Assertion failure: !aPrevSibling || aPrevSibling->GetParent() == aParentFrame (Parent and prevsibling don't match), at /builds/worker/checkouts/gecko/layout/base/nsCSSFrameConstructor.cpp:5546
Categories
(Core :: CSS Parsing and Computation, defect, P3)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox-esr115 | --- | unaffected |
| firefox-esr140 | --- | wontfix |
| firefox146 | --- | wontfix |
| firefox147 | --- | wontfix |
| firefox148 | --- | verified |
People
(Reporter: tsmith, Assigned: emilio)
References
(Blocks 2 open bugs, Regression)
Details
(5 keywords, Whiteboard: [bugmon:bisected,confirmed], [wptsync upstream])
Attachments
(2 files)
Found while fuzzing m-c 20251229-ea0aabc7aff5 (--enable-debug --enable-fuzzing)
To reproduce via Grizzly Replay:
$ pip install fuzzfetch grizzly-framework --upgrade
$ python -m fuzzfetch -d --fuzzing -n firefox
$ python -m grizzly.replay.bugzilla ./firefox/firefox <bugid>
Assertion failure: !aPrevSibling || aPrevSibling->GetParent() == aParentFrame (Parent and prevsibling don't match), at /builds/worker/checkouts/gecko/layout/base/nsCSSFrameConstructor.cpp:5546
#0 0x74268837e2ec in MOZ_CrashSequence /builds/worker/workspace/obj-build/dist/include/mozilla/Assertions.h:237:3
#1 0x74268837e2ec in nsCSSFrameConstructor::AppendFramesToParent(nsFrameConstructorState&, nsContainerFrame*, nsFrameList&, nsIFrame*, bool) /builds/worker/checkouts/gecko/layout/base/nsCSSFrameConstructor.cpp:5545:3
#2 0x74268838398a in nsCSSFrameConstructor::ContentAppended(nsIContent*, nsCSSFrameConstructor::InsertionKind) /builds/worker/checkouts/gecko/layout/base/nsCSSFrameConstructor.cpp:6580:5
#3 0x7426882715d5 in mozilla::RestyleManager::ProcessRestyledFrames(nsStyleChangeList&) /builds/worker/checkouts/gecko/layout/style/RestyleManager.cpp:1620:27
#4 0x742688278acd in mozilla::RestyleManager::DoProcessPendingRestyles(mozilla::ServoTraversalFlags) /builds/worker/checkouts/gecko/layout/style/RestyleManager.cpp:3250:7
#5 0x742688279d41 in mozilla::RestyleManager::ProcessPendingRestyles() /builds/worker/checkouts/gecko/layout/style/RestyleManager.cpp:3340:3
#6 0x7426883288d7 in mozilla::PresShell::DoFlushPendingNotifications(mozilla::ChangesToFlush) /builds/worker/checkouts/gecko/layout/base/PresShell.cpp:4471:37
#7 0x74268428bc6d in FlushPendingNotifications /builds/worker/workspace/obj-build/dist/include/mozilla/PresShell.h:1526:5
#8 0x74268428bc6d in mozilla::dom::Document::DetermineProximityToViewportAndNotifyResizeObservers() /builds/worker/checkouts/gecko/dom/base/Document.cpp:18890:11
#9 0x7426882eb934 in operator() /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:2504:14
#10 0x7426882eb934 in operator() /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:1312:7
#11 0x7426882eb934 in RunRenderingPhaseLegacy<(lambda at /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:1291:35)> /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:1284:3
#12 0x7426882eb934 in void nsRefreshDriver::RunRenderingPhase<nsRefreshDriver::Tick(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp, nsRefreshDriver::IsExtraTick)::$_10>(mozilla::RenderingPhase, nsRefreshDriver::Tick(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp, nsRefreshDriver::IsExtraTick)::$_10&&, bool (*)(mozilla::dom::Document const&)) /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:1291:3
#13 0x7426882e7a31 in nsRefreshDriver::Tick(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp, nsRefreshDriver::IsExtraTick) /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:2500:3
#14 0x7426882f11d1 in TickDriver /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:366:13
#15 0x7426882f11d1 in mozilla::RefreshDriverTimer::TickRefreshDrivers(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp, nsTArray<RefPtr<nsRefreshDriver>>&) /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:344:7
#16 0x7426882f10d0 in mozilla::RefreshDriverTimer::Tick(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp) /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:360:5
#17 0x7426882f0f7d in mozilla::VsyncRefreshDriverTimer::RunRefreshDrivers(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp) /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:950:5
#18 0x7426882f051a in mozilla::VsyncRefreshDriverTimer::TickRefreshDriver(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp) /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:860:5
#19 0x7426882efa06 in mozilla::VsyncRefreshDriverTimer::RefreshDriverVsyncObserver::NotifyVsyncTimerOnMainThread() /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:591:14
#20 0x742687698edb in mozilla::dom::VsyncMainChild::RecvNotify(mozilla::VsyncEvent const&, float const&) /builds/worker/checkouts/gecko/dom/ipc/VsyncMainChild.cpp:66:15
#21 0x74268791bce9 in mozilla::dom::PVsyncChild::OnMessageReceived(IPC::Message const&) /builds/worker/workspace/obj-build/ipc/ipdl/PVsyncChild.cpp:229:78
#22 0x742682ea1852 in mozilla::ipc::PBackgroundChild::OnMessageReceived(IPC::Message const&) /builds/worker/workspace/obj-build/ipc/ipdl/PBackgroundChild.cpp:5102:32
#23 0x742682e42dce in mozilla::ipc::MessageChannel::DispatchAsyncMessage(mozilla::ipc::ActorLifecycleProxy*, IPC::Message const&) /builds/worker/checkouts/gecko/ipc/glue/MessageChannel.cpp:1793:25
#24 0x742682e40350 in mozilla::ipc::MessageChannel::DispatchMessage(mozilla::ipc::ActorLifecycleProxy*, std::unique_ptr<IPC::Message, std::default_delete<IPC::Message>>) /builds/worker/checkouts/gecko/ipc/glue/MessageChannel.cpp:1719:9
#25 0x742682e40d57 in mozilla::ipc::MessageChannel::RunMessage(mozilla::ipc::ActorLifecycleProxy*, mozilla::ipc::MessageChannel::MessageTask&) /builds/worker/checkouts/gecko/ipc/glue/MessageChannel.cpp:1508:3
#26 0x742682e41d39 in mozilla::ipc::MessageChannel::MessageTask::Run() /builds/worker/checkouts/gecko/ipc/glue/MessageChannel.cpp:1610:14
#27 0x74268223ffc7 in mozilla::RunnableTask::Run() /builds/worker/checkouts/gecko/xpcom/threads/TaskController.cpp:705:16
#28 0x74268223a944 in mozilla::TaskController::DoExecuteNextTaskOnlyMainThreadInternal(mozilla::detail::BaseAutoLock<mozilla::Mutex&> const&) /builds/worker/checkouts/gecko/xpcom/threads/TaskController.cpp:1325:20
#29 0x7426822395c7 in mozilla::TaskController::ExecuteNextTaskOnlyMainThreadInternal(mozilla::detail::BaseAutoLock<mozilla::Mutex&> const&) /builds/worker/checkouts/gecko/xpcom/threads/TaskController.cpp:1148:15
#30 0x742682239a45 in mozilla::TaskController::ProcessPendingMTTask(bool) /builds/worker/checkouts/gecko/xpcom/threads/TaskController.cpp:641:36
#31 0x742682246e46 in operator() /builds/worker/checkouts/gecko/xpcom/threads/TaskController.cpp:333:37
#32 0x742682246e46 in mozilla::detail::RunnableFunction<mozilla::TaskController::TaskController()::$_0>::Run() /builds/worker/checkouts/gecko/xpcom/threads/nsThreadUtils.h:549:5
#33 0x742682258f23 in nsThread::ProcessNextEvent(bool, bool*) /builds/worker/checkouts/gecko/xpcom/threads/nsThread.cpp:1164:16
#34 0x74268225f81f in NS_ProcessNextEvent(nsIThread*, bool) /builds/worker/checkouts/gecko/xpcom/threads/nsThreadUtils.cpp:461:10
#35 0x742682e48657 in mozilla::ipc::MessagePump::Run(base::MessagePump::Delegate*) /builds/worker/checkouts/gecko/ipc/glue/MessagePump.cpp:85:21
#36 0x742682da22c1 in RunHandler /builds/worker/checkouts/gecko/ipc/chromium/src/base/message_loop.cc:361:3
#37 0x742682da22c1 in MessageLoop::Run() /builds/worker/checkouts/gecko/ipc/chromium/src/base/message_loop.cc:343:3
#38 0x742687ee8548 in nsBaseAppShell::Run() /builds/worker/checkouts/gecko/widget/nsBaseAppShell.cpp:152:27
#39 0x742687fb5a54 in nsAppShell::Run() /builds/worker/checkouts/gecko/widget/gtk/nsAppShell.cpp:555:33
#40 0x742689000c9b in XRE_RunAppShell() /builds/worker/checkouts/gecko/toolkit/xre/nsEmbedFunctions.cpp:656:20
#41 0x742682e49504 in mozilla::ipc::MessagePumpForChildProcess::Run(base::MessagePump::Delegate*) /builds/worker/checkouts/gecko/ipc/glue/MessagePump.cpp:235:9
#42 0x742682da22c1 in RunHandler /builds/worker/checkouts/gecko/ipc/chromium/src/base/message_loop.cc:361:3
#43 0x742682da22c1 in MessageLoop::Run() /builds/worker/checkouts/gecko/ipc/chromium/src/base/message_loop.cc:343:3
#44 0x7426890003f1 in XRE_InitChildProcess(int, char**, XREChildData const*) /builds/worker/checkouts/gecko/toolkit/xre/nsEmbedFunctions.cpp:594:34
#45 0x63cf19cebf1c in main /builds/worker/checkouts/gecko/browser/app/nsBrowserApp.cpp:465:22
Comment 1•7 months ago
|
||
Verified bug as reproducible on mozilla-central 20251231225543-810549a5947f.
The bug appears to have been introduced in the following build range:
Start: 75f921f6e4c120f2d230e1fd40b17107b340b671 (20250501022013)
End: c0919c5aca48b3dde1f1fd61b30d342ed47dbf7b (20250501022708)
Pushlog: https://hg.mozilla.org/integration/autoland/pushloghtml?fromchange=75f921f6e4c120f2d230e1fd40b17107b340b671&tochange=c0919c5aca48b3dde1f1fd61b30d342ed47dbf7b
Comment 2•7 months ago
|
||
Set release status flags based on info from the regressing bug 242829
:emilio, since you are the author of the regressor, bug 242829, could you take a look? Also, could you set the severity field?
For more information, please visit BugBot documentation.
Updated•7 months ago
|
| Assignee | ||
Updated•7 months ago
|
Comment 3•7 months ago
|
||
Successfully recorded a pernosco session. A link to the pernosco session will be added here shortly.
| Assignee | ||
Comment 5•7 months ago
|
||
This is somewhat related to bug 1424656... We're appending a bunch of frames, some are captions and some are not, and we end up with the wrong parent frame.
| Assignee | ||
Comment 6•7 months ago
|
||
Having all that duplicated code is kinda useless, since append needs to
deal with insert anyways due to things like ::after and
display: contents. This fixes the issue by virtue of this check:
Which is really what's going on. IsValidSibling is wrong and can go.
Instead let WipeContainingBlock* deal with it, since we run that after
constructing the items.
This unlocks further simplifications but seems like a step in the right
direction and I don't want to get too side tracked into rewriting the
frame constructor.
The fieldset frame change mirrors table captions. Legends are dealt with
properly by the existing check in ConstructFramesFromItemList and / or
WipeContainingBlock. That allows to remove some special cases in
nsFlexContainerFrame and InspectorUtils.
Updated•7 months ago
|
| Assignee | ||
Updated•7 months ago
|
| Assignee | ||
Comment 7•7 months ago
|
||
Comment 10•7 months ago
|
||
| bugherder | ||
Comment 12•7 months ago
|
||
Verified bug as fixed on rev mozilla-central 20260103212557-bd631654e320.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.
Comment 13•7 months ago
•
|
||
(In reply to Pulsebot from comment #8)
Pushed by ealvarez@mozilla.com:
https://github.com/mozilla-firefox/firefox/commit/5e022982db6b
https://hg.mozilla.org/integration/autoland/rev/4dc50e8367a1
Unify frame constructor append and insertion codepaths.
r=TYLin,layout-reviewers
Perfherder has detected a browsertime performance change from push 4dc50e8367a1d9082bc8f8fa8296481ec97a2ba4.
No action is required from the author; this comment is provided for informational purposes only.
Improvements:
| Ratio | Test | Platform | Options | Absolute values (old vs new) | Performance Profiles |
|---|---|---|---|---|---|
| 5% | speedometer3 TodoMVC-Backbone/CompletingAllItems/Async | linux1804-64-shippable-qr | fission webrender | 5.24 -> 4.99 | Before/After |
| 4% | speedometer BackboneJS-TodoMVC/CompletingAllItems/Async | android-hw-a55-14-0-aarch64-shippable | webrender | 8.10 -> 7.79 | |
| 3% | speedometer BackboneJS-TodoMVC/CompletingAllItems/Async | android-hw-a55-14-0-aarch64-shippable | fission webrender | 8.08 -> 7.81 | |
| 2% | speedometer3 TodoMVC-Backbone/CompletingAllItems/Async | macosx1500-aarch64-shippable | fission webrender | 1.45 -> 1.41 | Before/After |
Need Help or Information?
If you have any questions, please reach out to bacasandrei@mozilla.com. Alternatively, you can find help on Slack by joining #perf-help, and on Matrix you can find help by joining #perftest.
Details of the alert can be found in the alert summary, including links to graphs and comparisons for each of the affected tests.
Description
•