Open Bug 1954233 Opened 1 year ago Updated 1 year ago

Crash in [@ mozilla::dom::BrowsingContextGroup::AddDocument]

Categories

(Core :: DOM: Navigation, defect)

Unspecified
Windows 11
defect

Tracking

()

Tracking Status
firefox-esr115 --- unaffected
firefox-esr128 --- unaffected
firefox-esr140 --- wontfix
firefox136 --- unaffected
firefox137 --- unaffected
firefox138 --- wontfix
firefox139 --- wontfix
firefox140 --- wontfix

People

(Reporter: mccr8, Assigned: nika)

References

(Regression)

Details

(Keywords: crash, regression)

Crash Data

Crash report: https://crash-stats.mozilla.org/report/index/4d819e0c-1020-4527-85e5-280610250304

MOZ_CRASH Reason:

MOZ_CRASH(Document loading without first determining origin keying for origin!)

Top 10 frames:

0  xul.dll  mozilla::dom::BrowsingContextGroup::AddDocument(mozilla::dom::Document*)  docshell/base/BrowsingContextGroup.cpp:490
0  xul.dll  mozilla::dom::Document::GetDocGroupOrCreate()  dom/base/Document.cpp:7901
1  xul.dll  mozilla::dom::Document::SetScopeObject(nsIGlobalObject*)  dom/base/Document.cpp:7918
2  xul.dll  mozilla::dom::Document::SetScriptGlobalObject(nsIScriptGlobalObject*)  dom/base/Document.cpp:8097
3  xul.dll  nsGlobalWindowOuter::SetNewDocument(mozilla::dom::Document*, nsISupports*, bo...  dom/base/nsGlobalWindowOuter.cpp:2411
4  xul.dll  nsDocumentViewer::InitInternal(nsIWidget*, nsISupports*, mozilla::dom::Window...  layout/base/nsDocumentViewer.cpp:898
5  xul.dll  nsDocumentViewer::Init(nsIWidget*, mozilla::gfx::IntRectTyped<mozilla::Layout...  layout/base/nsDocumentViewer.cpp:679
6  xul.dll  nsDocShell::SetupNewViewer(nsIDocumentViewer*, mozilla::dom::WindowGlobalChild*)  docshell/base/nsDocShell.cpp:7992
6  xul.dll  nsDocShell::Embed(nsIDocumentViewer*, mozilla::dom::WindowGlobalChild*, bool,...  docshell/base/nsDocShell.cpp:5497
7  xul.dll  nsDocShell::CreateDocumentViewer(nsTSubstring<char> const&, nsIRequest*, nsIS...  docshell/base/nsDocShell.cpp:7822

It looks like this crash was added in bug 1665474. However, it is behind MOZ_DIAGNOSTIC_ASSERT_ENABLED so it won't affect late beta or release.

The crash signature is older, but the older crashes don't have this crash reason.

Set release status flags based on info from the regressing bug 1665474

:nika, since you are the author of the regressor, bug 1665474, could you take a look? Also, could you set the severity field?

For more information, please visit BugBot documentation.

See Also: → 1954597

I've filed bug 1954597, which I hope will fix these crashes by hardening the checks around this code.

Assignee: nobody → nika
Flags: needinfo?(nika)
Severity: -- → S3
You need to log in before you can comment on or make changes to this bug.