[2123] Assertion failure: false (MOZ_ASSERT_UNREACHABLE: Trying to manually manage activeness of a browsing context that isn't manually managed (see manualactiveness attribute)), at docshell/base/CanonicalBrowsingContext.cpp:3426
Categories
(Firefox :: Tabbed Browser, defect)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox-esr115 | --- | unaffected |
| firefox-esr140 | --- | unaffected |
| firefox146 | --- | unaffected |
| firefox147 | --- | disabled |
| firefox148 | --- | wontfix |
| firefox151 | --- | wontfix |
| firefox152 | --- | wontfix |
| firefox153 | --- | fixed |
People
(Reporter: petr.sumbera, Assigned: vhilla)
References
(Regression)
Details
(Keywords: regression)
Attachments
(2 files, 1 obsolete file)
Steps to reproduce:
Firefox on SPARC Solaris (Intel is ok) hits following assertion:
[2123] Assertion failure: false (MOZ_ASSERT_UNREACHABLE: Trying to manually manage activeness of a browsing context that isn't manually managed (see manualactiveness attribute)), at /builds/psumbera/mozilla-ce
ntral-build/docshell/base/CanonicalBrowsingContext.cpp:3426
#01: mozilla::dom::CanonicalBrowsingContext::SetIsActive(bool, mozilla::ErrorResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x272ffbe8]
#02: mozilla::dom::CanonicalBrowsingContext_Binding::set_isActive(JSContext*, JS::Handle<JSObject*>, void*, JSJitSetterCallArgs)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1fab2a
f4]
#03: bool mozilla::dom::binding_detail::GenericSetter<mozilla::dom::binding_detail::NormalThisPolicy>(JSContext*, unsigned int, JS::Value*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.s
o +0x21589fec]
#04: CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac63434]
#05: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac360f8]
#06: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac368a4]
#07: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libx
ul.so +0x2ac36b58]
#08: js::CallSetter(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac37e28]
#09: SetExistingProperty(JSContext*, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<js::NativeObject*>, js::PropertyResult const&, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28e35b30]
#10: bool js::NativeSetProperty<(js::QualifiedBool)1>(JSContext*, JS::Handle<js::NativeObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28e4def0]
#11: js::SetProperty(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x288d71f0]
#12: SetObjectElementOperation(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3bf00]
#13: js::Interpret(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac48a48]
#14: MaybeEnterInterpreterTrampoline(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3508c]
#15: js::RunScript(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3591c]
#16: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3636c]
#17: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac368a4]
#18: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac36b58]
#19: js::CallSetter(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac37e28]
#20: SetExistingProperty(JSContext*, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<js::NativeObject*>, js::PropertyResult const&, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28e35b30]
#21: bool js::NativeSetProperty<(js::QualifiedBool)1>(JSContext*, JS::Handle<js::NativeObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28e4def0]
#22: js::SetProperty(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x288d71f0]
#23: SetObjectElementOperation(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3bf00]
#24: js::Interpret(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac48a48]
#25: MaybeEnterInterpreterTrampoline(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3508c]
#26: js::RunScript(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3591c]
#27: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3636c]
#28: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac368a4]
#29: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac36b58]
#30: js::CallSelfHostedFunction(JSContext*, JS::Handle<js::PropertyName*>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28f37538]
#31: AsyncFunctionResume(JSContext*, JS::Handle<js::AsyncFunctionGeneratorObject*>, ResumeKind, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x289dafa8]
#32: js::AsyncFunctionAwaitedFulfilled(JSContext*, JS::Handle<js::AsyncFunctionGeneratorObject*>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x289db518]
#33: AsyncFunctionPromiseReactionJob(JSContext*, JS::Handle<PromiseReactionRecord*>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28d9003c]
#34: PromiseReactionJob(JSContext*, JS::Handle<JSObject*>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28d905f4]
#35: PromiseReactionJob(JSContext*, unsigned int, JS::Value*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28d91414]
#36: CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac63434]
#37: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac360f8]
#38: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac368a4]
#39: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac36b58]
#40: JS::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::HandleValueArray const&, JS::MutableHandle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28a82654]
#41: mozilla::PromiseJobRunnable::Call()[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a7e6908]
#42: mozilla::PromiseJobRunnable::Run(mozilla::AutoSlowOperation&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a7e6b60]
#43: mozilla::CycleCollectedJSContext::PerformMicroTaskCheckPoint(bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a7a46d8]
#44: mozilla::CycleCollectedJSContext::AfterProcessTask(unsigned int)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a7a07a0]
#45: XPCJSContext::AfterProcessTask(unsigned int)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1c5f0bc8]
#46: nsThread::ProcessNextEvent(bool, bool*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1aaccce4]
#47: NS_ProcessNextEvent(nsIThread*, bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1aaded2c]
#48: bool mozilla::SpinEventLoopUntil<(mozilla::ProcessFailureBehavior)1, nsThreadManager::SpinEventLoopUntilInternal(nsTSubstring<char> const&, nsINestedEventLoopCondition*, mozilla::ShutdownPhase)::{lambda()#1}>(nsTSubstring<char> const&, nsThreadManager::Sp[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1aae7cf0]
#49: nsThreadManager::SpinEventLoopUntilInternal(nsTSubstring<char> const&, nsINestedEventLoopCondition*, mozilla::ShutdownPhase)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1aad46bc]
#50: nsThreadManager::SpinEventLoopUntil(nsTSubstring<char> const&, nsINestedEventLoopCondition*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1aad42ec]
#51: NS_InvokeByIndex[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1ab4c9a0]
[RDD 3175, IPC I/O Child] WARNING: [7573429099466DCF.4508A3F7C3C8A27A]: Dropping message '<null>'; no connection to unknown peer 1.1: file /builds/psumbera/mozilla-central-build/ipc/glue/NodeController.cpp:366
[Socket 3086, IPC I/O Child] WARNING: [5BEDA902A8A94EB5.ED9963054C3A2FAB]: Dropping message '<null>'; no connection to unknown peer 1.1: file /builds/psumbera/mozilla-central-build/ipc/glue/NodeController.cpp:366
[Child 3174, IPC I/O Child] WARNING: [BC1F0CE9263BCE09.D1D7E3F6449791C8]: Dropping message '<null>'; no connection to unknown peer 1.1: file /builds/psumbera/mozilla-central-build/ipc/glue/NodeController.cpp:366
[Socket 3086, Main Thread] WARNING: Shutting down Socket process early due to a crash!: file /builds/psumbera/mozilla-central-build/netwerk/ipc/SocketProcessChild.cpp:240
[RDD 3175, Main Thread] WARNING: Shutting down RDD process early due to a crash!: file /builds/psumbera/mozilla-central-build/dom/media/ipc/RDDParent.cpp:319
Crash Annotation GraphicsCriticalError: |[C0][GFX1-]: CompositorBridgeChild receives IPC close with reason=AbnormalShutdown (t=61.3404) [GFX1-]: CompositorBridgeChild receives IPC close with reason=AbnormalShutdown
Exiting due to channel error.
This first is commit was:
changeset: 818157:5f9e366c17fc
user: Henri Sivonen <hsivonen@hsivonen.fi>
date: Mon Nov 24 06:32:05 2025 +0100
description:
Bug 543435 - Make initial about:blank not get overwritten by an async about:blank load. r=sessionstore-reviewers,sfoster,timhuang,credential-management-reviewers,issammani,webidl,extension-reviewers,tabbrowser-reviewers,migration-reviewers,home-newtab-reviewers,hsivonen,cookie-reviewers,fxview-reviewers,firefox-desktop-core-reviewers ,dao,valentin,mossop,smaug,geckoview-reviewers,Jamie,mtigley,thecount,media-playback-reviewers,padenot,dom-worker-reviewers,jesup,jdescottes,asuth,robwu,karlt,profiler-reviewers,kpatenio,devtools-reviewers,tcampbell,nchevobbe
Co-authored-by: Vincent Hilla <vhilla@mozilla.com>
Signed-off-by: Vincent Hilla <vhilla@mozilla.com>
Differential Revision: https://phabricator.services.mozilla.com/D155376
| Reporter | ||
Updated•9 months ago
|
Comment 1•9 months ago
|
||
:vhilla, since you are the author of the regressor, bug 543435, could you take a look? Also, could you set the severity field?
For more information, please visit BugBot documentation.
Too many places to guess:
https://searchfox.org/firefox-main/search?q=symbol:%23docShellIsActive&redirect=false
Reporter, could you, please, do p DumpJSStack() in gdb when you see this failure?
I don't see any cases where there'd be an opportunity for an about:blank load between the creation of a top-level browsing context and setting the manualactiveness attribute.
Setting severity per the bot request: It seems to me this can't be higher than S3. This is a debug assertion on the front end's own assumptions, and if this occurred commonly across platforms, I'd expect an assertions-enabled build on any platform to encounter this.
tsmith, do your assertions-enabled runs exercise opening new tabs and windows?
| Reporter | ||
Comment 4•9 months ago
|
||
I should add that I see it only when I run: firefox --screenshot about:blank
(In reply to Petr Sumbera from comment #4)
I should add that I see it only when I run:
firefox --screenshot about:blank
I don't see the assertion in that case on x86_64 Linux.
| Reporter | ||
Comment 7•9 months ago
|
||
(In reply to Emilio Cobos Álvarez [:emilio] from comment #5)
We dump the JS stack right before crashing here, what does that say?
0 set docShellIsActive(val = "true") ["chrome://global/content/elements/browser-custom-element.mjs":498:5]
this = [object XULFrameElement]
1 createBrowserElement() ["resource://gre/modules/ExtensionParent.sys.mjs":1505:5]
2 AsyncFunctionNext(val = "[object Event]") ["self-hosted":780:27]
this = [object Object]
3 observe("null", ""quit-application"", ""shutdown"") ["resource://gre/modules/AsyncShutdown.sys.mjs":570:17]
this = [object Object]
4 handleCmdLineArgs() ["moz-src:///browser/components/shell/HeadlessShell.sys.mjs":256:24]
5 AsyncFunctionNext(val = "undefined") ["self-hosted":780:27]
this = [object Object]
``
Comment 8•9 months ago
|
||
But that sets the attribute above... So maybe something unbinds the embedder from the browsing context.
Comment 9•9 months ago
|
||
(In reply to Henri Sivonen (:hsivonen) from comment #3)
tsmith, do your assertions-enabled runs exercise opening new tabs and windows?
Some of the fuzzers do. Live site testing does not open new tabs or windows. Unfortunately I have not seen this assertion reported.
The plan for 147 is to back bug 543435 out of beta in bug 2003720.
| Reporter | ||
Comment 11•9 months ago
|
||
Now I see it also on x86_64 (after Bug 2003043 was integrated) :
0 set docShellIsActive(val = "true") ["chrome://global/content/elements/browser-custom-element.mjs":498:5]
this = [object XULFrameElement]
1 createBrowserElement() ["resource://gre/modules/ExtensionParent.sys.mjs":1505:5]
2 AsyncFunctionNext(val = "[object Event]") ["self-hosted":780:27]
this = [object Object]
3 observe("null", ""quit-application"", ""shutdown"") ["resource://gre/modules/AsyncShutdown.sys.mjs":570:17]
this = [object Object]
4 handleCmdLineArgs() ["moz-src:///browser/components/shell/HeadlessShell.sys.mjs":256:24]
5 InterpretGeneratorResume(gen = "[object Object]", val = "undefined", kind = ""next"") ["self-hosted":1317:34]
6 AsyncFunctionNext(val = "undefined") ["self-hosted":780:27]
this = [object Object]
[837880] Assertion failure: false (MOZ_ASSERT_UNREACHABLE: Trying to manually manage activeness of a browsing context that isn't manually managed (see manualactiveness attribute)), at /builds/psumbera/mozilla-central-build/docshell/base/CanonicalBrowsingContext.cpp:3441
#01: mozilla::dom::CanonicalBrowsingContext::SetIsActive(bool, mozilla::ErrorResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2820e4ab]
#02: mozilla::dom::CanonicalBrowsingContext_Binding::set_isActive(JSContext*, JS::Handle<JSObject*>, void*, JSJitSetterCallArgs)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x22dc7c9a]
#03: bool mozilla::dom::binding_detail::GenericSetter<mozilla::dom::binding_detail::NormalThisPolicy>(JSContext*, unsigned int, JS::Value*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x24085b57]
#04: CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aa829e2]
#05: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aa61114]
#06: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aa615f2]
#07: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aa617b8]
#08: js::CallSetter(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aa62445]
#09: SetExistingProperty(JSContext*, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<js::NativeObject*>, js::PropertyResult const&, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2950e706]
#10: bool js::NativeSetProperty<(js::QualifiedBool)1>(JSContext*, JS::Handle<js::NativeObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2951f90d]
..
Comment 12•9 months ago
|
||
Bug 543435 was reverted from Fx147. Updating the flags accordingly.
Comment 13•9 months ago
|
||
The bug has a release status flag that shows some version of Firefox is affected, thus it will be considered confirmed.
| Reporter | ||
Comment 14•9 months ago
|
||
I started to see it on SPARC again:
0 set docShellIsActive(val = "true") ["chrome://global/content/elements/browser-custom-element.mjs":498:5]
this = [object XULFrameElement]
1 createBrowserElement() ["resource://gre/modules/ExtensionParent.sys.mjs":1505:5]
2 AsyncFunctionNext(val = "[object Event]") ["self-hosted":780:27]
this = [object Object]
3 observe("null", ""quit-application"", ""shutdown"") ["resource://gre/modules/AsyncShutdown.sys.mjs":570:17]
this = [object Object]
4 handleCmdLineArgs() ["moz-src:///browser/components/shell/HeadlessShell.sys.mjs":256:24]
5 AsyncFunctionNext(val = "undefined") ["self-hosted":780:27]
this = [object Object]
[830] Assertion failure: false (MOZ_ASSERT_UNREACHABLE: Trying to manually manage activeness of a browsing context that isn't manually managed (see manualactiveness attribute)), at /builds/psumbera/mozilla-cen
tral-build/docshell/base/CanonicalBrowsingContext.cpp:3441
#01: mozilla::dom::CanonicalBrowsingContext::SetIsActive(bool, mozilla::ErrorResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x27566ac4]
#02: mozilla::dom::CanonicalBrowsingContext_Binding::set_isActive(JSContext*, JS::Handle<JSObject*>, void*, JSJitSetterCallArgs)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1fcca2
dc]
#03: bool mozilla::dom::binding_detail::GenericSetter<mozilla::dom::binding_detail::NormalThisPolicy>(JSContext*, unsigned int, JS::Value*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.s
o +0x217b0774]
#04: CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2af09304]
#05: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedbfc8]
#06: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedc774]
#07: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libx
ul.so +0x2aedca28]
#08: js::CallSetter(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aeddcf8]
#09: SetExistingProperty(JSContext*, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<js::NativeObject*>, js::PropertyResult const&, JS::ObjectOpResult&)[/builds/psumbera/m
ozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x290c49c8]
#10: bool js::NativeSetProperty<(js::QualifiedBool)1>(JSContext*, JS::Handle<js::NativeObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera
/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x290dcd88]
#11: js::SetProperty(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/fire
fox/libxul.so +0x28b62d58]
#12: SetObjectElementOperation(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/l
ibxul.so +0x2aee1dd0]
#13: js::Interpret(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aeee918]
#14: MaybeEnterInterpreterTrampoline(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedaf5c]
#15: js::RunScript(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedb7ec]
#16: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedc23c]
#17: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedc774]
#18: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedca28]
#19: js::CallSetter(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aeddcf8]
#20: SetExistingProperty(JSContext*, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<js::NativeObject*>, js::PropertyResult const&, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x290c49c8]
#21: bool js::NativeSetProperty<(js::QualifiedBool)1>(JSContext*, JS::Handle<js::NativeObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x290dcd88]
#22: js::SetProperty(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28b62d58]
#23: SetObjectElementOperation(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aee1dd0]
#24: js::Interpret(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aeee918]
#25: MaybeEnterInterpreterTrampoline(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedaf5c]
#26: js::RunScript(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedb7ec]
#27: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedc23c]
#28: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedc774]
#29: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedca28]
#30: js::CallSelfHostedFunction(JSContext*, JS::Handle<js::PropertyName*>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x291c71b4]
#31: AsyncFunctionResume(JSContext*, JS::Handle<js::AsyncFunctionGeneratorObject*>, ResumeKind, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28c67004]
#32: js::AsyncFunctionAwaitedFulfilled(JSContext*, JS::Handle<js::AsyncFunctionGeneratorObject*>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28c67574]
#33: AsyncFunctionPromiseReactionJob(JSContext*, JS::Handle<PromiseReactionRecord*>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2901e580]
#34: PromiseReactionJob(JSContext*, JS::Handle<JSObject*>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2901eb38]
#35: JS::RunJSMicroTask(JSContext*, JS::Handle<JSObject*>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x29034e60]
#36: mozilla::MustConsumeMicroTask::RunAndConsumeJSMicroTask(JSContext*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a98fd94]
#37: mozilla::RunMicroTask(JSContext*, JS::MutableHandle<mozilla::MustConsumeMicroTask>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a96a730]
#38: mozilla::CycleCollectedJSContext::PerformMicroTaskCheckPoint(bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a96bc4c]
#39: mozilla::CycleCollectedJSContext::AfterProcessTask(unsigned int)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a9682dc]
#40: XPCJSContext::AfterProcessTask(unsigned int)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1c7e73cc]
#41: nsThread::ProcessNextEvent(bool, bool*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1ac984c4]
#42: NS_ProcessNextEvent(nsIThread*, bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1acaa500]
#43: bool mozilla::SpinEventLoopUntil<(mozilla::ProcessFailureBehavior)1, nsThreadManager::SpinEventLoopUntilInternal(nsTSubstring<char> const&, nsINestedEventLoopCondition*, mozilla::ShutdownPhase)::{lambda()#1}>(nsTSubstring<char> const&, nsThreadManager::Sp[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1acb34c4]
#44: nsThreadManager::SpinEventLoopUntilInternal(nsTSubstring<char> const&, nsINestedEventLoopCondition*, mozilla::ShutdownPhase)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1ac9fe9c]
#45: nsThreadManager::SpinEventLoopUntil(nsTSubstring<char> const&, nsINestedEventLoopCondition*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1ac9facc]
#46: NS_InvokeByIndex[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1ad18180]
Comment 15•9 months ago
|
||
(In reply to Emilio Cobos Álvarez [:emilio] from comment #8)
But that sets the attribute above... So maybe something unbinds the embedder from the browsing context.
Rob do you know off-hand how this could happen? Should we bail out from ExtensionParent initialization if the app is shutting down?
Comment 16•9 months ago
|
||
(In reply to Emilio Cobos Álvarez [:emilio] from comment #15)
(In reply to Emilio Cobos Álvarez [:emilio] from comment #8)
But that sets the attribute above... So maybe something unbinds the embedder from the browsing context.
Rob do you know off-hand how this could happen? Should we bail out from ExtensionParent initialization if the app is shutting down?
We could bail out indeed, if that is needed to fix this bug. Up in the stack, we already (eventually) clean up if shutdown has commenced.
This bug reminds me of bug 1959339, where shutdown commences while extensions are still starting. It could easily be reproduced by screenshotting about:blank. Coincidentally, the reporter of that bug is the same as the reporter of this bug.
I can imagine an about:blank load happening if the extension load request is aborted, e.g. at shutdown.
The keywords of this bug reminds me of bug 1901894, a case from the past where there was an "unexpected" about:blank load in the background browser. This is likely unrelated, but there may be useful information to aid in debugging.
| Comment hidden (Intermittent Failures Robot) |
| Comment hidden (Intermittent Failures Robot) |
| Comment hidden (Intermittent Failures Robot) |
| Comment hidden (Intermittent Failures Robot) |
| Comment hidden (Intermittent Failures Robot) |
Comment 22•4 months ago
|
||
I see this as well for a lot of CI jobs for the following try build:
Note that these WebDriver tests open Firefox, attempt to run a navigation, and then immediately quit Firefox again. Here the crash details:
The stack of the crashing thread is quite huge but when scrolling down I can see nsContentUtils::DispatchTrustedEvent and based on its parent frame it most likely is the load event that is getting dispatched but fails.
Comment 23•4 months ago
|
||
The actual test which triggers this failure for this try push is the following:
@pytest.mark.allow_system_access
async def test_chrome_url_with_system_access(bidi_session, new_tab):
CHROME_URL = "chrome://browser/content/browser.xhtml"
await bidi_session.browsing_context.navigate(
context=new_tab["context"], url=CHROME_URL, wait="complete"
)
contexts = await bidi_session.browsing_context.get_tree(
root=new_tab["context"], max_depth=0
)
assert contexts[0]["url"] == CHROME_URL
Here we are navigating to a chrome:// URL within a tab.
It can as well easily be reproduced with a debug build when loading chrome://browser/content/browser.xhtml via the location bar.
Maybe the two different scenarios have the same underlying reason? Vincent, could you take a look?
| Assignee | ||
Comment 25•4 months ago
|
||
(In reply to Emilio Cobos Álvarez [:emilio] from comment #24)
Loading browser.xhtml in a tab is not a use case we want to support.
It does work in Nightly :(
| Assignee | ||
Comment 27•4 months ago
|
||
Based on Rob's comment, I can reproduce this bug flakily on Mac debug build with ./mach run --temp-profile -screenshot about:blank
I can confirm that GetEmbedderElement() is null. In ExtensionParent right before setting docShellIsActive, it is browser.isConnected=true, this.unloaded=false, Services.startup.shuttingDown=true, browser.browsingContext.embedderElement=null.
I'll put up a patch to make it clearer if the assertion fails due to a lack of an embedder element. And I'll add a check to HiddenXULWindow.createBrowserElement before setting docShellIsActive.
Regarding WebDriver / chrome://, that seems to be an unrelated issue.
Pernosco: https://pernos.co/debug/A7OiKW8-A6GAH7u0AMWrSg/index.html
Tabbrowser._setupInitialBrowserAndTab binds some panel and then activates it. But BrowsingContext::SetEmbedderElement never runs, likely because nsFrameLoader::ShowRemoteFrame fails with NS_ERROR("Couldn't create child process."). It fails because !EnsureRemoteBrowser(), which is due to the URI being disallowed.
| Assignee | ||
Updated•4 months ago
|
| Assignee | ||
Comment 28•4 months ago
|
||
This avoids crashing in debug when shutdown races with ExtensionParent
activating a browser.
This change also tweaks the assertion to be clearer when the embedder is
missing, rather than manualactiveness not set.
Updated•4 months ago
|
Comment 29•4 months ago
|
||
The patch above does something special for extensions, but I wonder whether it really should be extension-specific. Logically there is something odd going on:
The JS side calls browser.docShellIsActive = true, triggering https://searchfox.org/firefox-main/rev/cebc55aab4d2661d1f6c2d1526362947ec4016c1/toolkit/content/widgets/browser-custom-element.mjs#503-514 :
- returns early (and silently) when
this.browsingContextis void. - then sets
this.browsingContext.isActive = val; - then checks if
isRemoteBrowser, and if so, conditionally interacts withthis.frameLoader.
The assertion here is a debug-only assertion, but it does cause differences between debug and release:
- the
frameLoader?.check later suggests thatisActivecan be set even if frameLoader is unset. - but the implementation does a debug-only check, relying on
GetEmbedderElement(). Which can be nullptr if frameLoader is null:embedderElementcan be null ifnsFrameLoader::SetOwnerContentis called with nullptr. That happens whennsFrameLoader::StartDestroyis called.
Do you have a pernosco trace that shows how we get in this situation?
Alternatively add a profile marker in nsFrameLoader::StartDestroy (or its only caller - nsFrameLoader::Destroy and capture a profile and share that profile.
| Comment hidden (Intermittent Failures Robot) |
| Assignee | ||
Comment 31•3 months ago
|
||
No pernosco on Mac, unsure how to get a profile while using -screenshot. But here's a log with MozWalkTheStack during nsFrameLoader::StartDestroy.
| Assignee | ||
Comment 32•3 months ago
•
|
||
Right, there's
Failure taking screenshot: [Exception... "Data conversion failed because significant data would be lost" nsresult: "0x80460003 (NS_ERROR_LOSS_OF_SIGNIFICANT_DATA)" location: "<unknown>" data: no]
and whenever the assertion is hit, there's no screenshot.png file being created. WindowGlobalParent::DrawSnapshotInternal calls LostFragment, seems like a second bug. aReason=ActorDestroyed, which is due to ActorDestroyReason::Deletion.
Though while that probably causes the race with SetIsActive to show up, I think these are separate issues. I agree this isn't really extension specific. I wonder if we should not fail the assertion if there is no embedder, or not set isActive in docShellIsActive, or store the manualactiveness bit on the BC at least for verification in debug.
| Assignee | ||
Comment 33•3 months ago
|
||
// Ignore the initial about:blank, unless about:blank is requested
That looks incorrect and I missed it as part of bug 543435. It should likely check .isUncommittedInitialDocument. Though the crash still reproduces with that.
| Assignee | ||
Comment 34•3 months ago
|
||
Ah, but takeScreenshot binds the browser before starting the load. So an initial about:blank load has already kicked off when we navigate to about:blank again. We resolve on the first load and the second one races with the screenshot, possibly destroying the actor. We need to set nodefaultsrc there.
Comment 35•3 months ago
|
||
(In reply to Vincent Hilla [:vhilla] from comment #32)
Right, there's
Failure taking screenshot: [Exception... "Data conversion failed because significant data would be lost" nsresult: "0x80460003 (NS_ERROR_LOSS_OF_SIGNIFICANT_DATA)" location: "<unknown>" data: no]
and whenever the assertion is hit, there's no
screenshot.pngfile being created.
FYI I recently investigated the same error triggered via drawSnapshot. If that method is also used here, then the debugging in https://bugzilla.mozilla.org/show_bug.cgi?id=2040023#c1 and the commits / commit messages that follow may be of interest to you. The second patch to that bug fixes the issue (the patch had nothing to do with the bug report, but I fixed bugs that I found while working on fixing the test).
| Assignee | ||
Comment 36•3 months ago
|
||
Updated•3 months ago
|
Comment 37•3 months ago
|
||
Comment 38•3 months ago
|
||
| bugherder | ||
Updated•3 months ago
|
Description
•