSmall memory/build/mozjemalloc.cpp:3292
1 mozglue.dll static Allocator<MozJemallocBase>::free memory/build/malloc_decls.h:54
2 xul.dll nsXPCWrappedJS::~nsXPCWrappedJS js/xpconnect/src/XPCWrappedJS.cpp:431
3 xul.dll nsXPCWrappedJS::cycleCollection::DeleteCycleCollectable js/xpconnect/src/xpcprivate.h:1567
4 xul.dll nsPurpleBuffer::VisitEntries<SnowWhiteKiller> xpcom/base/nsCycleCollector.cpp:942
5 xul.dll nsCycleCollector_doDeferredDeletionWithBudget xpcom/base/nsCycleCollector.cpp:3889
6 xul.dll AsyncFreeSnowWhite::Run js/xpconnect/src/XPCJSRuntime.cpp:147
7 xul.dll IdleRunnableWrapper::Run xpcom/threads/nsThreadUtils.cpp:344
8 xul.dll nsThread::ProcessNextEvent xpcom/threads/nsThread.cpp:1211
9 xul.dll mozilla::ipc::MessagePump::Run ipc/glue/MessagePump.cpp:87

I'm not sure if this is the right component. This appears to be a regression that started with buildid 20200515093304. We're hitting this assertion: MOZ_DIAGNOSTIC_ASSERT(diff == regind * size). Gian-Carlo you recently changed this code in bug 1553717, could it be related to this?

Flags: needinfo?(gpascutto)

Bug 1553717 didn't change this at all, but of course with more memory allocations being randomized there's certainly a possibility that we're surfacing existing bugs now.

Flags: needinfo?(gpascutto)

I'd guess that this is a signature change. If you search on crash-stats for ~nsXPCWrappedJS, there's some similar looking crashes, including this one which even has the same assertion. bp-5252b7aa-131f-4b55-9d0e-b21840200514

[@ arena_t::DallocSmall | Allocator<T>::free | replace_free | nsXPCWrappedJS::~nsXPCWrappedJS ]

I could believe that something is going wrong in XPCWrappedJS, but I don't see how we can make any progress on this crash.

Crash Signature: [@ arena_t::DallocSmall | Allocator<T>::free | nsXPCWrappedJS::~nsXPCWrappedJS] → [@ arena_t::DallocSmall | Allocator<T>::free | nsXPCWrappedJS::~nsXPCWrappedJS] [@ arena_t::DallocSmall | Allocator<T>::free | replace_free | nsXPCWrappedJS::~nsXPCWrappedJS ]
Component: Memory Allocator → XPConnect

There are similar crash signatures from old Firefox versions, but these particular crash signatures appear to have first appeared in 77.0a1.

P3 until we have STR or crash volume increases.

S2 crash

Severity: -- → S2
Priority: -- → P3

It doesn't look like we're seeing this crash anymore.

Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → WORKSFORME
You need to log in before you can comment on or make changes to this bug.