Assertion failure: hasActiveLoad, at /builds/worker/checkouts/gecko/uriloader/base/nsDocLoader.cpp:809
Categories
(Core :: DOM: Navigation, defect)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox-esr140 | --- | unaffected |
| firefox145 | --- | unaffected |
| firefox146 | --- | unaffected |
| firefox147 | --- | disabled |
| firefox148 | --- | wontfix |
| firefox149 | --- | verified |
People
(Reporter: tsmith, Assigned: vhilla)
References
(Blocks 1 open bug, Regression)
Details
(4 keywords, Whiteboard: [bugmon:bisected,confirmed])
Attachments
(2 files)
Found while fuzzing mozilla-central rev c291f45cf566 (--enable-debug --enable-fuzzing)
To reproduce via Grizzly Replay:
$ pip install fuzzfetch grizzly-framework --upgrade
$ python -m fuzzfetch -d --fuzzing -n firefox
$ python -m grizzly.replay.bugzilla ./firefox/firefox <bugid>
Assertion failure: hasActiveLoad, at /builds/worker/checkouts/gecko/uriloader/base/nsDocLoader.cpp:809
#0 0x75f7a9c0601a in MOZ_CrashSequence /builds/worker/workspace/obj-build/dist/include/mozilla/Assertions.h:237:3
#1 0x75f7a9c0601a in nsDocLoader::DocLoaderIsEmpty(bool, mozilla::Maybe<nsresult> const&) /builds/worker/checkouts/gecko/uriloader/base/nsDocLoader.cpp:809:5
#2 0x75f7a9c0739a in nsDocLoader::OnStopRequest(nsIRequest*, nsresult) /builds/worker/checkouts/gecko/uriloader/base/nsDocLoader.cpp:722:5
#3 0x75f7af2e307f in nsDocShell::OnStopRequest(nsIRequest*, nsresult) /builds/worker/checkouts/gecko/docshell/base/nsDocShell.cpp:14751:23
#4 0x75f7a8f98f1f in mozilla::net::nsLoadGroup::NotifyRemovalObservers(nsIRequest*, nsresult) /builds/worker/checkouts/gecko/netwerk/base/nsLoadGroup.cpp:656:22
#5 0x75f7a8f9a0c6 in mozilla::net::nsLoadGroup::RemoveRequest(nsIRequest*, nsISupports*, nsresult) /builds/worker/checkouts/gecko/netwerk/base/nsLoadGroup.cpp:540:10
#6 0x75f7aad4474c in mozilla::dom::Document::DoUnblockOnload() /builds/worker/checkouts/gecko/dom/base/Document.cpp:12520:18
#7 0x75f7aad2a856 in mozilla::dom::Document::DispatchContentLoadedEvents() /builds/worker/checkouts/gecko/dom/base/Document.cpp:8766:3
#8 0x75f7aad2b378 in mozilla::dom::Document::EndLoad() /builds/worker/checkouts/gecko/dom/base/Document.cpp:8817:3
#9 0x75f7af2e1461 in nsDocShell::CompleteInitialAboutBlankLoad(nsDocShellLoadState*, nsILoadInfo*) /builds/worker/checkouts/gecko/docshell/base/nsDocShell.cpp:11301:8
#10 0x75f7af2d7fd4 in nsDocShell::DoURILoad(nsDocShellLoadState*, mozilla::Maybe<unsigned int>, nsIRequest**) /builds/worker/checkouts/gecko/docshell/base/nsDocShell.cpp:10997:12
#11 0x75f7af23f4c2 in nsDocShell::InternalLoad(nsDocShellLoadState*, mozilla::Maybe<unsigned int>) /builds/worker/checkouts/gecko/docshell/base/nsDocShell.cpp:10031:8
#12 0x75f7af290868 in nsDocShell::LoadURI(nsDocShellLoadState*, bool, bool) /builds/worker/checkouts/gecko/docshell/base/nsDocShell.cpp:895:8
#13 0x75f7aafc75db in nsFrameLoader::ReallyStartLoadingInternal() /builds/worker/checkouts/gecko/dom/base/nsFrameLoader.cpp:772:18
#14 0x75f7aafc6c74 in nsFrameLoader::ReallyStartLoading() /builds/worker/checkouts/gecko/dom/base/nsFrameLoader.cpp:638:17
#15 0x75f7aad34686 in mozilla::dom::Document::MaybeInitializeFinalizeFrameLoaders() /builds/worker/checkouts/gecko/dom/base/Document.cpp:10088:13
#16 0x75f7aadf3655 in operator()<> /builds/worker/workspace/obj-build/dist/include/nsThreadUtils.h:1083:18
#17 0x75f7aadf3655 in __invoke_impl<void, (lambda at /builds/worker/workspace/obj-build/dist/include/nsThreadUtils.h:1082:9)> /builds/worker/fetches/sysroot-x86_64-linux-gnu/usr/lib/gcc/x86_64-linux-gnu/10/../../../../include/c++/10/bits/invoke.h:60:14
#18 0x75f7aadf3655 in __invoke<(lambda at /builds/worker/workspace/obj-build/dist/include/nsThreadUtils.h:1082:9)> /builds/worker/fetches/sysroot-x86_64-linux-gnu/usr/lib/gcc/x86_64-linux-gnu/10/../../../../include/c++/10/bits/invoke.h:95:14
#19 0x75f7aadf3655 in __apply_impl<(lambda at /builds/worker/workspace/obj-build/dist/include/nsThreadUtils.h:1082:9), std::tuple<> &> /builds/worker/fetches/sysroot-x86_64-linux-gnu/usr/lib/gcc/x86_64-linux-gnu/10/../../../../include/c++/10/tuple:1740:14
#20 0x75f7aadf3655 in apply<(lambda at /builds/worker/workspace/obj-build/dist/include/nsThreadUtils.h:1082:9), std::tuple<> &> /builds/worker/fetches/sysroot-x86_64-linux-gnu/usr/lib/gcc/x86_64-linux-gnu/10/../../../../include/c++/10/tuple:1751:14
#21 0x75f7aadf3655 in apply<mozilla::dom::Document, void (mozilla::dom::Document::*)()> /builds/worker/workspace/obj-build/dist/include/nsThreadUtils.h:1081:12
#22 0x75f7aadf3655 in mozilla::detail::RunnableMethodImpl<mozilla::dom::Document*, void (mozilla::dom::Document::*)(), true, (mozilla::RunnableKind)0>::Run() /builds/worker/workspace/obj-build/dist/include/nsThreadUtils.h:1132:13
#23 0x75f7aaaaad2e in nsContentUtils::RemoveScriptBlocker() /builds/worker/checkouts/gecko/dom/base/nsContentUtils.cpp:6900:17
#24 0x75f7aad298fb in mozilla::dom::Document::EndUpdate() /builds/worker/checkouts/gecko/dom/base/Document.cpp:8593:3
#25 0x75f7aaffcd57 in ~mozAutoDocUpdate /builds/worker/checkouts/gecko/dom/base/mozAutoDocUpdate.h:34:18
#26 0x75f7aaffcd57 in nsINode::ReplaceOrInsertBefore(bool, nsINode*, nsINode*, MutationEffectOnScript, mozilla::ErrorResult&) /builds/worker/checkouts/gecko/dom/base/nsINode.cpp:3160:1
#27 0x75f7ab53e8b9 in InsertBeforeInternal /builds/worker/checkouts/gecko/dom/base/nsINode.h:2390:12
#28 0x75f7ab53e8b9 in AppendChildInternal /builds/worker/checkouts/gecko/dom/base/nsINode.h:2404:12
#29 0x75f7ab53e8b9 in AppendChild /builds/worker/checkouts/gecko/dom/base/nsINode.h:2398:12
#30 0x75f7ab53e8b9 in mozilla::dom::Node_Binding::appendChild(JSContext*, JS::Handle<JSObject*>, void*, JSJitMethodCallArgs const&) /builds/worker/workspace/obj-build/dom/bindings/./NodeBinding.cpp:950:60
#31 0x75f7ac1d71fd in bool mozilla::dom::binding_detail::GenericMethod<mozilla::dom::binding_detail::NormalThisPolicy, mozilla::dom::binding_detail::ThrowExceptions>(JSContext*, unsigned int, JS::Value*) /builds/worker/checkouts/gecko/dom/bindings/BindingUtils.cpp:3306:13
#32 0x0e33d709840d ([anon:js-executable-memory]+0x6040d)
Comment 1•8 months ago
|
||
Unable to reproduce bug 2004132 using build mozilla-central 20251125043558-95ed8ab23f39. Without a baseline, bugmon is unable to analyze this bug.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.
| Assignee | ||
Comment 2•8 months ago
|
||
I added the assert in bug 2003255.
| Assignee | ||
Updated•8 months ago
|
| Assignee | ||
Comment 3•8 months ago
|
||
Should be S3. I guess flushing layout caused the load to happen. So hasActiveLoad is false and maybe the assertions need some tweaking.
Comment 4•8 months ago
|
||
Set release status flags based on info from the regressing bug 2003255
Comment 5•8 months ago
|
||
Set release status flags based on info from the regressing bug 2003255
Updated•8 months ago
|
Updated•8 months ago
|
| Assignee | ||
Updated•8 months ago
|
Comment 6•8 months ago
|
||
Verified bug as reproducible on mozilla-central 20251217214341-26b8f5c9bc78.
The bug appears to have been introduced in the following build range:
Start: e2c9f606dd426f79b25a5a448c9d0ebcb6ac21e4 (20251203220105)
End: 82e18501de372884a9cd3b82689dde3b62b87bf1 (20251203232337)
Pushlog: https://hg.mozilla.org/integration/autoland/pushloghtml?fromchange=e2c9f606dd426f79b25a5a448c9d0ebcb6ac21e4&tochange=82e18501de372884a9cd3b82689dde3b62b87bf1
Successfully recorded a pernosco session. A link to the pernosco session will be added here shortly.
Comment 8•7 months ago
|
||
This is not a release assertion, so wontfixing now that Fx148 is in beta
| Assignee | ||
Comment 9•6 months ago
•
|
||
I took a look at the trace and think we should just remove the assertion. I think I added it to ensure we always get a sync load, but apparently the frameloader can be destroyed during the layout flush.
A quick summary of what happens. When the iframe loads, it is re-appended to a use element. This happens indefinitely (and synchronous). Due to the long stack, I assume hitting the right conditions for the assert is racy (or we depend on a failing rv due to getting close to the stack limit? [1]). But at some point, a frameloader A loads, DocLoaderIsEmpty flushes notifications, that causes Document::UpdateSVGUseElementShadowTrees to re-bind the iframe to the tree, the new frameloader B loads, re-binds the iframe again, and this destroys A. So when the document flush is complete, DocLoaderIsEmpty hits the assert for A because the mDocumentRequest was cleared during destroy.
Edit [1]: Yes, stdout shows Overrecursion in SetNewDocument
| Assignee | ||
Comment 10•6 months ago
|
||
Updated•6 months ago
|
Comment 11•6 months ago
|
||
Comment 12•6 months ago
|
||
| bugherder | ||
Comment 13•6 months ago
|
||
Verified bug as fixed on rev mozilla-central 20260127040820-73fc8b9acb15.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.
Description
•