Closed Bug 1878215 Opened 2 years ago Closed 9 months ago

Assertion failure: !_owningThread || _owningThread->IsCurrentThread() (WeakPtr accessed from multiple threads), at /builds/worker/workspace/obj-build/dist/include/mozilla/WeakPtr.h:184

Categories

(Core :: Layout: Scrolling and Overflow, defect, P3)

defect

Tracking

()

RESOLVED FIXED
148 Branch
Tracking Status
firefox-esr115 --- disabled
firefox-esr140 --- disabled
firefox122 --- disabled
firefox123 --- disabled
firefox124 --- disabled
firefox146 --- disabled
firefox147 --- disabled
firefox148 --- fixed

People

(Reporter: tsmith, Assigned: boris)

References

(Blocks 2 open bugs, )

Details

(5 keywords)

Crash Data

Attachments

(1 file, 1 obsolete file)

1.96 KB, application/x-javascript
Details

Found with m-c 20240201-366005a91eda (--enable-debug --enable-fuzzing)

This was found by visiting a live website with a debug build.

STR:

  • Launch browser and visit site

This issue was triggered by visiting http://veeam.com/.

Assertion failure: !_owningThread || _owningThread->IsCurrentThread() (WeakPtr accessed from multiple threads), at /builds/worker/workspace/obj-build/dist/include/mozilla/WeakPtr.h:184

#0 0x7fa8606fd595 in get /builds/worker/workspace/obj-build/dist/include/mozilla/WeakPtr.h:184:5
#1 0x7fa8606fd595 in mozilla::WeakPtr<nsDocShell, (mozilla::detail::WeakPtrDestructorBehavior)0>::get() const /builds/worker/workspace/obj-build/dist/include/mozilla/WeakPtr.h:303:49
#2 0x7fa8606efa06 in operator nsDocShell * /builds/worker/workspace/obj-build/dist/include/mozilla/WeakPtr.h:304:32
#3 0x7fa8606efa06 in mozilla::dom::Document::GetDocShell() const /builds/worker/checkouts/gecko/dom/base/Document.cpp:16563:53
#4 0x7fa8636be135 in mozilla::dom::BrowserChild::GetFrom(mozilla::PresShell*) /builds/worker/checkouts/gecko/dom/ipc/BrowserChild.cpp:2893:39
#5 0x7fa86455721e in GetPaintedLayerScaleForFrame(nsIFrame*, bool) /builds/worker/checkouts/gecko/layout/generic/nsGfxScrollFrame.cpp:2968:13
#6 0x7fa86455f324 in nsHTMLScrollFrame::GetScrolledRect() const /builds/worker/checkouts/gecko/layout/generic/nsGfxScrollFrame.cpp:6887:24
#7 0x7fa8645cf0ad in GetScrollRange /builds/worker/checkouts/gecko/layout/generic/nsGfxScrollFrame.cpp:4698:18
#8 0x7fa8645cf0ad in GetLayoutScrollRange /builds/worker/checkouts/gecko/layout/generic/nsGfxScrollFrame.cpp:4693:10
#9 0x7fa8645cf0ad in GetScrollRange /builds/worker/checkouts/gecko/layout/generic/nsGfxScrollFrame.h:224:48
#10 0x7fa8645cf0ad in non-virtual thunk to nsHTMLScrollFrame::GetScrollRange() const /builds/worker/checkouts/gecko/layout/generic/nsGfxScrollFrame.h
#11 0x7fa864534026 in nsIScrollableFrame::GetAvailableScrollingDirections() const /builds/worker/checkouts/gecko/layout/generic/nsGfxScrollFrame.cpp:7229:24
#12 0x7fa86042e69b in mozilla::dom::ScrollTimeline::GetCurrentTimeAsDuration() const /builds/worker/checkouts/gecko/dom/animation/ScrollTimeline.cpp:131:21
#13 0x7fa860412016 in GetCurrentTimeForHoldTime /builds/worker/checkouts/gecko/dom/animation/Animation.cpp:412:54
#14 0x7fa860412016 in GetUnconstrainedCurrentTime /builds/worker/checkouts/gecko/dom/animation/Animation.h:472:12
#15 0x7fa860412016 in mozilla::dom::Animation::AtProgressTimelineBoundary() const /builds/worker/checkouts/gecko/dom/animation/Animation.h:387:42
#16 0x7fa860407dbf in mozilla::dom::AnimationEffect::GetComputedTiming(mozilla::TimingParams const*) const /builds/worker/checkouts/gecko/dom/animation/AnimationEffect.cpp:272:32
#17 0x7fa86040eac3 in mozilla::dom::KeyframeEffect::ComposeStyle(mozilla::StyleAnimationValueMap&, nsCSSPropertyIDSet const&) /builds/worker/checkouts/gecko/dom/animation/KeyframeEffect.cpp:613:35
#18 0x7fa86040e947 in mozilla::dom::Animation::ComposeStyle(mozilla::StyleAnimationValueMap&, nsCSSPropertyIDSet const&) /builds/worker/checkouts/gecko/dom/animation/Animation.cpp:1322:23
#19 0x7fa86041eb0f in mozilla::ComposeSortedEffects(nsTArray<mozilla::dom::KeyframeEffect*> const&, mozilla::EffectSet const*, mozilla::EffectCompositor::CascadeLevel, mozilla::StyleAnimationValueMap*) /builds/worker/checkouts/gecko/dom/animation/EffectCompositor.cpp:397:16
#20 0x7fa86041e65e in mozilla::EffectCompositor::GetServoAnimationRule(mozilla::dom::Element const*, mozilla::PseudoStyleType, mozilla::EffectCompositor::CascadeLevel, mozilla::StyleAnimationValueMap*) /builds/worker/checkouts/gecko/dom/animation/EffectCompositor.cpp:438:3
#21 0x7fa86965707f in style::gecko::wrapper::get_animation_rule::h01c28c1359d9310d /builds/worker/checkouts/gecko/servo/components/style/gecko/wrapper.rs:974:17
#22 0x7fa86923c3a3 in style::dom::TElement::animation_declarations::hfdac8e529fb67573 /builds/worker/checkouts/gecko/servo/components/style/dom.rs:495:25
#23 0x7fa86923c3a3 in style::style_resolver::StyleResolverForElement$LT$E$GT$::match_primary::ha1db56fd79b61adb /builds/worker/checkouts/gecko/servo/components/style/style_resolver.rs:490:13
#24 0x7fa86923d91d in style::style_resolver::StyleResolverForElement$LT$E$GT$::resolve_primary_style::h606b46ce975b31de /builds/worker/checkouts/gecko/servo/components/style/style_resolver.rs:191:31
#25 0x7fa86923ca1b in style::style_resolver::StyleResolverForElement$LT$E$GT$::resolve_style::h34365b580b41d404 /builds/worker/checkouts/gecko/servo/components/style/style_resolver.rs:266:29
#26 0x7fa86926aad4 in style::style_resolver::StyleResolverForElement$LT$E$GT$::resolve_style_with_default_parents::_$u7b$$u7b$closure$u7d$$u7d$::h76bccf0f838c8da5 /builds/worker/checkouts/gecko/servo/components/style/style_resolver.rs:301:13
#27 0x7fa86926aad4 in style::style_resolver::with_default_parent_styles::h0ab5bb67ba4ff8e1 /builds/worker/checkouts/gecko/servo/components/style/style_resolver.rs:119:5
#28 0x7fa86926aad4 in style::style_resolver::StyleResolverForElement$LT$E$GT$::resolve_style_with_default_parents::h83f2f2c2ba4cf0a0 /builds/worker/checkouts/gecko/servo/components/style/style_resolver.rs:300:9
#29 0x7fa86926aad4 in style::traversal::compute_style::hc38477f53c5b7010 /builds/worker/checkouts/gecko/servo/components/style/traversal.rs:615:34
#30 0x7fa8692681c1 in style::traversal::recalc_style_at::hedb2542e62c0d381 /builds/worker/checkouts/gecko/servo/components/style/traversal.rs:428:13
#31 0x7fa8692681c1 in _$LT$style..gecko..traversal..RecalcStyleOnly$u20$as$u20$style..traversal..DomTraversal$LT$style..gecko..wrapper..GeckoElement$GT$$GT$::process_preorder::h388d262593830907 /builds/worker/checkouts/gecko/servo/components/style/gecko/traversal.rs:37:13
#32 0x7fa8692681c1 in style::parallel::style_trees::h56a02b96e3e69ffb /builds/worker/checkouts/gecko/servo/components/style/parallel.rs:158:9
#33 0x7fa86928d994 in style::parallel::distribute_one_chunk::_$u7b$$u7b$closure$u7d$$u7d$::h781e6c6b42abc2cd /builds/worker/checkouts/gecko/servo/components/style/parallel.rs:84:9
#34 0x7fa86928d994 in rayon_core::scope::ScopeFifo::spawn_fifo::_$u7b$$u7b$closure$u7d$$u7d$::_$u7b$$u7b$closure$u7d$$u7d$::h9ceecdb8a641c0c2 /builds/worker/checkouts/gecko/third_party/rust/rayon-core/src/scope/mod.rs:586:57
#35 0x7fa86928d994 in _$LT$core..panic..unwind_safe..AssertUnwindSafe$LT$F$GT$$u20$as$u20$core..ops..function..FnOnce$LT$$LP$$RP$$GT$$GT$::call_once::hb12e60ca458ab562 /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/core/src/panic/unwind_safe.rs:272:9
#36 0x7fa86928d994 in std::panicking::try::do_call::hfac62094749f94d8 /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/std/src/panicking.rs:552:40
#37 0x7fa86928d994 in std::panicking::try::hb3f037962e0b7d1a /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/std/src/panicking.rs:516:19
#38 0x7fa86928d994 in std::panic::catch_unwind::h578d94922bc4f8d2 /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/std/src/panic.rs:142:14
#39 0x7fa86928d994 in rayon_core::unwind::halt_unwinding::h10f142f1f622ca42 /builds/worker/checkouts/gecko/third_party/rust/rayon-core/src/unwind.rs:17:5
#40 0x7fa86928d994 in rayon_core::scope::ScopeBase::execute_job_closure::hfc795e3fa205c961 /builds/worker/checkouts/gecko/third_party/rust/rayon-core/src/scope/mod.rs:689:28
#41 0x7fa86928d994 in rayon_core::scope::ScopeBase::execute_job::h1db170de5639988e /builds/worker/checkouts/gecko/third_party/rust/rayon-core/src/scope/mod.rs:679:29
#42 0x7fa86928d994 in rayon_core::scope::ScopeFifo::spawn_fifo::_$u7b$$u7b$closure$u7d$$u7d$::hb2016b3b7030ab3f /builds/worker/checkouts/gecko/third_party/rust/rayon-core/src/scope/mod.rs:586:13
#43 0x7fa86928d994 in _$LT$rayon_core..job..HeapJob$LT$BODY$GT$$u20$as$u20$rayon_core..job..Job$GT$::execute::h357e1c2cabf7475b /builds/worker/checkouts/gecko/third_party/rust/rayon-core/src/job.rs:169:9
#44 0x7fa869934a43 in rayon_core::job::JobRef::execute::hdb4bfc6a4d44dc65 /builds/worker/checkouts/gecko/third_party/rust/rayon-core/src/job.rs:64:9
#45 0x7fa869934a43 in rayon_core::registry::WorkerThread::execute::h0550fbcda15c8212 /builds/worker/checkouts/gecko/third_party/rust/rayon-core/src/registry.rs:859:13
#46 0x7fa869934a43 in rayon_core::registry::WorkerThread::wait_until_cold::hdc4fefacb16e7c0c /builds/worker/checkouts/gecko/third_party/rust/rayon-core/src/registry.rs:793:26
#47 0x7fa86993130c in rayon_core::registry::WorkerThread::wait_until::hd24fa7f46c51eebc /builds/worker/checkouts/gecko/third_party/rust/rayon-core/src/registry.rs:768:13
#48 0x7fa86993130c in rayon_core::registry::WorkerThread::wait_until_out_of_work::h3d6d947faa6dac05 /builds/worker/checkouts/gecko/third_party/rust/rayon-core/src/registry.rs:817:9
#49 0x7fa86993130c in rayon_core::registry::main_loop::hc07c0003137fa534 /builds/worker/checkouts/gecko/third_party/rust/rayon-core/src/registry.rs:922:5
#50 0x7fa86993130c in rayon_core::registry::ThreadBuilder::run::h1f8fcbaab1c5ecc1 /builds/worker/checkouts/gecko/third_party/rust/rayon-core/src/registry.rs:52:18
#51 0x7fa8693a70fe in style::global_style_data::thread_spawn::_$u7b$$u7b$closure$u7d$$u7d$::h784f9f50f742607b /builds/worker/checkouts/gecko/servo/components/style/global_style_data.rs:75:34
#52 0x7fa8693a70fe in std::sys_common::backtrace::__rust_begin_short_backtrace::h0fb9efd27e7e3577 /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/std/src/sys_common/backtrace.rs:154:18
#53 0x7fa8693b237b in std::thread::Builder::spawn_unchecked_::_$u7b$$u7b$closure$u7d$$u7d$::_$u7b$$u7b$closure$u7d$$u7d$::h406656ea46a81668 /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/std/src/thread/mod.rs:529:17
#54 0x7fa8693b237b in _$LT$core..panic..unwind_safe..AssertUnwindSafe$LT$F$GT$$u20$as$u20$core..ops..function..FnOnce$LT$$LP$$RP$$GT$$GT$::call_once::h152db91c58cdb5bc /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/core/src/panic/unwind_safe.rs:272:9
#55 0x7fa8693b237b in std::panicking::try::do_call::h93a97057b4dec44a /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/std/src/panicking.rs:552:40
#56 0x7fa8693b237b in std::panicking::try::h9def937b1c254698 /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/std/src/panicking.rs:516:19
#57 0x7fa8693b237b in std::panic::catch_unwind::h1c47a6fc8e9dc89b /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/std/src/panic.rs:142:14
#58 0x7fa8693b237b in std::thread::Builder::spawn_unchecked_::_$u7b$$u7b$closure$u7d$$u7d$::h7a5ded4e1ccbe021 /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/std/src/thread/mod.rs:528:30
#59 0x7fa8693b237b in core::ops::function::FnOnce::call_once$u7b$$u7b$vtable.shim$u7d$$u7d$::ha2cea7fec3d014c6 /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/core/src/ops/function.rs:250:5
#60 0x7fa869a1cb54 in _$LT$alloc..boxed..Box$LT$F$C$A$GT$$u20$as$u20$core..ops..function..FnOnce$LT$Args$GT$$GT$::call_once::hc7eafaff61e32df9 /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/alloc/src/boxed.rs:2007:9
#61 0x7fa869a1cb54 in _$LT$alloc..boxed..Box$LT$F$C$A$GT$$u20$as$u20$core..ops..function..FnOnce$LT$Args$GT$$GT$::call_once::h6ba4a5de48dd2304 /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/alloc/src/boxed.rs:2007:9
#62 0x7fa869a1cb54 in std::sys::unix::thread::Thread::new::thread_start::he469335aef763e45 /rustc/82e1608dfa6e0b5569232559e3d385fea5a93112/library/std/src/sys/unix/thread.rs:108:17
#63 0x7fa873a94ac2 in start_thread nptl/pthread_create.c:442:8
#64 0x7fa873b2684f  misc/../sysdeps/unix/sysv/linux/x86_64/clone3.S:81

Looks like this is on a Stylo thread, so Emilio might have some thoughts.

Flags: needinfo?(emilio)

Seems related to scroll animations. Boris, can you look?

I think this code is not shipped to release yet but Boris can probably confirm.

Flags: needinfo?(emilio) → needinfo?(boris.chiou)

(In reply to Emilio Cobos Álvarez (:emilio) from comment #2)

Seems related to scroll animations. Boris, can you look?

I think this code is not shipped to release yet but Boris can probably confirm.

Scroll animation is disabled on all channels, including Nightly. The call stack looks like we are trying to get the scroll range during animation restyle. Perhaps we have to find another thread-safe way to access it.

Attached file prefs.js

Is this disabled? This was found with a m-c debug build using this prefs.js file.

(In reply to Tyson Smith [:tsmith] from comment #4)

Created attachment 9378012 [details]
prefs.js

Is this disabled? This was found with a m-c debug build using this prefs.js file.

It looks like prefs.js doesn't enable it, and so we shouldn't create ScrollTimeline. So weird. :O

Is this on a regular debug build, or on a fuzzing debug build? Because we enable all css properties when fuzzing unconditionally.

Flags: needinfo?(twsmith)

Off-hand I can't repro this on a non-fuzzing build (visiting the url in comment 0)

(In reply to Emilio Cobos Álvarez (:emilio) from comment #6)

Is this on a regular debug build, or on a fuzzing debug build? Because we enable all css properties when fuzzing unconditionally.

Ah ha. Yes it is a fuzzing build.

Flags: needinfo?(twsmith)
Severity: -- → S3
Priority: -- → P3

Remove myself from ni because this is on my radar (because it blocks scroll-animations).

Flags: needinfo?(boris.chiou)

I am able to reproduce with a debug build (non-fuzzing) by visiting: https://developer.android.com/studio?hl=zh-cn without setting any prefs.

Flags: needinfo?(boris.chiou)

(In reply to Tyson Smith [:tsmith] (PTO) from comment #10)

I am able to reproduce with a debug build (non-fuzzing) by visiting: https://developer.android.com/studio?hl=zh-cn without setting any prefs.

Would you mind capturing and sharing a pernosco trace when you've got a chance?

RE "without setting any prefs" -- note that scroll-driven animations are default-enabled for Nightly-channel-only right now (not riding the trains), as of a few months ago in bug 1817303. So for the time being, any badness here is probably Nightly-only.

Flags: needinfo?(twsmith)

It seems we are trying to get the scroll range when styling (which is in multiple threads). A possible way to avoid this is to cache the range before styling. Perhaps we have to store the scroll range in the scroll timeline, or need some special ways to make sure we don't have to retrieve the scroll range from nsHTMLScrollFrame when styling. (Note. we need the scroll range for interpolation, which happens in animation-only traversal, during styling).

I remember that Boris told me that the scroll driven animation spec has been updated since we implemented it, and now the spec clearly describes when each scroll timeline updates their current time; https://drafts.csswg.org/scroll-animations-1/#event-loop . So once after we change our implementation to align with the updated spec, this assertion will be gone.

For live site testing we are scrolling the page to help load content. Since that is the case this bug is potentially blocking our ability to identify other issues with site-scout. Can you please prioritize a fix for this bug?

A Pernosco session is available here: https://pernos.co/debug/mHguREycBijj_NokwWj1Kw/index.html

Flags: needinfo?(twsmith)
Keywords: pernosco
Attached file (secure) (obsolete) —

It's not expected to retrive the the scrolled rect, i.e.
ScrollContainerFrame::GetScrolledRect() out of the main thread.
However, we need to get the offset (for interpolation) during restyling
(in parallel), so for now we just cache the range before sampling on the
main thread, for ScrollTimeline.

Bug 1817051 may revist this. For now it should be fine to avoid
hitting any assertion, given that this is only enabled on Nightly.

See Also: → 1980789
Duplicate of this bug: 1980789

Hey Boris, any chance you have time to revisit this issue? We are still hitting it frequently during live site testing.

(In reply to Tyson Smith [:tsmith] from comment #17)

Hey Boris, any chance you have time to revisit this issue? We are still hitting it frequently during live site testing.

I'm trying to fix in Bug 1817051, which caches the offsets in HTML event loop (so it is on the main thread). When we restyle the element, we just retrieve the cached current time.

We can verify this after we finish Bug 1817051.

Depends on: 1817051
Flags: needinfo?(boris.chiou)
Blocks: 1954230
Attachment #9500184 - Attachment is obsolete: true

We landed Bug 1817051 recently. Tyson, could you please verify the patch to make sure we fix this bug? Thanks.

Flags: needinfo?(twsmith)

Of course, thanks for the heads up. The last report was from m-c 20251215-88405e58e2b8.

Status: NEW → RESOLVED
Closed: 9 months ago
Flags: needinfo?(twsmith)
Resolution: --- → FIXED
Group: layout-core-security → core-security-release
Assignee: nobody → boris.chiou
Target Milestone: --- → 148 Branch
QA Whiteboard: [sec] [qa-triage-done-c149/b148]
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: