Closed Bug 1643517 Opened 6 years ago Closed 6 years ago

Crash in [@ InvalidArrayIndex_CRASH | mozilla::layers::InputQueue::ProcessQueue]

Categories

(Core :: Panning and Zooming, defect)

defect

Tracking

()

RESOLVED DUPLICATE of bug 1643884
Tracking Status
firefox-esr68 --- unaffected
firefox77 --- unaffected
firefox78 --- fixed
firefox79 --- fixed

People

(Reporter: mccr8, Unassigned)

References

(Regression)

Details

(Keywords: crash, regression)

Crash Data

This bug is for crash report bp-b61945a3-1d11-461a-9562-dceb50200603.

Top 10 frames of crashing thread:

0 XUL InvalidArrayIndex_CRASH xpcom/ds/nsTArray.cpp:27
1 XUL mozilla::layers::InputQueue::ProcessQueue gfx/layers/apz/src/InputQueue.cpp
2 XUL mozilla::layers::InputQueue::ReceiveInputEvent gfx/layers/apz/src/InputQueue.cpp:57
3 XUL mozilla::layers::APZCTreeManager::ReceiveInputEvent gfx/layers/apz/src/APZCTreeManager.cpp:1727
4 XUL non-virtual thunk to mozilla::layers::APZCTreeManager::ReceiveInputEvent gfx/layers/apz/src/APZCTreeManager.cpp
5 XUL nsChildView::DispatchAPZInputEvent widget/cocoa/nsChildView.mm:2063
6 XUL -[ChildView magnifyWithEvent:] widget/cocoa/nsChildView.mm:2848
7 AppKit -[NSWindow _reallySendEvent:isDelayedEvent:] 
8 AppKit -[NSWindow sendEvent:] 
9 XUL -[ToolbarWindow sendEvent:] widget/cocoa/nsCocoaWindow.mm:3732

4 crashes with this signature, starting with the 20200601093812 build. The crash reason for them all is ElementAt(aIndex = 0, aLength = 0), so something is trying to do something with an empty queue it looks like. It looks like the crashes are all happening in InputQueue::ReceivePinchGestureInput, but there's no line number for the actual crash.

Maybe this is related to "desktop zooming"? The first crash was a few days after the email about it.

Flags: needinfo?(botond)

Definitely related to desktop zooming, though the reason for the crash is not immediately clear. The array accesses that occur directly in ProcessQueue() are guarded against the queue being empty, and the function should only be called on one thread.

Flags: needinfo?(botond)
Regressed by: 1619187
Has Regression Range: --- → yes

Looks like it started in the build 20200601093812. Combining the cpu info and the adaptor id (gpu) it looks like 3 systems are responsible for the 16 crashes. There is at least one crash for a buildid for every date in June except June 7, so something that landed in the range of 1-2 days before the June 1 build could be looked at for potential regressors.

I think the most likely explanation is that this was introduced by the pinch handling code, but the codepath only got activated when people flipped the apz.allow_zooming pref manually, and for some users that seems to be causing this crash.

Hi Botond, can you set a severity? If this is caused by a user pref flip, it doesn't sound too severe.

Flags: needinfo?(botond)

S3 for a crash that only occurs with a modified pref. This bug does block bug 1620055, so should be fixed before the pref is enabled by default.

Severity: -- → S3
Flags: needinfo?(botond)

I have a patch in bug 1643884

No longer blocks: 1643884
Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.