Closed Bug 2048353 Opened 3 months ago Closed 2 months ago

Assertion failure: mRawPtr != nullptr (You can't dereference a NULL RefPtr with operator->().), at /builds/worker/workspace/obj-build/dist/include/mozilla/RefPtr.h:341

Categories

(Core :: Networking: Cookies, defect, P2)

defect
Points:
3

Tracking

()

RESOLVED FIXED
155 Branch
Tracking Status
firefox-esr115 --- unaffected
firefox-esr140 --- wontfix
firefox-esr153 --- fixed
firefox153 --- wontfix
firefox154 --- fixed
firefox155 --- fixed

People

(Reporter: tsmith, Assigned: baku)

References

(Blocks 1 open bug)

Details

(Keywords: assertion, pernosco, Whiteboard: [necko-triaged] [necko-priority-next])

Attachments

(3 files)

Found while fuzzing m-c 20260418-cb6a766e9c14 (--enable-debug --enable-fuzzing)

The available testcase has been difficult to reduce. A Pernosco session is available here: https://pernos.co/debug/yCCpyORj_8AicK7g6IHPQw/index.html

Assertion failure: mRawPtr != nullptr (You can't dereference a NULL RefPtr with operator->().), at /builds/worker/workspace/obj-build/dist/include/mozilla/RefPtr.h:341

#0 0x7fffe9945d26 in MOZ_CrashSequence /builds/worker/workspace/obj-build/dist/include/mozilla/Assertions.h:235:3
#1 0x7fffe9945d26 in operator-> /builds/worker/workspace/obj-build/dist/include/mozilla/RefPtr.h:340:5
#2 0x7fffe9945d26 in mozilla::dom::CookieStoreNotificationWatcherWrapper::ResolvePromiseWhenNotified(nsID const&, mozilla::dom::Promise*)::PromiseResolver::Run() /builds/worker/workspace/obj-build/dom/cookiestore/./../../../../checkouts/gecko/dom/cookiestore/CookieStoreNotificationWatcherWrapper.cpp:102:7
#3 0x7fffe5b08189 in nsThread::ProcessNextEvent(bool, bool*) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/nsThread.cpp:1173:16
#4 0x7fffe5b0dc2f in NS_ProcessNextEvent(nsIThread*, bool) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/nsThreadUtils.cpp:465:10
#5 0x7fffeb439f04 in mozilla::dom::WorkerPrivate::DoRunLoop(JSContext*) /builds/worker/workspace/obj-build/dom/workers/./../../../../checkouts/gecko/dom/workers/WorkerPrivate.cpp:3967:7
#6 0x7fffeb41d292 in mozilla::dom::workerinternals::(anonymous namespace)::WorkerThreadPrimaryRunnable::Run() /builds/worker/workspace/obj-build/dom/workers/./../../../../checkouts/gecko/dom/workers/RuntimeService.cpp:2295:42
#7 0x7fffe5b08189 in nsThread::ProcessNextEvent(bool, bool*) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/nsThread.cpp:1173:16
#8 0x7fffe5b0dc2f in NS_ProcessNextEvent(nsIThread*, bool) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/nsThreadUtils.cpp:465:10
#9 0x7fffe66e8fb9 in mozilla::ipc::MessagePumpForNonMainThreads::Run(base::MessagePump::Delegate*) /builds/worker/workspace/obj-build/ipc/glue/./../../../../checkouts/gecko/ipc/glue/MessagePump.cpp:327:5
#10 0x7fffe66408d1 in RunHandler /builds/worker/workspace/obj-build/ipc/chromium/./../../../../checkouts/gecko/ipc/chromium/src/base/message_loop.cc:364:3
#11 0x7fffe66408d1 in MessageLoop::Run() /builds/worker/workspace/obj-build/ipc/chromium/./../../../../checkouts/gecko/ipc/chromium/src/base/message_loop.cc:346:3
#12 0x7fffe5b03c5a in nsThread::ThreadFunc(void*) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/nsThread.cpp:374:10
#13 0x7ffff79ea41c in _pt_root /builds/worker/workspace/obj-build/config/external/nspr/pr/./../../../../../../checkouts/gecko/nsprpub/pr/src/pthreads/ptthread.c:190:3
#14 0x7ffff7a86ac2 in start_thread ./nptl/pthread_create.c:442:8
Severity: -- → S3
Points: --- → 3
Rank: 2
Priority: -- → P2
Whiteboard: [necko-triaged] [necko-priority-next]
Assignee: nobody → amarchesini
Status: NEW → ASSIGNED
Status: ASSIGNED → RESOLVED
Closed: 2 months ago
Resolution: --- → FIXED
Target Milestone: --- → 155 Branch

The patch landed in nightly and beta is affected.
:baku, is this bug important enough to require an uplift?

For more information, please visit BugBot documentation.

Flags: needinfo?(amarchesini)
Flags: needinfo?(amarchesini)
Attachment #9616096 - Flags: approval-mozilla-beta?

firefox-beta Uplift Approval Request

  • User impact if declined/Reason for urgency: A rare crash can occur in the content process.
  • Code covered by automated testing?: no
  • Fix verified in Nightly?: no
  • Needs manual QE testing?: no
  • Steps to reproduce for manual QE testing: n/a
  • Risk associated with taking this patch: low
  • Explanation of risk level: Extremely rare to reproduce, the fix is a variable nullptr check.
  • String changes made/needed?: n/a
  • Is Android affected?: yes
Attachment #9616096 - Flags: approval-mozilla-beta? → approval-mozilla-beta+

Please add an ESR153 uplift request also.

Flags: needinfo?(amarchesini)

firefox-esr153 Uplift Approval Request

  • User impact if declined/Reason for urgency: A rare crash can occur
  • Code covered by automated testing?: no
  • Fix verified in Nightly?: no
  • Needs manual QE testing?: no
  • Steps to reproduce for manual QE testing: n/a
  • Risk associated with taking this patch: low
  • Explanation of risk level: This is a null if-stmt check to prevent a crash. It's safe.
  • String changes made/needed?: no
  • Is Android affected?: yes
Attachment #9618464 - Flags: approval-mozilla-esr153?
Attachment #9618464 - Flags: approval-mozilla-esr153? → approval-mozilla-esr153+
QA Whiteboard: [qa-triage-done-c155/b154]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: