Closed Bug 2003265 Opened 9 months ago Closed 3 months ago

[2123] Assertion failure: false (MOZ_ASSERT_UNREACHABLE: Trying to manually manage activeness of a browsing context that isn't manually managed (see manualactiveness attribute)), at docshell/base/CanonicalBrowsingContext.cpp:3426

Categories

(Firefox :: Tabbed Browser, defect)

defect

Tracking

()

RESOLVED FIXED
153 Branch
Tracking Status
firefox-esr115 --- unaffected
firefox-esr140 --- unaffected
firefox146 --- unaffected
firefox147 --- disabled
firefox148 --- wontfix
firefox151 --- wontfix
firefox152 --- wontfix
firefox153 --- fixed

People

(Reporter: petr.sumbera, Assigned: vhilla)

References

(Regression)

Details

(Keywords: regression)

Attachments

(2 files, 1 obsolete file)

Steps to reproduce:

Firefox on SPARC Solaris (Intel is ok) hits following assertion:

[2123] Assertion failure: false (MOZ_ASSERT_UNREACHABLE: Trying to manually manage activeness of a browsing context that isn't manually managed (see manualactiveness attribute)), at /builds/psumbera/mozilla-ce
ntral-build/docshell/base/CanonicalBrowsingContext.cpp:3426
#01: mozilla::dom::CanonicalBrowsingContext::SetIsActive(bool, mozilla::ErrorResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x272ffbe8]
#02: mozilla::dom::CanonicalBrowsingContext_Binding::set_isActive(JSContext*, JS::Handle<JSObject*>, void*, JSJitSetterCallArgs)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1fab2a
f4]
#03: bool mozilla::dom::binding_detail::GenericSetter<mozilla::dom::binding_detail::NormalThisPolicy>(JSContext*, unsigned int, JS::Value*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.s
o +0x21589fec]
#04: CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac63434]
#05: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac360f8]
#06: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac368a4]
#07: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libx
ul.so +0x2ac36b58]
#08: js::CallSetter(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac37e28]
#09: SetExistingProperty(JSContext*, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<js::NativeObject*>, js::PropertyResult const&, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28e35b30]
#10: bool js::NativeSetProperty<(js::QualifiedBool)1>(JSContext*, JS::Handle<js::NativeObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28e4def0]
#11: js::SetProperty(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x288d71f0]
#12: SetObjectElementOperation(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3bf00]
#13: js::Interpret(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac48a48]
#14: MaybeEnterInterpreterTrampoline(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3508c]
#15: js::RunScript(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3591c]
#16: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3636c]
#17: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac368a4]
#18: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac36b58]
#19: js::CallSetter(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac37e28]
#20: SetExistingProperty(JSContext*, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<js::NativeObject*>, js::PropertyResult const&, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28e35b30]
#21: bool js::NativeSetProperty<(js::QualifiedBool)1>(JSContext*, JS::Handle<js::NativeObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28e4def0]
#22: js::SetProperty(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x288d71f0]
#23: SetObjectElementOperation(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3bf00]
#24: js::Interpret(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac48a48]
#25: MaybeEnterInterpreterTrampoline(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3508c]
#26: js::RunScript(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3591c]
#27: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac3636c]
#28: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac368a4]
#29: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac36b58]
#30: js::CallSelfHostedFunction(JSContext*, JS::Handle<js::PropertyName*>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28f37538]
#31: AsyncFunctionResume(JSContext*, JS::Handle<js::AsyncFunctionGeneratorObject*>, ResumeKind, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x289dafa8]
#32: js::AsyncFunctionAwaitedFulfilled(JSContext*, JS::Handle<js::AsyncFunctionGeneratorObject*>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x289db518]
#33: AsyncFunctionPromiseReactionJob(JSContext*, JS::Handle<PromiseReactionRecord*>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28d9003c]
#34: PromiseReactionJob(JSContext*, JS::Handle<JSObject*>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28d905f4]
#35: PromiseReactionJob(JSContext*, unsigned int, JS::Value*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28d91414]
#36: CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac63434]
#37: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac360f8]
#38: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac368a4]
#39: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2ac36b58]
#40: JS::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::HandleValueArray const&, JS::MutableHandle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28a82654]
#41: mozilla::PromiseJobRunnable::Call()[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a7e6908]
#42: mozilla::PromiseJobRunnable::Run(mozilla::AutoSlowOperation&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a7e6b60]
#43: mozilla::CycleCollectedJSContext::PerformMicroTaskCheckPoint(bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a7a46d8]
#44: mozilla::CycleCollectedJSContext::AfterProcessTask(unsigned int)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a7a07a0]
#45: XPCJSContext::AfterProcessTask(unsigned int)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1c5f0bc8]
#46: nsThread::ProcessNextEvent(bool, bool*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1aaccce4]
#47: NS_ProcessNextEvent(nsIThread*, bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1aaded2c]
#48: bool mozilla::SpinEventLoopUntil<(mozilla::ProcessFailureBehavior)1, nsThreadManager::SpinEventLoopUntilInternal(nsTSubstring<char> const&, nsINestedEventLoopCondition*, mozilla::ShutdownPhase)::{lambda()#1}>(nsTSubstring<char> const&, nsThreadManager::Sp[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1aae7cf0]
#49: nsThreadManager::SpinEventLoopUntilInternal(nsTSubstring<char> const&, nsINestedEventLoopCondition*, mozilla::ShutdownPhase)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1aad46bc]
#50: nsThreadManager::SpinEventLoopUntil(nsTSubstring<char> const&, nsINestedEventLoopCondition*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1aad42ec]
#51: NS_InvokeByIndex[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1ab4c9a0]
[RDD 3175, IPC I/O Child] WARNING: [7573429099466DCF.4508A3F7C3C8A27A]: Dropping message '<null>'; no connection to unknown peer 1.1: file /builds/psumbera/mozilla-central-build/ipc/glue/NodeController.cpp:366
[Socket 3086, IPC I/O Child] WARNING: [5BEDA902A8A94EB5.ED9963054C3A2FAB]: Dropping message '<null>'; no connection to unknown peer 1.1: file /builds/psumbera/mozilla-central-build/ipc/glue/NodeController.cpp:366
[Child 3174, IPC I/O Child] WARNING: [BC1F0CE9263BCE09.D1D7E3F6449791C8]: Dropping message '<null>'; no connection to unknown peer 1.1: file /builds/psumbera/mozilla-central-build/ipc/glue/NodeController.cpp:366
[Socket 3086, Main Thread] WARNING: Shutting down Socket process early due to a crash!: file /builds/psumbera/mozilla-central-build/netwerk/ipc/SocketProcessChild.cpp:240
[RDD 3175, Main Thread] WARNING: Shutting down RDD process early due to a crash!: file /builds/psumbera/mozilla-central-build/dom/media/ipc/RDDParent.cpp:319
Crash Annotation GraphicsCriticalError: |[C0][GFX1-]: CompositorBridgeChild receives IPC close with reason=AbnormalShutdown (t=61.3404) [GFX1-]: CompositorBridgeChild receives IPC close with reason=AbnormalShutdown
Exiting due to channel error.

This first is commit was:

changeset:   818157:5f9e366c17fc
user:        Henri Sivonen <hsivonen@hsivonen.fi>
date:        Mon Nov 24 06:32:05 2025 +0100
description:
        Bug 543435 - Make initial about:blank not get overwritten by an async about:blank load. r=sessionstore-reviewers,sfoster,timhuang,credential-management-reviewers,issammani,webidl,extension-reviewers,tabbrowser-reviewers,migration-reviewers,home-newtab-reviewers,hsivonen,cookie-reviewers,fxview-reviewers,firefox-desktop-core-reviewers ,dao,valentin,mossop,smaug,geckoview-reviewers,Jamie,mtigley,thecount,media-playback-reviewers,padenot,dom-worker-reviewers,jesup,jdescottes,asuth,robwu,karlt,profiler-reviewers,kpatenio,devtools-reviewers,tcampbell,nchevobbe

        Co-authored-by: Vincent Hilla <vhilla@mozilla.com>
        Signed-off-by: Vincent Hilla <vhilla@mozilla.com>

        Differential Revision: https://phabricator.services.mozilla.com/D155376
Keywords: regression
Regressed by: sync-about-blank

:vhilla, since you are the author of the regressor, bug 543435, could you take a look? Also, could you set the severity field?

For more information, please visit BugBot documentation.

Flags: needinfo?(vhilla)

Too many places to guess:
https://searchfox.org/firefox-main/search?q=symbol:%23docShellIsActive&redirect=false

Reporter, could you, please, do p DumpJSStack() in gdb when you see this failure?

Flags: needinfo?(petr.sumbera)

I don't see any cases where there'd be an opportunity for an about:blank load between the creation of a top-level browsing context and setting the manualactiveness attribute.

Setting severity per the bot request: It seems to me this can't be higher than S3. This is a debug assertion on the front end's own assumptions, and if this occurred commonly across platforms, I'd expect an assertions-enabled build on any platform to encounter this.

tsmith, do your assertions-enabled runs exercise opening new tabs and windows?

Severity: -- → S3
Component: Untriaged → Tabbed Browser
Flags: needinfo?(vhilla) → needinfo?(twsmith)

I should add that I see it only when I run: firefox --screenshot about:blank

We dump the JS stack right before crashing here, what does that say?

(In reply to Petr Sumbera from comment #4)

I should add that I see it only when I run: firefox --screenshot about:blank

I don't see the assertion in that case on x86_64 Linux.

(In reply to Emilio Cobos Álvarez [:emilio] from comment #5)

We dump the JS stack right before crashing here, what does that say?

0 set docShellIsActive(val = "true") ["chrome://global/content/elements/browser-custom-element.mjs":498:5]
    this = [object XULFrameElement]
1 createBrowserElement() ["resource://gre/modules/ExtensionParent.sys.mjs":1505:5]
2 AsyncFunctionNext(val = "[object Event]") ["self-hosted":780:27]
    this = [object Object]
3 observe("null", ""quit-application"", ""shutdown"") ["resource://gre/modules/AsyncShutdown.sys.mjs":570:17]
    this = [object Object]
4 handleCmdLineArgs() ["moz-src:///browser/components/shell/HeadlessShell.sys.mjs":256:24]
5 AsyncFunctionNext(val = "undefined") ["self-hosted":780:27]
    this = [object Object]
``
Flags: needinfo?(petr.sumbera)

So that'd be: https://searchfox.org/firefox-main/rev/5ccf4a7d77a329f237d3a41e400049f9c47dc71f/toolkit/components/extensions/ExtensionParent.sys.mjs#1475,1479,1505

But that sets the attribute above... So maybe something unbinds the embedder from the browsing context.

(In reply to Henri Sivonen (:hsivonen) from comment #3)

tsmith, do your assertions-enabled runs exercise opening new tabs and windows?

Some of the fuzzers do. Live site testing does not open new tabs or windows. Unfortunately I have not seen this assertion reported.

Flags: needinfo?(twsmith)

The plan for 147 is to back bug 543435 out of beta in bug 2003720.

Now I see it also on x86_64 (after Bug 2003043 was integrated) :

0 set docShellIsActive(val = "true") ["chrome://global/content/elements/browser-custom-element.mjs":498:5]
    this = [object XULFrameElement]
1 createBrowserElement() ["resource://gre/modules/ExtensionParent.sys.mjs":1505:5]
2 AsyncFunctionNext(val = "[object Event]") ["self-hosted":780:27]
    this = [object Object]
3 observe("null", ""quit-application"", ""shutdown"") ["resource://gre/modules/AsyncShutdown.sys.mjs":570:17]
    this = [object Object]
4 handleCmdLineArgs() ["moz-src:///browser/components/shell/HeadlessShell.sys.mjs":256:24]
5 InterpretGeneratorResume(gen = "[object Object]", val = "undefined", kind = ""next"") ["self-hosted":1317:34]
6 AsyncFunctionNext(val = "undefined") ["self-hosted":780:27]
    this = [object Object]

[837880] Assertion failure: false (MOZ_ASSERT_UNREACHABLE: Trying to manually manage activeness of a browsing context that isn't manually managed (see manualactiveness attribute)), at /builds/psumbera/mozilla-central-build/docshell/base/CanonicalBrowsingContext.cpp:3441
#01: mozilla::dom::CanonicalBrowsingContext::SetIsActive(bool, mozilla::ErrorResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2820e4ab]
#02: mozilla::dom::CanonicalBrowsingContext_Binding::set_isActive(JSContext*, JS::Handle<JSObject*>, void*, JSJitSetterCallArgs)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x22dc7c9a]
#03: bool mozilla::dom::binding_detail::GenericSetter<mozilla::dom::binding_detail::NormalThisPolicy>(JSContext*, unsigned int, JS::Value*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x24085b57]
#04: CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aa829e2]
#05: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aa61114]
#06: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aa615f2]
#07: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aa617b8]
#08: js::CallSetter(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aa62445]
#09: SetExistingProperty(JSContext*, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<js::NativeObject*>, js::PropertyResult const&, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2950e706]
#10: bool js::NativeSetProperty<(js::QualifiedBool)1>(JSContext*, JS::Handle<js::NativeObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2951f90d]
..

Bug 543435 was reverted from Fx147. Updating the flags accordingly.

The bug has a release status flag that shows some version of Firefox is affected, thus it will be considered confirmed.

Status: UNCONFIRMED → NEW
Ever confirmed: true

I started to see it on SPARC again:

0 set docShellIsActive(val = "true") ["chrome://global/content/elements/browser-custom-element.mjs":498:5]
    this = [object XULFrameElement]
1 createBrowserElement() ["resource://gre/modules/ExtensionParent.sys.mjs":1505:5]
2 AsyncFunctionNext(val = "[object Event]") ["self-hosted":780:27]
    this = [object Object]
3 observe("null", ""quit-application"", ""shutdown"") ["resource://gre/modules/AsyncShutdown.sys.mjs":570:17]
    this = [object Object]
4 handleCmdLineArgs() ["moz-src:///browser/components/shell/HeadlessShell.sys.mjs":256:24]
5 AsyncFunctionNext(val = "undefined") ["self-hosted":780:27]
    this = [object Object]

[830] Assertion failure: false (MOZ_ASSERT_UNREACHABLE: Trying to manually manage activeness of a browsing context that isn't manually managed (see manualactiveness attribute)), at /builds/psumbera/mozilla-cen
tral-build/docshell/base/CanonicalBrowsingContext.cpp:3441
#01: mozilla::dom::CanonicalBrowsingContext::SetIsActive(bool, mozilla::ErrorResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x27566ac4]
#02: mozilla::dom::CanonicalBrowsingContext_Binding::set_isActive(JSContext*, JS::Handle<JSObject*>, void*, JSJitSetterCallArgs)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1fcca2
dc]
#03: bool mozilla::dom::binding_detail::GenericSetter<mozilla::dom::binding_detail::NormalThisPolicy>(JSContext*, unsigned int, JS::Value*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.s
o +0x217b0774]
#04: CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2af09304]
#05: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedbfc8]
#06: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedc774]
#07: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libx
ul.so +0x2aedca28]
#08: js::CallSetter(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aeddcf8]
#09: SetExistingProperty(JSContext*, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<js::NativeObject*>, js::PropertyResult const&, JS::ObjectOpResult&)[/builds/psumbera/m
ozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x290c49c8]
#10: bool js::NativeSetProperty<(js::QualifiedBool)1>(JSContext*, JS::Handle<js::NativeObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera
/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x290dcd88]
#11: js::SetProperty(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/fire
fox/libxul.so +0x28b62d58]
#12: SetObjectElementOperation(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/l
ibxul.so +0x2aee1dd0]
#13: js::Interpret(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aeee918]
#14: MaybeEnterInterpreterTrampoline(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedaf5c]
#15: js::RunScript(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedb7ec]
#16: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedc23c]
#17: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedc774]
#18: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedca28]
#19: js::CallSetter(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aeddcf8]
#20: SetExistingProperty(JSContext*, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::Handle<js::NativeObject*>, js::PropertyResult const&, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x290c49c8]
#21: bool js::NativeSetProperty<(js::QualifiedBool)1>(JSContext*, JS::Handle<js::NativeObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x290dcd88]
#22: js::SetProperty(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::ObjectOpResult&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28b62d58]
#23: SetObjectElementOperation(JSContext*, JS::Handle<JSObject*>, JS::Handle<JS::PropertyKey>, JS::Handle<JS::Value>, JS::Handle<JS::Value>, bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aee1dd0]
#24: js::Interpret(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aeee918]
#25: MaybeEnterInterpreterTrampoline(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedaf5c]
#26: js::RunScript(JSContext*, js::RunState&)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedb7ec]
#27: js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedc23c]
#28: InternalCall(JSContext*, js::AnyInvokeArgs const&, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedc774]
#29: js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2aedca28]
#30: js::CallSelfHostedFunction(JSContext*, JS::Handle<js::PropertyName*>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x291c71b4]
#31: AsyncFunctionResume(JSContext*, JS::Handle<js::AsyncFunctionGeneratorObject*>, ResumeKind, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28c67004]
#32: js::AsyncFunctionAwaitedFulfilled(JSContext*, JS::Handle<js::AsyncFunctionGeneratorObject*>, JS::Handle<JS::Value>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x28c67574]
#33: AsyncFunctionPromiseReactionJob(JSContext*, JS::Handle<PromiseReactionRecord*>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2901e580]
#34: PromiseReactionJob(JSContext*, JS::Handle<JSObject*>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x2901eb38]
#35: JS::RunJSMicroTask(JSContext*, JS::Handle<JSObject*>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x29034e60]
#36: mozilla::MustConsumeMicroTask::RunAndConsumeJSMicroTask(JSContext*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a98fd94]
#37: mozilla::RunMicroTask(JSContext*, JS::MutableHandle<mozilla::MustConsumeMicroTask>)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a96a730]
#38: mozilla::CycleCollectedJSContext::PerformMicroTaskCheckPoint(bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a96bc4c]
#39: mozilla::CycleCollectedJSContext::AfterProcessTask(unsigned int)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1a9682dc]
#40: XPCJSContext::AfterProcessTask(unsigned int)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1c7e73cc]
#41: nsThread::ProcessNextEvent(bool, bool*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1ac984c4]
#42: NS_ProcessNextEvent(nsIThread*, bool)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1acaa500]
#43: bool mozilla::SpinEventLoopUntil<(mozilla::ProcessFailureBehavior)1, nsThreadManager::SpinEventLoopUntilInternal(nsTSubstring<char> const&, nsINestedEventLoopCondition*, mozilla::ShutdownPhase)::{lambda()#1}>(nsTSubstring<char> const&, nsThreadManager::Sp[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1acb34c4]
#44: nsThreadManager::SpinEventLoopUntilInternal(nsTSubstring<char> const&, nsINestedEventLoopCondition*, mozilla::ShutdownPhase)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1ac9fe9c]
#45: nsThreadManager::SpinEventLoopUntil(nsTSubstring<char> const&, nsINestedEventLoopCondition*)[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1ac9facc]
#46: NS_InvokeByIndex[/builds/psumbera/mozilla-central-build/INSTALLED/lib/firefox/libxul.so +0x1ad18180]

(In reply to Emilio Cobos Álvarez [:emilio] from comment #8)

So that'd be: https://searchfox.org/firefox-main/rev/5ccf4a7d77a329f237d3a41e400049f9c47dc71f/toolkit/components/extensions/ExtensionParent.sys.mjs#1475,1479,1505

But that sets the attribute above... So maybe something unbinds the embedder from the browsing context.

Rob do you know off-hand how this could happen? Should we bail out from ExtensionParent initialization if the app is shutting down?

Flags: needinfo?(rob)

(In reply to Emilio Cobos Álvarez [:emilio] from comment #15)

(In reply to Emilio Cobos Álvarez [:emilio] from comment #8)

So that'd be: https://searchfox.org/firefox-main/rev/5ccf4a7d77a329f237d3a41e400049f9c47dc71f/toolkit/components/extensions/ExtensionParent.sys.mjs#1475,1479,1505

But that sets the attribute above... So maybe something unbinds the embedder from the browsing context.

Rob do you know off-hand how this could happen? Should we bail out from ExtensionParent initialization if the app is shutting down?

We could bail out indeed, if that is needed to fix this bug. Up in the stack, we already (eventually) clean up if shutdown has commenced.

This bug reminds me of bug 1959339, where shutdown commences while extensions are still starting. It could easily be reproduced by screenshotting about:blank. Coincidentally, the reporter of that bug is the same as the reporter of this bug.

I can imagine an about:blank load happening if the extension load request is aborted, e.g. at shutdown.

The keywords of this bug reminds me of bug 1901894, a case from the past where there was an "unexpected" about:blank load in the background browser. This is likely unrelated, but there may be useful information to aid in debugging.

Flags: needinfo?(rob)

I see this as well for a lot of CI jobs for the following try build:

https://treeherder.mozilla.org/jobs?repo=try&revision=6ea373bcfe59006c68cdec325e03f3849ebca221&searchStr=wdspec&selectedTaskRun=HX0pefGASqy8-fq6n-IgwQ.0

Note that these WebDriver tests open Firefox, attempt to run a navigation, and then immediately quit Firefox again. Here the crash details:

https://treeherder.mozilla.org/logviewer?job_id=567414632&repo=try&task=HX0pefGASqy8-fq6n-IgwQ.0&lineNumber=14251

The stack of the crashing thread is quite huge but when scrolling down I can see nsContentUtils::DispatchTrustedEvent and based on its parent frame it most likely is the load event that is getting dispatched but fails.

The actual test which triggers this failure for this try push is the following:

@pytest.mark.allow_system_access
async def test_chrome_url_with_system_access(bidi_session, new_tab):
    CHROME_URL = "chrome://browser/content/browser.xhtml"

    await bidi_session.browsing_context.navigate(
        context=new_tab["context"], url=CHROME_URL, wait="complete"
    )

    contexts = await bidi_session.browsing_context.get_tree(
        root=new_tab["context"], max_depth=0
    )
    assert contexts[0]["url"] == CHROME_URL

Here we are navigating to a chrome:// URL within a tab.

It can as well easily be reproduced with a debug build when loading chrome://browser/content/browser.xhtml via the location bar.

Maybe the two different scenarios have the same underlying reason? Vincent, could you take a look?

Flags: needinfo?(vhilla)

Loading browser.xhtml in a tab is not a use case we want to support.

(In reply to Emilio Cobos Álvarez [:emilio] from comment #24)

Loading browser.xhtml in a tab is not a use case we want to support.

It does work in Nightly :(

Well, "works". See discussion in bug 1892593.

See Also: → 1892593

Based on Rob's comment, I can reproduce this bug flakily on Mac debug build with ./mach run --temp-profile -screenshot about:blank

I can confirm that GetEmbedderElement() is null. In ExtensionParent right before setting docShellIsActive, it is browser.isConnected=true, this.unloaded=false, Services.startup.shuttingDown=true, browser.browsingContext.embedderElement=null.

I'll put up a patch to make it clearer if the assertion fails due to a lack of an embedder element. And I'll add a check to HiddenXULWindow.createBrowserElement before setting docShellIsActive.


Regarding WebDriver / chrome://, that seems to be an unrelated issue.

Pernosco: https://pernos.co/debug/A7OiKW8-A6GAH7u0AMWrSg/index.html

Tabbrowser._setupInitialBrowserAndTab binds some panel and then activates it. But BrowsingContext::SetEmbedderElement never runs, likely because nsFrameLoader::ShowRemoteFrame fails with NS_ERROR("Couldn't create child process."). It fails because !EnsureRemoteBrowser(), which is due to the URI being disallowed.

Flags: needinfo?(vhilla)

This avoids crashing in debug when shutdown races with ExtensionParent
activating a browser.

This change also tweaks the assertion to be clearer when the embedder is
missing, rather than manualactiveness not set.

Assignee: nobody → vhilla
Status: NEW → ASSIGNED

The patch above does something special for extensions, but I wonder whether it really should be extension-specific. Logically there is something odd going on:

The JS side calls browser.docShellIsActive = true, triggering https://searchfox.org/firefox-main/rev/cebc55aab4d2661d1f6c2d1526362947ec4016c1/toolkit/content/widgets/browser-custom-element.mjs#503-514 :

  • returns early (and silently) when this.browsingContext is void.
  • then sets this.browsingContext.isActive = val;
  • then checks if isRemoteBrowser, and if so, conditionally interacts with this.frameLoader.

The assertion here is a debug-only assertion, but it does cause differences between debug and release:

  • the frameLoader?. check later suggests that isActive can be set even if frameLoader is unset.
  • but the implementation does a debug-only check, relying on GetEmbedderElement(). Which can be nullptr if frameLoader is null: embedderElement can be null if nsFrameLoader::SetOwnerContent is called with nullptr. That happens when nsFrameLoader::StartDestroy is called.

Do you have a pernosco trace that shows how we get in this situation?
Alternatively add a profile marker in nsFrameLoader::StartDestroy (or its only caller - nsFrameLoader::Destroy and capture a profile and share that profile.

Flags: needinfo?(vhilla)
Attached file log.txt

No pernosco on Mac, unsure how to get a profile while using -screenshot. But here's a log with MozWalkTheStack during nsFrameLoader::StartDestroy.

Flags: needinfo?(vhilla)

Right, there's

Failure taking screenshot: [Exception... "Data conversion failed because significant data would be lost" nsresult: "0x80460003 (NS_ERROR_LOSS_OF_SIGNIFICANT_DATA)" location: "<unknown>" data: no]

and whenever the assertion is hit, there's no screenshot.png file being created. WindowGlobalParent::DrawSnapshotInternal calls LostFragment, seems like a second bug. aReason=ActorDestroyed, which is due to ActorDestroyReason::Deletion.

Though while that probably causes the race with SetIsActive to show up, I think these are separate issues. I agree this isn't really extension specific. I wonder if we should not fail the assertion if there is no embedder, or not set isActive in docShellIsActive, or store the manualactiveness bit on the BC at least for verification in debug.

https://searchfox.org/firefox-main/rev/e28b34ab33dbf49364999070168cbb7e11e8e5bd/browser/components/shell/HeadlessShell.sys.mjs#52-55

// Ignore the initial about:blank, unless about:blank is requested

That looks incorrect and I missed it as part of bug 543435. It should likely check .isUncommittedInitialDocument. Though the crash still reproduces with that.

Ah, but takeScreenshot binds the browser before starting the load. So an initial about:blank load has already kicked off when we navigate to about:blank again. We resolve on the first load and the second one races with the screenshot, possibly destroying the actor. We need to set nodefaultsrc there.

(In reply to Vincent Hilla [:vhilla] from comment #32)

Right, there's

Failure taking screenshot: [Exception... "Data conversion failed because significant data would be lost" nsresult: "0x80460003 (NS_ERROR_LOSS_OF_SIGNIFICANT_DATA)" location: "<unknown>" data: no]

and whenever the assertion is hit, there's no screenshot.png file being created.

FYI I recently investigated the same error triggered via drawSnapshot. If that method is also used here, then the debugging in https://bugzilla.mozilla.org/show_bug.cgi?id=2040023#c1 and the commits / commit messages that follow may be of interest to you. The second patch to that bug fixes the issue (the patch had nothing to do with the bug report, but I fixed bugs that I found while working on fixing the test).

See Also: → 2042891
Attachment #9588076 - Attachment is obsolete: true
See Also: → 2043216
Status: ASSIGNED → RESOLVED
Closed: 3 months ago
Resolution: --- → FIXED
Target Milestone: --- → 153 Branch
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: