Closed Bug 1779205 Opened 4 years ago Closed 3 years ago

CNET.com displays a Firefox error page

Categories

(Core :: Graphics, defect)

Firefox 102
defect

Tracking

()

RESOLVED FIXED
105 Branch
Tracking Status
firefox105 --- fixed

People

(Reporter: jonbonjovi886, Assigned: jfkthame)

Details

Crash Data

Attachments

(4 files)

Attached image CNET website 1.png

User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:102.0) Gecko/20100101 Firefox/102.0

Steps to reproduce:

I just browsed to https://www.cnet.com

Actual results:

It shows a hang site or crashed site page of Firefox and stops on that page or pages

Expected results:

it should have loaded cnet.com website without error pages

Attached image CNET website2.png

This tab has locked (translated literally from "Questa scheda si è bloccata")

The Bugbug bot thinks this bug should belong to the 'Core::Networking' component, and is moving the bug to that component. Please correct in case you think the bot is wrong.

Component: Untriaged → Networking
Product: Firefox → Core

Thanks for the report, Ste.
Are you able to attach http logs during behaviour?
https://firefox-source-docs.mozilla.org/networking/http/logging.html

Flags: needinfo?(jonbonjovi886)

I hope this log is right, I put it on OneDrive because it is too large:

https://1drv.ms/u/s!AnvadG_zDk0fgwX2KBcMECQgKE6G

Flags: needinfo?(jonbonjovi886)

(In reply to Ed Guloien [:edguloien] from comment #4)

Thanks for the report, Ste.
Are you able to attach http logs during behaviour?
https://firefox-source-docs.mozilla.org/networking/http/logging.html

I hope this log is right, I put it on OneDrive because it is too large:

https://1drv.ms/u/s!AnvadG_zDk0fgwX2KBcMECQgKE6G

Hi, thanks for the log. Looks good already. Have you submitted the crash report of the tab? Can you look in about:crashes and link the submitted crash report here for easier debugging?

Not to self: The English version of the error page shows "Gah. Your tab just crashed."[1] in aboutTabCrashed.xhtml

Flags: needinfo?(jonbonjovi886)

(In reply to Manuel Bucher from comment #7)

Hi, thanks for the log. Looks good already. Have you submitted the crash report of the tab? Can you look in about:crashes and link the submitted crash report here for easier debugging?

Not to self: The English version of the error page shows "Gah. Your tab just crashed."[1] in aboutTabCrashed.xhtml

I usually remove crash reports, so now I created a new one browsing to www.cnet.com, here it is:

https://crash-stats.mozilla.org/report/index/5db7e2f3-187b-4ff3-ae90-ade790220714

Flags: needinfo?(jonbonjovi886)

Moving to graphics component, because the functions from the stack trace belongs there. Interesting lines from the stack trace:

...
74346 	CoreText 	CoreText@0x000000000004e805 		frame_pointer
74347 	XUL 	mozilla::gfx::ScaledFontMac::ScaledFontMac(CGFont*, RefPtr<mozilla::gfx::UnscaledFont> const&, float, bool, mozilla::gfx::DeviceColor const&, bool, bool, bool) 	gfx/2d/ScaledFontMac.cpp:142 	frame_pointer
74348 	XUL 	gfxFont::Draw(gfxTextRun const*, unsigned int, unsigned int, mozilla::gfx::PointTyped<mozilla::gfx::UnknownUnits, float>*, TextRunDrawParams const&, mozilla::gfx::ShapedTextFlags) 	gfx/thebes/gfxFont.cpp:2165 	cfi
74349 	XUL 	gfxTextRun::Draw(gfxTextRun::Range, mozilla::gfx::PointTyped<mozilla::gfx::UnknownUnits, float>, gfxTextRun::DrawParams const&) const 	gfx/thebes/gfxTextRun.cpp:691 	cfi
74350 	XUL 	nsTextFrame::DrawTextRun(gfxTextRun::Range, mozilla::gfx::PointTyped<mozilla::gfx::UnknownUnits, float> const&, nsTextFrame::DrawTextRunParams const&) 	layout/generic/nsTextFrame.cpp:7144 	cfi
74351 	XUL 	nsTextFrame::DrawText(gfxTextRun::Range, mozilla::gfx::PointTyped<mozilla::gfx::UnknownUnits, float> const&, nsTextFrame::DrawTextParams const&) 	layout/generic/nsTextFrame.cpp:7386 	cfi
74352 	XUL 	nsTextFrame::PaintText(nsTextFrame::PaintTextParams const&, int, int, nsPoint const&, bool, float) 	layout/generic/nsTextFrame.cpp:7070 	cfi
74353 	XUL 	mozilla::nsDisplayText::CreateWebRenderCommands(mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, mozilla::layers::StackingContextHelper const&, mozilla::layers::RenderRootStateManager*, mozilla::nsDisplayListBuilder*) 	layout/painting/nsDisplayList.cpp:7555 	cfi
74354 	XUL 	mozilla::layers::WebRenderCommandBuilder::CreateWebRenderCommandsFromDisplayList(mozilla::nsDisplayList*, mozilla::nsDisplayItem*, mozilla::nsDisplayListBuilder*, mozilla::layers::StackingContextHelper const&, mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, bool) 	gfx/layers/wr/WebRenderCommandBuilder.cpp:2085 	cfi
74355 	XUL 	mozilla::nsDisplayOwnLayer::CreateWebRenderCommands(mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, mozilla::layers::StackingContextHelper const&, mozilla::layers::RenderRootStateManager*, mozilla::nsDisplayListBuilder*) 	layout/painting/nsDisplayList.cpp:5270 	cfi
74356 	XUL 	mozilla::layers::WebRenderCommandBuilder::CreateWebRenderCommandsFromDisplayList(mozilla::nsDisplayList*, mozilla::nsDisplayItem*, mozilla::nsDisplayListBuilder*, mozilla::layers::StackingContextHelper const&, mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, bool) 	gfx/layers/wr/WebRenderCommandBuilder.cpp:2085 	cfi

Last good looking function: https://hg.mozilla.org/releases/mozilla-release/file/a7294bfb43712ab3225c76087cd359a22ea8fa7d/gfx/2d/ScaledFontMac.cpp#l142

Crash Signature: CoreGraphics@0x4846b8
Component: Networking → Graphics

Triage - tentatively assigning S3, this may be upgraded depending on crash report frequency.

lsalzman, can you take a look?

Flags: needinfo?(lsalzman)
Severity: -- → S3
Blocks: gfx-triage

From comment #8:

74334 CoreGraphics CoreGraphics@0x0000000000484701 frame_pointer
Ø 74335 CoreGraphics CoreGraphics@0x0000000000484701 frame_pointer
Ø 74336 CoreGraphics CoreGraphics@0x0000000000484701 frame_pointer
Ø 74337 CoreGraphics CoreGraphics@0x0000000000483f75 frame_pointer
Ø 74338 CoreText CoreText@0x000000000009317f frame_pointer
Ø 74339 CoreText CoreText@0x0000000000093082 frame_pointer
Ø 74340 CoreText CoreText@0x000000000000c837 frame_pointer
Ø 74341 CoreText CoreText@0x00000000000e8e12 frame_pointer
Ø 74342 CoreText CoreText@0x00000000000a2739 frame_pointer
Ø 74343 CoreText CoreText@0x000000000004eb4f frame_pointer
Ø 74344 CoreText CoreText@0x000000000004ea16 frame_pointer
Ø 74345 CoreText CoreText@0x000000000004e841 frame_pointer
Ø 74346 CoreText CoreText@0x000000000004e805 frame_pointer
74347 XUL mozilla::gfx::ScaledFontMac::ScaledFontMac(CGFont*, RefPtr<mozilla::gfx::UnscaledFont> const&, float, bool, mozilla::gfx::DeviceColor const&, bool, bool, bool) gfx/2d/ScaledFontMac.cpp:142 frame_pointer

@jkew Stack overflow (infinite recursion?) called from mozilla::gfx::ScaledFontMac::ScaledFontMac?

@gsvelto It looks like we're missing mac system lib symbols here. Shouldn't we have those? Maybe it's due to the 74-thousand-frame stack?

Flags: needinfo?(jkew)
Flags: needinfo?(jmuizelaar)

Seems like the crash reports are confined to macOS 10.12 and inside a call to CreateCTFontFromCGFontWithVariations is where it takes off, somewhere inside here: https://searchfox.org/mozilla-central/source/gfx/2d/ScaledFontMac.cpp#98

Would be nice to have symbols to dig deeper.

Flags: needinfo?(lsalzman)

Yeah, symbols would be helpful if there's some way to get them. As it stands, this looks to me like it's probably a bug in macOS, somehow going into infinite recursion internally on one of the CT/CG calls we make. It might be triggered by a specific font, possibly with a broken (variation?) table in it, but it doesn't reproduce for me under either 10.13 or macOS 13; I don't have a 10.12 machine on hand.

Could be that CoreGraphics is choking on the MonumentGrotesk webfont that the site uses, which is a variable font. Dumping that font resource with TTX, it does note one anomaly: some of the standard font name strings have been stripped from the "name" table, including the style name "Regular", which the "STAT" table references. Maybe it's conceivable that this is causing macOS to go into some kind of recursive search for a name that it never finds. But that's a wild guess, really. And given that it doesn't happen on newer systems, it seems likely to be a bug that subsequently got fixed.

Does one of you have a machine with 10.12 to try this on? If we can reproduce, we could experiment with possible mitigations, but if not then we'll just be flailing in the dark.

Flags: needinfo?(jkew)

The bug has a crash signature, thus the bug will be considered confirmed.

Status: UNCONFIRMED → NEW
Ever confirmed: true
Assignee: nobody → jgilbert
User Agent 	Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:104.0) Gecko/20100101 Firefox/104.0
OS 	Darwin 16.7.0 Darwin Kernel Version 16.7.0: Thu Jun 15 17:36:27 PDT 2017; root:xnu-3789.70.16~2/RELEASE_X86_64

(In reply to Kelsey Gilbert [:jgilbert] (previously Jeff) from comment #16)

User Agent 	Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:104.0) Gecko/20100101 Firefox/104.0
OS 	Darwin 16.7.0 Darwin Kernel Version 16.7.0: Thu Jun 15 17:36:27 PDT 2017; root:xnu-3789.70.16~2/RELEASE_X86_64

Yep, confirmed here. Ready to experiment!

Flags: needinfo?(jkew)

If you set layout.css.font-variations.enabled to false, does that avoid the crash?

Flags: needinfo?(jkew) → needinfo?(jgilbert)

Also confirmed after OS auto-update:

User Agent 	Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:104.0) Gecko/20100101 Firefox/104.0
OS 	Darwin 16.7.0 Darwin Kernel Version 16.7.0: Sun Jun 2 20:26:31 PDT 2019; root:xnu-3789.73.50~1/RELEASE_X86_64

In about:config, layout.css.font-variations.enabled is greyed out with a 'locked' icon, but shows false already.

Flags: needinfo?(jgilbert) → needinfo?(jkew)

I've pushed a try job at https://treeherder.mozilla.org/jobs?repo=try&revision=7cb426a11ab7a4b5815493173b95f6c9cd6d5438 with a patch that might have some effect. Once the build is ready, if you could confirm whether it still crashes that'd be great. (If the problem still persists, I have another idea to try but it'll be a bit uglier of a patch so I'm hoping this might help...)

Flags: needinfo?(jkew) → needinfo?(jgilbert)

I tested the debug build and it seems to be fixed/unaffected.

Flags: needinfo?(jmuizelaar)
Flags: needinfo?(jkew)
Flags: needinfo?(jgilbert)

Cool, thanks. So it appears that dropping the variation tables from the font resource means we don't hit the problematic Core Graphics path here. And as we don't even attempt to support variations on such old macOS versions anyhow, dropping the tables doesn't lose us any functionality.

Flags: needinfo?(jkew)
Pushed by jkew@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/f0d33d068908 Drop variation tables entirely during sanitization if we don't support variations on the current platform. r=gfx-reviewers,aosmond
Flags: needinfo?(jgilbert)

Ugh, that's a pain.... we can't check gfxPlatform here. OK, will look into it.

Flags: needinfo?(jgilbert) → needinfo?(jfkthame)
Assignee: jgilbert → jfkthame

To avoid the GPU-process failures in comment 26, we can make gfxPlatform::HasVariationFontSupport a static method that doesn't require initializing a gfxPlatform instance.

Flags: needinfo?(jfkthame)
Attachment #9288068 - Attachment description: Bug 1779205 - Drop variation tables entirely during sanitization if we don't support variations on the current platform. r=#gfx-reviewers → Bug 1779205 - part 2 - Drop variation tables entirely during sanitization if we don't support variations on the current platform. r=#gfx-reviewers
Pushed by jkew@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/186424c5f4ea part 1 - Make gfxPlatform::HasVariationFontSupport() a static method that does not require a gfxPlatform instance. r=gfx-reviewers,jrmuizel https://hg.mozilla.org/integration/autoland/rev/ea288d88571f part 2 - Drop variation tables entirely during sanitization if we don't support variations on the current platform. r=gfx-reviewers,aosmond

Backed out 2 changesets (bug 1779205) for causing browser-chrome failures in gfx/thebes/gfxPlatform.cpp

Backout link: https://hg.mozilla.org/integration/autoland/rev/a7d8ae83e74268bc3a46c3a008d1b7044feead0d

Push with failures

Failure log

INFO - GECKO(1661) | SUMMARY: ThreadSanitizer: data race /builds/worker/checkouts/gecko/gfx/thebes/gfxPlatform.cpp:788:30 in gfxPlatform::HasVariationFontSupport()
Flags: needinfo?(jfkthame)
Pushed by jkew@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/49f2cdcc1a6b part 1 - Make gfxPlatform::HasVariationFontSupport() a static method that does not require a gfxPlatform instance. r=gfx-reviewers,jrmuizel https://hg.mozilla.org/integration/autoland/rev/a3b604b751e8 part 2 - Drop variation tables entirely during sanitization if we don't support variations on the current platform. r=gfx-reviewers,aosmond

Backed out for causing windows 2012 build bustages on gfxWindowsPlatform.

Push with failures

Failure log

Backout link

[task 2022-08-04T14:31:58.607Z] 14:31:58     INFO -  gmake[4]: Entering directory '/builds/worker/workspace/obj-build/gfx/thebes'
[task 2022-08-04T14:31:58.610Z] 14:31:58     INFO -  /builds/worker/fetches/sccache/sccache /builds/worker/fetches/clang/bin/clang-cl -Xclang -std=c++17 -FogfxWindowsPlatform.obj -c  -I/builds/worker/workspace/obj-build/dist/stl_wrappers -guard:cf -U_FORTIFY_SOURCE -Xclang -fno-common -DNDEBUG=1 -DTRIMMED=1 -DUNICODE -D_UNICODE -D_CRT_RAND_S -DCERT_CHAIN_PARA_HAS_EXTRA_FIELDS -D_SECURE_ATL -DCHROMIUM_BUILD -DU_STATIC_IMPLEMENTATION -DOS_WIN=1 -DWIN32 -D_WIN32 -D_WINDOWS -DWIN32_LEAN_AND_MEAN -DCOMPILER_MSVC -DMOZ_ENABLE_D3D10_LAYER -DGRAPHITE2_STATIC -DWINAPI_NO_BUNDLED_LIBRARIES -DMOZ_HAS_MOZGLUE -DMOZILLA_INTERNAL_API -DIMPL_LIBXUL -DSTATIC_EXPORTABLE_JS_API -I/builds/worker/checkouts/gecko/gfx/thebes -I/builds/worker/workspace/obj-build/gfx/thebes -I/builds/worker/workspace/obj-build/ipc/ipdl/_ipdlheaders -I/builds/worker/checkouts/gecko/ipc/chromium/src -I/builds/worker/workspace/obj-build/security/rlbox -I/builds/worker/checkouts/gecko/dom/base -I/builds/worker/checkouts/gecko/dom/media/platforms/apple -I/builds/worker/checkouts/gecko/dom/xml -I/builds/worker/checkouts/gecko/gfx/cairo/cairo/src -I/builds/worker/checkouts/gecko/widget/gtk -I/builds/worker/checkouts/gecko/gfx/skia -I/builds/worker/checkouts/gecko/gfx/skia/skia -I/builds/worker/workspace/obj-build/dist/include -I/builds/worker/workspace/obj-build/dist/include/nspr -I/builds/worker/workspace/obj-build/dist/include/nss -MD -FI /builds/worker/workspace/obj-build/mozilla-config.h -DMOZILLA_CLIENT -Qunused-arguments -Qunused-arguments -W3 -Wbitfield-enum-conversion -Wdeprecated-this-capture -Wempty-body -Wformat-type-confusion -Wignored-qualifiers -Wpointer-arith -Wshadow-field-in-constructor-modified -Wsign-compare -Wtype-limits -Wno-error=tautological-type-limit-compare -Wunreachable-code -Wunreachable-code-return -Wunused-but-set-parameter -Wno-invalid-offsetof -Wclass-varargs -Wempty-init-stmt -Wfloat-overflow-conversion -Wfloat-zero-conversion -Wloop-analysis -Wno-range-loop-analysis -Wc++2a-compat -Wenum-compare-conditional -Wno-ambiguous-reversed-operator -Wno-error=deprecated -Wno-error=deprecated-anon-enum-enum-conversion -Wno-error=deprecated-enum-enum-conversion -Wno-error=deprecated-enum-float-conversion -Wno-error=deprecated-pragma -Wno-error=deprecated-this-capture -Wno-error=deprecated-volatile -Wcomma -Wimplicit-fallthrough -Werror=non-literal-null-conversion -Wstring-conversion -Wno-inline-new-delete -Wno-error=deprecated-declarations -Wno-error=array-bounds -Wno-error=backend-plugin -Wno-error=free-nonheap-object -Wno-error=return-std-move -Wno-error=atomic-alignment -Wno-error=deprecated-copy -Wno-unknown-pragmas -Wno-ignored-pragmas -Wno-deprecated-declarations -Wno-microsoft-enum-value -Wno-microsoft-include -Wno-invalid-noreturn -Wno-inconsistent-missing-override -Wno-implicit-exception-spec-mismatch -Wno-microsoft-exception-spec -Wno-unused-local-typedef -Wno-ignored-attributes -Wno-used-but-marked-unused -Wno-gnu-zero-variadic-macro-arguments -Wno-psabi -Wthread-safety -fsanitize=address -fsanitize-blacklist=/builds/worker/checkouts/gecko/build/sanitizers/asan_blacklist_win.txt -fcrash-diagnostics-dir=/builds/worker/artifacts -fcrash-diagnostics-dir=/builds/worker/artifacts -fcrash-diagnostics-dir=/builds/worker/artifacts -TP -Zc:sizedDealloc- -D_HAS_EXCEPTIONS=0 -Gy -Zc:inline -D_SILENCE_TR1_NAMESPACE_DEPRECATION_WARNING -GR- -Z7 -Xclang -load -Xclang /builds/worker/workspace/obj-build/build/clang-plugin/libclang-plugin.so -Xclang -add-plugin -Xclang moz-check -O2 -gline-tables-only -Oy- -Werror -Werror=switch -fno-strict-aliasing -Xclang -ffp-contract=off  -Xclang -MP -Xclang -dependency-file -Xclang .deps/gfxWindowsPlatform.obj.pp -Xclang -MT -Xclang gfxWindowsPlatform.obj   /builds/worker/checkouts/gecko/gfx/thebes/gfxWindowsPlatform.cpp
[task 2022-08-04T14:31:58.611Z] 14:31:58     INFO -  /builds/worker/checkouts/gecko/gfx/thebes/gfxWindowsPlatform.cpp(629,3): error: use of undeclared identifier 'sHasVariationFontSupport'; did you mean 'mHasNativeColrFontSupport'?
[task 2022-08-04T14:31:58.611Z] 14:31:58     INFO -    sHasVariationFontSupport = false;
[task 2022-08-04T14:31:58.611Z] 14:31:58     INFO -    ^~~~~~~~~~~~~~~~~~~~~~~~
[task 2022-08-04T14:31:58.611Z] 14:31:58     INFO -    mHasNativeColrFontSupport
[task 2022-08-04T14:31:58.611Z] 14:31:58     INFO -  /builds/worker/checkouts/gecko/gfx/thebes/gfxPlatform.h(924,8): note: 'mHasNativeColrFontSupport' declared here
[task 2022-08-04T14:31:58.611Z] 14:31:58     INFO -    bool mHasNativeColrFontSupport = false;
[task 2022-08-04T14:31:58.611Z] 14:31:58     INFO -         ^
[task 2022-08-04T14:31:58.611Z] 14:31:58     INFO -  1 error generated.
[task 2022-08-04T14:31:58.612Z] 14:31:58    ERROR -  gmake[4]: *** [/builds/worker/checkouts/gecko/config/rules.mk:668: gfxWindowsPlatform.obj] Error 1
[task 2022-08-04T14:31:58.612Z] 14:31:58     INFO -  gmake[4]: Leaving directory '/builds/worker/workspace/obj-build/gfx/thebes'
[task 2022-08-04T14:31:58.612Z] 14:31:58     INFO -  gmake[4]: *** Waiting for unfinished jobs....
[task 2022-08-04T14:31:58.614Z] 14:31:58     INFO -  gmake[4]: Entering directory '/builds/worker/workspace/obj-build/ipc/chromium'
Flags: needinfo?(jfkthame)
Flags: needinfo?(jfkthame)
No longer blocks: gfx-triage
Pushed by jkew@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/6525c2617932 part 1 - Make gfxPlatform::HasVariationFontSupport() a static method that does not require a gfxPlatform instance. r=gfx-reviewers,jrmuizel https://hg.mozilla.org/integration/autoland/rev/8d392cb8c537 part 2 - Drop variation tables entirely during sanitization if we don't support variations on the current platform. r=gfx-reviewers,aosmond
Status: NEW → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
Target Milestone: --- → 105 Branch

== Change summary for alert #35002 (as of Thu, 04 Aug 2022 07:56:13 GMT) ==

Improvements:

Ratio Test Platform Options Absolute values (old vs new)
7% tsvg_static linux1804-64-shippable-qr e10s fission stylo webrender 72.87 -> 67.87

For up to date results, see: https://treeherder.mozilla.org/perfherder/alerts?id=35002

Flags: needinfo?(jfkthame)
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: