Crash in [@ arena_t::DallocSmall | Allocator<T>::free | nsXPCWrappedJS::~nsXPCWrappedJS]
Categories
(Core :: XPConnect, defect, P3)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox-esr68 | --- | unaffected |
| firefox76 | --- | unaffected |
| firefox77 | --- | wontfix |
| firefox78 | --- | wontfix |
| firefox79 | --- | affected |
People
(Reporter: gsvelto, Unassigned)
Details
(Keywords: crash)
Crash Data
This bug is for crash report bp-fe749c34-2dde-4325-b833-024860200516.
Top 10 frames of crashing thread:
0 mozglue.dll arena_t::DallocSmall memory/build/mozjemalloc.cpp:3292
1 mozglue.dll static Allocator<MozJemallocBase>::free memory/build/malloc_decls.h:54
2 xul.dll nsXPCWrappedJS::~nsXPCWrappedJS js/xpconnect/src/XPCWrappedJS.cpp:431
3 xul.dll nsXPCWrappedJS::cycleCollection::DeleteCycleCollectable js/xpconnect/src/xpcprivate.h:1567
4 xul.dll nsPurpleBuffer::VisitEntries<SnowWhiteKiller> xpcom/base/nsCycleCollector.cpp:942
5 xul.dll nsCycleCollector_doDeferredDeletionWithBudget xpcom/base/nsCycleCollector.cpp:3889
6 xul.dll AsyncFreeSnowWhite::Run js/xpconnect/src/XPCJSRuntime.cpp:147
7 xul.dll IdleRunnableWrapper::Run xpcom/threads/nsThreadUtils.cpp:344
8 xul.dll nsThread::ProcessNextEvent xpcom/threads/nsThread.cpp:1211
9 xul.dll mozilla::ipc::MessagePump::Run ipc/glue/MessagePump.cpp:87
I'm not sure if this is the right component. This appears to be a regression that started with buildid 20200515093304. We're hitting this assertion: MOZ_DIAGNOSTIC_ASSERT(diff == regind * size). Gian-Carlo you recently changed this code in bug 1553717, could it be related to this?
Comment 1•6 years ago
|
||
Bug 1553717 didn't change this at all, but of course with more memory allocations being randomized there's certainly a possibility that we're surfacing existing bugs now.
Comment 2•6 years ago
|
||
I'd guess that this is a signature change. If you search on crash-stats for ~nsXPCWrappedJS, there's some similar looking crashes, including this one which even has the same assertion. bp-5252b7aa-131f-4b55-9d0e-b21840200514
[@ arena_t::DallocSmall | Allocator<T>::free | replace_free | nsXPCWrappedJS::~nsXPCWrappedJS ]
Comment 3•6 years ago
|
||
I could believe that something is going wrong in XPCWrappedJS, but I don't see how we can make any progress on this crash.
| Reporter | ||
Comment 4•6 years ago
|
||
There's a few URLs in the crash reports that come up more than once, maybe we could use them to find an STR:
Comment 5•6 years ago
|
||
There are similar crash signatures from old Firefox versions, but these particular crash signatures appear to have first appeared in 77.0a1.
P3 until we have STR or crash volume increases.
S2 crash
Updated•6 years ago
|
Comment 6•5 years ago
|
||
It doesn't look like we're seeing this crash anymore.
Description
•