Closed
Bug 2048353
Opened 3 months ago
Closed 2 months ago
Assertion failure: mRawPtr != nullptr (You can't dereference a NULL RefPtr with operator->().), at /builds/worker/workspace/obj-build/dist/include/mozilla/RefPtr.h:341
Categories
(Core :: Networking: Cookies, defect, P2)
Core
Networking: Cookies
Tracking
()
RESOLVED
FIXED
155 Branch
People
(Reporter: tsmith, Assigned: baku)
References
(Blocks 1 open bug)
Details
(Keywords: assertion, pernosco, Whiteboard: [necko-triaged] [necko-priority-next])
Attachments
(3 files)
|
48 bytes,
text/x-phabricator-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
phab-bot
:
approval-mozilla-beta+
|
Details | Review |
|
48 bytes,
text/x-phabricator-request
|
phab-bot
:
approval-mozilla-esr153+
|
Details | Review |
Found while fuzzing m-c 20260418-cb6a766e9c14 (--enable-debug --enable-fuzzing)
The available testcase has been difficult to reduce. A Pernosco session is available here: https://pernos.co/debug/yCCpyORj_8AicK7g6IHPQw/index.html
Assertion failure: mRawPtr != nullptr (You can't dereference a NULL RefPtr with operator->().), at /builds/worker/workspace/obj-build/dist/include/mozilla/RefPtr.h:341
#0 0x7fffe9945d26 in MOZ_CrashSequence /builds/worker/workspace/obj-build/dist/include/mozilla/Assertions.h:235:3
#1 0x7fffe9945d26 in operator-> /builds/worker/workspace/obj-build/dist/include/mozilla/RefPtr.h:340:5
#2 0x7fffe9945d26 in mozilla::dom::CookieStoreNotificationWatcherWrapper::ResolvePromiseWhenNotified(nsID const&, mozilla::dom::Promise*)::PromiseResolver::Run() /builds/worker/workspace/obj-build/dom/cookiestore/./../../../../checkouts/gecko/dom/cookiestore/CookieStoreNotificationWatcherWrapper.cpp:102:7
#3 0x7fffe5b08189 in nsThread::ProcessNextEvent(bool, bool*) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/nsThread.cpp:1173:16
#4 0x7fffe5b0dc2f in NS_ProcessNextEvent(nsIThread*, bool) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/nsThreadUtils.cpp:465:10
#5 0x7fffeb439f04 in mozilla::dom::WorkerPrivate::DoRunLoop(JSContext*) /builds/worker/workspace/obj-build/dom/workers/./../../../../checkouts/gecko/dom/workers/WorkerPrivate.cpp:3967:7
#6 0x7fffeb41d292 in mozilla::dom::workerinternals::(anonymous namespace)::WorkerThreadPrimaryRunnable::Run() /builds/worker/workspace/obj-build/dom/workers/./../../../../checkouts/gecko/dom/workers/RuntimeService.cpp:2295:42
#7 0x7fffe5b08189 in nsThread::ProcessNextEvent(bool, bool*) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/nsThread.cpp:1173:16
#8 0x7fffe5b0dc2f in NS_ProcessNextEvent(nsIThread*, bool) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/nsThreadUtils.cpp:465:10
#9 0x7fffe66e8fb9 in mozilla::ipc::MessagePumpForNonMainThreads::Run(base::MessagePump::Delegate*) /builds/worker/workspace/obj-build/ipc/glue/./../../../../checkouts/gecko/ipc/glue/MessagePump.cpp:327:5
#10 0x7fffe66408d1 in RunHandler /builds/worker/workspace/obj-build/ipc/chromium/./../../../../checkouts/gecko/ipc/chromium/src/base/message_loop.cc:364:3
#11 0x7fffe66408d1 in MessageLoop::Run() /builds/worker/workspace/obj-build/ipc/chromium/./../../../../checkouts/gecko/ipc/chromium/src/base/message_loop.cc:346:3
#12 0x7fffe5b03c5a in nsThread::ThreadFunc(void*) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/nsThread.cpp:374:10
#13 0x7ffff79ea41c in _pt_root /builds/worker/workspace/obj-build/config/external/nspr/pr/./../../../../../../checkouts/gecko/nsprpub/pr/src/pthreads/ptthread.c:190:3
#14 0x7ffff7a86ac2 in start_thread ./nptl/pthread_create.c:442:8
Updated•3 months ago
|
Severity: -- → S3
Points: --- → 3
Rank: 2
Priority: -- → P2
Whiteboard: [necko-triaged] [necko-priority-next]
| Assignee | ||
Comment 1•2 months ago
|
||
Updated•2 months ago
|
Assignee: nobody → amarchesini
Status: NEW → ASSIGNED
Pushed by amarchesini@mozilla.com:
https://github.com/mozilla-firefox/firefox/commit/74e007f613c1
https://hg.mozilla.org/integration/autoland/rev/c73c5600a962
Improve worker shutdown support in CookieStoreNotificationWatcher r=manuel
Status: ASSIGNED → RESOLVED
Closed: 2 months ago
status-firefox155:
--- → fixed
Resolution: --- → FIXED
Target Milestone: --- → 155 Branch
Comment 4•2 months ago
|
||
The patch landed in nightly and beta is affected.
:baku, is this bug important enough to require an uplift?
- If yes, please nominate the patch for beta approval.
- See https://wiki.mozilla.org/Release_Management/Requesting_an_Uplift for documentation on how to request an uplift.
- If no, please set
status-firefox154towontfix.
For more information, please visit BugBot documentation.
Flags: needinfo?(amarchesini)
| Assignee | ||
Updated•2 months ago
|
Flags: needinfo?(amarchesini)
| Assignee | ||
Comment 5•2 months ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D311765
Updated•2 months ago
|
Attachment #9616096 -
Flags: approval-mozilla-beta?
Comment 6•2 months ago
|
||
firefox-beta Uplift Approval Request
- User impact if declined/Reason for urgency: A rare crash can occur in the content process.
- Code covered by automated testing?: no
- Fix verified in Nightly?: no
- Needs manual QE testing?: no
- Steps to reproduce for manual QE testing: n/a
- Risk associated with taking this patch: low
- Explanation of risk level: Extremely rare to reproduce, the fix is a variable nullptr check.
- String changes made/needed?: n/a
- Is Android affected?: yes
Updated•2 months ago
|
Attachment #9616096 -
Flags: approval-mozilla-beta? → approval-mozilla-beta+
Updated•2 months ago
|
Comment 8•2 months ago
|
||
Please add an ESR153 uplift request also.
status-firefox153:
--- → wontfix
status-firefox-esr115:
--- → unaffected
status-firefox-esr140:
--- → wontfix
status-firefox-esr153:
--- → affected
Flags: needinfo?(amarchesini)
| Assignee | ||
Updated•2 months ago
|
Flags: needinfo?(amarchesini)
Comment 9•2 months ago
|
||
firefox-esr153 Uplift Approval Request
- User impact if declined/Reason for urgency: A rare crash can occur
- Code covered by automated testing?: no
- Fix verified in Nightly?: no
- Needs manual QE testing?: no
- Steps to reproduce for manual QE testing: n/a
- Risk associated with taking this patch: low
- Explanation of risk level: This is a null if-stmt check to prevent a crash. It's safe.
- String changes made/needed?: no
- Is Android affected?: yes
Attachment #9618464 -
Flags: approval-mozilla-esr153?
| Assignee | ||
Comment 10•2 months ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D311765
Updated•2 months ago
|
Attachment #9618464 -
Flags: approval-mozilla-esr153? → approval-mozilla-esr153+
Updated•2 months ago
|
Comment 11•2 months ago
|
||
| uplift | ||
Updated•1 month ago
|
QA Whiteboard: [qa-triage-done-c155/b154]
You need to log in
before you can comment on or make changes to this bug.
Description
•