Closed Bug 1806490 Opened 3 years ago Closed 3 years ago

Assertion failure: !Exists(), at /builds/worker/workspace/obj-build/dist/include/mozilla/MozPromise.h:1485

Categories

(Core :: DOM: File, defect, P1)

defect

Tracking

()

VERIFIED FIXED
111 Branch
Tracking Status
firefox-esr102 --- unaffected
firefox108 --- disabled
firefox109 --- disabled
firefox110 --- disabled
firefox111 --- verified

People

(Reporter: tsmith, Assigned: janv)

References

(Blocks 2 open bugs, Regression)

Details

(Keywords: assertion, regression, testcase, Whiteboard: [bugmon:bisected,confirmed])

Crash Data

Attachments

(2 files)

Attached file testcase.html

Found while fuzzing m-c 20221217-59c15c902a18 (--enable-debug --enable-fuzzing)

To reproduce via Grizzly Replay:

$ pip install fuzzfetch grizzly-framework
$ python -m fuzzfetch -d --fuzzing -n firefox
$ python -m grizzly.replay ./firefox/firefox testcase.html

Assertion failure: !Exists(), at /builds/worker/workspace/obj-build/dist/include/mozilla/MozPromise.h:1485

#0 0x7fd75ebbd6e3 in Track /builds/worker/workspace/obj-build/dist/include/mozilla/MozPromise.h:1485:5
#1 0x7fd75ebbd6e3 in Track /builds/worker/workspace/obj-build/dist/include/mozilla/MozPromise.h:1016:22
#2 0x7fd75ebbd6e3 in mozilla::dom::FileSystemManager::BeginRequest(std::function<void (RefPtr<mozilla::dom::FileSystemManagerChild> const&)>&&, std::function<void (nsresult)>&&) /builds/worker/checkouts/gecko/dom/fs/api/FileSystemManager.cpp:96:9
#3 0x7fd75ebd2c06 in mozilla::dom::fs::FileSystemRequestHandler::GetRootHandle(RefPtr<mozilla::dom::FileSystemManager>, RefPtr<mozilla::dom::Promise>, mozilla::ErrorResult&) /builds/worker/checkouts/gecko/dom/fs/child/FileSystemRequestHandler.cpp:344:13
#4 0x7fd75ebbd7d0 in mozilla::dom::FileSystemManager::GetDirectory(mozilla::ErrorResult&) /builds/worker/checkouts/gecko/dom/fs/api/FileSystemManager.cpp:109:20
#5 0x7fd75f81558f in mozilla::dom::StorageManager::GetDirectory(mozilla::ErrorResult&) /builds/worker/checkouts/gecko/dom/quota/StorageManager.cpp:797:42
#6 0x7fd75dac4993 in getDirectory /builds/worker/workspace/obj-build/dom/bindings/StorageManagerBinding.cpp:310:60
#7 0x7fd75dac4993 in mozilla::dom::StorageManager_Binding::getDirectory_promiseWrapper(JSContext*, JS::Handle<JSObject*>, void*, JSJitMethodCallArgs const&) /builds/worker/workspace/obj-build/dom/bindings/StorageManagerBinding.cpp:326:13
#8 0x7fd75e4d8645 in bool mozilla::dom::binding_detail::GenericMethod<mozilla::dom::binding_detail::NormalThisPolicy, mozilla::dom::binding_detail::ConvertExceptionsToPromises>(JSContext*, unsigned int, JS::Value*) /builds/worker/checkouts/gecko/dom/bindings/BindingUtils.cpp:3287:13
#9 0x7fd762809cb6 in CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&) /builds/worker/checkouts/gecko/js/src/vm/Interpreter.cpp:459:13
#10 0x7fd7628095df in js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason) /builds/worker/checkouts/gecko/js/src/vm/Interpreter.cpp:547:12
#11 0x7fd7627fb21f in CallFromStack /builds/worker/checkouts/gecko/js/src/vm/Interpreter.cpp:619:10
#12 0x7fd7627fb21f in Interpret(JSContext*, js::RunState&) /builds/worker/checkouts/gecko/js/src/vm/Interpreter.cpp:3379:16
#13 0x7fd7627ee8de in js::RunScript(JSContext*, js::RunState&) /builds/worker/checkouts/gecko/js/src/vm/Interpreter.cpp:431:13
#14 0x7fd7628094db in js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason) /builds/worker/checkouts/gecko/js/src/vm/Interpreter.cpp:579:13
#15 0x7fd76280aa0c in js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason) /builds/worker/checkouts/gecko/js/src/vm/Interpreter.cpp:646:8
#16 0x7fd7628c6dac in JS::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::HandleValueArray const&, JS::MutableHandle<JS::Value>) /builds/worker/checkouts/gecko/js/src/vm/CallAndConstruct.cpp:117:10
#17 0x7fd75e1a9ef1 in mozilla::dom::EventHandlerNonNull::Call(mozilla::dom::BindingCallContext&, JS::Handle<JS::Value>, mozilla::dom::Event&, JS::MutableHandle<JS::Value>, mozilla::ErrorResult&) /builds/worker/workspace/obj-build/dom/bindings/EventHandlerBinding.cpp:65:37
#18 0x7fd75eabdf29 in void mozilla::dom::EventHandlerNonNull::Call<nsCOMPtr<mozilla::dom::EventTarget>>(nsCOMPtr<mozilla::dom::EventTarget> const&, mozilla::dom::Event&, JS::MutableHandle<JS::Value>, mozilla::ErrorResult&, char const*, mozilla::dom::CallbackObject::ExceptionHandling, JS::Realm*) /builds/worker/workspace/obj-build/dist/include/mozilla/dom/EventHandlerBinding.h:82:12
#19 0x7fd75eabd144 in mozilla::JSEventHandler::HandleEvent(mozilla::dom::Event*) /builds/worker/checkouts/gecko/dom/events/JSEventHandler.cpp:201:12
#20 0x7fd75ea9df1d in mozilla::EventListenerManager::HandleEventSubType(mozilla::EventListenerManager::Listener*, mozilla::dom::Event*, mozilla::dom::EventTarget*) /builds/worker/checkouts/gecko/dom/events/EventListenerManager.cpp:1314:22
#21 0x7fd75ea9eb89 in mozilla::EventListenerManager::HandleEventInternal(nsPresContext*, mozilla::WidgetEvent*, mozilla::dom::Event**, mozilla::dom::EventTarget*, nsEventStatus*, bool) /builds/worker/checkouts/gecko/dom/events/EventListenerManager.cpp:1504:17
#22 0x7fd75ea93b56 in HandleEvent /builds/worker/checkouts/gecko/dom/events/EventListenerManager.h:395:5
#23 0x7fd75ea93b56 in mozilla::EventTargetChainItem::HandleEvent(mozilla::EventChainPostVisitor&, mozilla::ELMCreationDetector&) /builds/worker/checkouts/gecko/dom/events/EventDispatcher.cpp:347:17
#24 0x7fd75ea9308b in mozilla::EventTargetChainItem::HandleEventTargetChain(nsTArray<mozilla::EventTargetChainItem>&, mozilla::EventChainPostVisitor&, mozilla::EventDispatchingCallback*, mozilla::ELMCreationDetector&) /builds/worker/checkouts/gecko/dom/events/EventDispatcher.cpp:549:16
#25 0x7fd75ea9584b in mozilla::EventDispatcher::Dispatch(nsISupports*, nsPresContext*, mozilla::WidgetEvent*, mozilla::dom::Event*, nsEventStatus*, mozilla::EventDispatchingCallback*, nsTArray<mozilla::dom::EventTarget*>*) /builds/worker/checkouts/gecko/dom/events/EventDispatcher.cpp:1122:11
#26 0x7fd75ea98326 in mozilla::EventDispatcher::DispatchDOMEvent(nsISupports*, mozilla::WidgetEvent*, mozilla::dom::Event*, nsPresContext*, nsEventStatus*) /builds/worker/checkouts/gecko/dom/events/EventDispatcher.cpp
#27 0x7fd75ea6c86b in mozilla::DOMEventTargetHelper::DispatchEvent(mozilla::dom::Event&, mozilla::dom::CallerType, mozilla::ErrorResult&) /builds/worker/checkouts/gecko/dom/events/DOMEventTargetHelper.cpp:176:17
#28 0x7fd75eaa55f2 in mozilla::dom::EventTarget::DispatchEvent(mozilla::dom::Event&) /builds/worker/checkouts/gecko/dom/events/EventTarget.cpp:180:13
#29 0x7fd75fe6f217 in mozilla::dom::MessageEventRunnable::DispatchDOMEvent(JSContext*, mozilla::dom::WorkerPrivate*, mozilla::DOMEventTargetHelper*, bool) /builds/worker/checkouts/gecko/dom/workers/MessageEventRunnable.cpp:104:12
#30 0x7fd75feb513e in mozilla::dom::WorkerRunnable::Run() /builds/worker/checkouts/gecko/dom/workers/WorkerRunnable.cpp:377:12
#31 0x7fd75b362b54 in nsThread::ProcessNextEvent(bool, bool*) /builds/worker/checkouts/gecko/xpcom/threads/nsThread.cpp:1203:16
#32 0x7fd75b3692dd in NS_ProcessNextEvent(nsIThread*, bool) /builds/worker/checkouts/gecko/xpcom/threads/nsThreadUtils.cpp:476:10
#33 0x7fd75fea3c94 in mozilla::dom::WorkerPrivate::DoRunLoop(JSContext*) /builds/worker/checkouts/gecko/dom/workers/WorkerPrivate.cpp:3234:7
#34 0x7fd75fe8b1fd in mozilla::dom::workerinternals::(anonymous namespace)::WorkerThreadPrimaryRunnable::Run() /builds/worker/checkouts/gecko/dom/workers/RuntimeService.cpp:2044:42
#35 0x7fd75b362b54 in nsThread::ProcessNextEvent(bool, bool*) /builds/worker/checkouts/gecko/xpcom/threads/nsThread.cpp:1203:16
#36 0x7fd75b3692dd in NS_ProcessNextEvent(nsIThread*, bool) /builds/worker/checkouts/gecko/xpcom/threads/nsThreadUtils.cpp:476:10
#37 0x7fd75bf5526a in mozilla::ipc::MessagePumpForNonMainThreads::Run(base::MessagePump::Delegate*) /builds/worker/checkouts/gecko/ipc/glue/MessagePump.cpp:300:20
#38 0x7fd75be78d78 in MessageLoop::RunInternal() /builds/worker/checkouts/gecko/ipc/chromium/src/base/message_loop.cc:381:10
#39 0x7fd75be78c81 in RunHandler /builds/worker/checkouts/gecko/ipc/chromium/src/base/message_loop.cc:374:3
#40 0x7fd75be78c81 in MessageLoop::Run() /builds/worker/checkouts/gecko/ipc/chromium/src/base/message_loop.cc:356:3
#41 0x7fd75b35dee7 in nsThread::ThreadFunc(void*) /builds/worker/checkouts/gecko/xpcom/threads/nsThread.cpp:383:10
#42 0x7fd76fe4dc86 in _pt_root /builds/worker/checkouts/gecko/nsprpub/pr/src/pthreads/ptthread.c:201:5
#43 0x7fd7706f6b42 in start_thread nptl/pthread_create.c:442:8
#44 0x7fd7707889ff  misc/../sysdeps/unix/sysv/linux/x86_64/clone3.S:81
Flags: in-testsuite?

Verified bug as reproducible on mozilla-central 20221219162526-91a9bbbe6bea.
The bug appears to have been introduced in the following build range:

Start: ca2873779214f6109ffe1b23e1455350294ac325 (20221020105605)
End: 2439cdd33386dd961b5880aa911e732eb535495a (20221020074158)
Pushlog: https://hg.mozilla.org/mozilla-central/pushloghtml?fromchange=ca2873779214f6109ffe1b23e1455350294ac325&tochange=2439cdd33386dd961b5880aa911e732eb535495a

Keywords: regression
Whiteboard: [bugmon:bisected,confirmed]
Severity: -- → S3
Priority: -- → P3
Assignee: nobody → jvarga
Status: NEW → ASSIGNED

Testing a patch for this.

Set release status flags based on info from the regressing bug 1792245

It can happen that BeginRequest is called multiple times when the actor doesn't
exist yet. Such situations can't be handled by a single MozPromiseRequestHolder.

This started showing in crash reports, bug 1810527.

Priority: P3 → P1
Pushed by jvarga@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/cb35e5c2851c Make it possible to track all CreateFileSystemManagerChild requests in FileSystemManager; r=dom-storage-reviewers,jari
Status: ASSIGNED → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED
Target Milestone: --- → 111 Branch
Flags: in-testsuite? → in-testsuite+

Verified bug as fixed on rev mozilla-central 20230117161302-455aa95a34de.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.

Status: RESOLVED → VERIFIED
Keywords: bugmon
Duplicate of this bug: 1810527

Copying crash signatures from duplicate bugs.

Crash Signature: [@ mozilla::MozPromiseRequestHolder<T>::Track]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: