Closed Bug 188474 Opened 23 years ago Closed 23 years ago

M130B Trunk crash [@ SinkContext::AddComment ]

Categories

(Core :: DOM: HTML Parser, defect)

defect
Not set
critical

Tracking

()

VERIFIED WORKSFORME

People

(Reporter: bugzilla, Assigned: harishd)

References

()

Details

(Keywords: crash, testcase, topcrash+)

Crash Data

Attachments

(1 file, 1 obsolete file)

going to: http://nyhedsgrupper.tdconline.dk crashes mozilla 20030109 on WinXP
Keywords: crash
confirming using build 2003010808 on Win2k: TB16006921X.
Severity: normal → critical
Keywords: stackwanted
Whiteboard: TB16006921X
stephend, could you get the stack?
Attached file Reduced (HTML) testcase (obsolete) —
This testcase crashes, note however that loading http://nyhedsgrupper.tdconline.dk/usenet.js directly in browser also crashes Mozilla. Maybe a document.write() regression ?
Comment on attachment 111156 [details] Reduced (HTML) testcase sorry for the spam, this testcase crashed for me when loading usenet.js from local file, does not crash when loading usenet.js from external server. Will try to reduce the JS in a next testcase.
Attachment #111156 - Attachment is obsolete: true
This time, reduced testcase.
Hmm. Reduced testcase crash me on WinXP with Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.3b) Gecko/20030109, but initial site not. Not crashed with Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.2.1) Gecko/20021130 on Win98. BTW, I think div foo could be removed, and a comment from header.
Both testcases are also working (= NO crash) with mozilla 20021211 on NT 4..
Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.3b) Gecko/20030108 TB16012223E, TB16012435E, TB16012910H, TB16013392H All talkbacks but one from original URL, last talkback from fresh booted Win98SE, fresh started mozilla. One talkback from crash at closing mozilla: After crash restarted mozilla to copy data (bug-# and URL), the sent talkback, closed that newly opened mozilla, crash.
Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.3b) Gecko/20030108 TB16013751Z 2nd reduced testcase
must be dupe of bug 185073.
Keywords: testcase
URL and testcase workforme with linux cvs trunk from yesterday. patch for bug 185073 was checked in this morning (4:30AM). you might try a build from today.
Regression between Jan, 3rd and Jan 4th Build ID 2003010304 Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.3b) Gecko/20030103 is ok Build ID 2003010408 Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.3b) Gecko/20030104 crashes TB16014329K, TB16015761W, TB16015876H
Works for me now, Build ID 2003011004 Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.3b) Gecko/20030110
Im not sure that this was the same as bug 185073. I dont crash in my current cvs debug build, both with and without the patch from that bug. So, really cant say without looking at a stack or further investigation.
also crashes Linux build 20030109, not 20030110. OS -> All.
OS: Windows XP → All
Hardware: PC → All
SinkContext::AddComment [c:/builds/seamonkey/mozilla/content/html/document/src/nsHTMLContentSink.cpp, line 1955] HTMLContentSink::AddComment [c:/builds/seamonkey/mozilla/content/html/document/src/nsHTMLContentSink.cpp, line 3673] CNavDTD::HandleCommentToken [c:/builds/seamonkey/mozilla/htmlparser/src/CNavDTD.cpp, line 2256] CNavDTD::HandleToken [c:/builds/seamonkey/mozilla/htmlparser/src/CNavDTD.cpp, line 963]
Keywords: stackwanted
Whiteboard: TB16006921X
To parser. I bet this _is_ a dup of bug 185073 -- the parent we are trying to append to is garbage when I crash.... Note that whether the crash happens depends on what random memory the parent pointer is pointing to, so some people may not see this _every_ time. In any case, I crash on the testcase with builds up to this morning; this morning's build does _not_ crash.
Assignee: asa → harishd
Component: Browser-General → Parser
Depends on: 185073
QA Contact: asa → moied
WFM in 20030110.
Status: NEW → RESOLVED
Closed: 23 years ago
Resolution: --- → WORKSFORME
Summary: http://nyhedsgrupper.tdconline.dk crash → http://nyhedsgrupper.tdconline.dk crash [@ SinkContext::AddComment ]
v
Status: RESOLVED → VERIFIED
Adding topcrash keyword for future reference...this *was* a topcrasher on the MozillaTrunk. No crashes reported after builds from 1/10.
Keywords: topcrash
Reopening for now to see what everyone else thinks...but I just crashed with a similar stacktrace going to http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=3008284272&category=15046 . Here is my incident: Incident ID 17300619 Stack Signature SinkContext::AddComment 3aeac5d5 Email Address jpatel@netscape.com Product ID MozillaTrunk Build ID 2003021008 Trigger Time 2003-02-18 13:09:11 Platform Win32 Operating System Windows NT 5.1 build 2600 Module gklayout.dll URL visited http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=3008284272&category=15046 User Comments Just cut and pasted the URL and tried to load. Crashed immediately. Trigger Reason Access violation Source File Name c:/builds/seamonkey/mozilla/content/html/document/src/nsHTMLContentSink.cpp Trigger Line No. 1957 Stack Trace SinkContext::AddComment [c:/builds/seamonkey/mozilla/content/html/document/src/nsHTMLContentSink.cpp, line 1957] HTMLContentSink::AddComment [c:/builds/seamonkey/mozilla/content/html/document/src/nsHTMLContentSink.cpp, line 3677] CNavDTD::HandleCommentToken [c:/builds/seamonkey/mozilla/htmlparser/src/CNavDTD.cpp, line 2243] CNavDTD::HandleToken [c:/builds/seamonkey/mozilla/htmlparser/src/CNavDTD.cpp, line 961] CNavDTD::BuildModel [c:/builds/seamonkey/mozilla/htmlparser/src/CNavDTD.cpp, line 528] nsParser::BuildModel [c:/builds/seamonkey/mozilla/htmlparser/src/nsParser.cpp, line 1909] nsParser::ResumeParse [c:/builds/seamonkey/mozilla/htmlparser/src/nsParser.cpp, line 1773] nsParser::ContinueParsing [c:/builds/seamonkey/mozilla/htmlparser/src/nsParser.cpp, line 1390] HTMLContentSink::ScriptEvaluated [c:/builds/seamonkey/mozilla/content/html/document/src/nsHTMLContentSink.cpp, line 5595] nsScriptLoader::FireScriptEvaluated [c:/builds/seamonkey/mozilla/content/base/src/nsScriptLoader.cpp, line 533] nsScriptLoader::ProcessRequest [c:/builds/seamonkey/mozilla/content/base/src/nsScriptLoader.cpp, line 492] nsScriptLoader::OnStreamComplete [c:/builds/seamonkey/mozilla/content/base/src/nsScriptLoader.cpp, line 832] nsStreamLoader::OnStopRequest [c:/builds/seamonkey/mozilla/netwerk/base/src/nsStreamLoader.cpp, line 144] nsStreamListenerTee::OnStopRequest [c:/builds/seamonkey/mozilla/netwerk/base/src/nsStreamListenerTee.cpp, line 66] nsHttpChannel::OnStopRequest [c:/builds/seamonkey/mozilla/netwerk/protocol/http/src/nsHttpChannel.cpp, line 2951] nsInputStreamPump::OnStateStop [c:/builds/seamonkey/mozilla/netwerk/base/src/nsInputStreamPump.cpp, line 468] nsInputStreamPump::OnInputStreamReady [c:/builds/seamonkey/mozilla/netwerk/base/src/nsInputStreamPump.cpp, line 321] nsInputStreamReadyEvent::EventHandler [c:/builds/seamonkey/mozilla/xpcom/io/nsStreamUtils.cpp, line 112] PL_HandleEvent [c:/builds/seamonkey/mozilla/xpcom/threads/plevent.c, line 664] PL_ProcessPendingEvents [c:/builds/seamonkey/mozilla/xpcom/threads/plevent.c, line 597] _md_EventReceiverProc [c:/builds/seamonkey/mozilla/xpcom/threads/plevent.c, line 1386] USER32.dll + 0x3d91 (0x77d43d91) USER32.dll + 0x3df7 (0x77d43df7) nsAppShellService::Run [c:/builds/seamonkey/mozilla/xpfe/appshell/src/nsAppShellService.cpp, line 480] main1 [c:/builds/seamonkey/mozilla/xpfe/bootstrap/nsAppRunner.cpp, line 1289] main [c:/builds/seamonkey/mozilla/xpfe/bootstrap/nsAppRunner.cpp, line 1639] WinMain [c:/builds/seamonkey/mozilla/xpfe/bootstrap/nsAppRunner.cpp, line 1660] WinMainCRTStartup() kernel32.dll + 0x214c7 (0x77e814c7) If that is the same crash, I can add more Talkback data. But since the testcase attached no longer crashes, let me know if I should log a new bug. Thanks.
Status: VERIFIED → REOPENED
Keywords: topcrashtopcrash+
Resolution: WORKSFORME → ---
Summary: http://nyhedsgrupper.tdconline.dk crash [@ SinkContext::AddComment ] → M130B Trunk crash [@ SinkContext::AddComment ]
filed bug 194329 for the new crash (it appears to be different) re-resolving WFM
Status: REOPENED → RESOLVED
Closed: 23 years ago23 years ago
Resolution: --- → WORKSFORME
v.wfm.
Status: RESOLVED → VERIFIED
Flags: in-testsuite+
Crash Signature: [@ SinkContext::AddComment ]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: