Closed Bug 2053281 Opened 13 days ago Closed 8 days ago

Assertion failure: isSome(), at /builds/worker/workspace/obj-build/dist/include/mozilla/Maybe.h:1012

Categories

(Core :: DOM: Animation, defect)

defect

Tracking

()

VERIFIED FIXED
154 Branch
Tracking Status
firefox-esr140 --- unaffected
firefox152 --- wontfix
firefox153 --- wontfix
firefox154 --- verified

People

(Reporter: tsmith, Assigned: hiro)

References

(Blocks 2 open bugs, Regression)

Details

(4 keywords, Whiteboard: [bugmon:bisected,confirmed], [wptsync upstream])

Crash Data

Attachments

(5 files)

Attached file testcase.html

Found while fuzzing m-c 20260706-843b141a4b58 (--enable-address-sanitizer --enable-fuzzing)

To reproduce via Grizzly Replay:

$ pip install fuzzfetch grizzly-framework --upgrade
$ python -m fuzzfetch -a --fuzzing -n firefox
$ python -m grizzly.replay.bugzilla ./firefox/firefox <bugid>

Assertion failure: isSome(), at /builds/worker/workspace/obj-build/dist/include/mozilla/Maybe.h:1012

#0 0x6e8c75df6343 in MOZ_CrashSequence /builds/worker/workspace/obj-build/dist/include/mozilla/Assertions.h:261:3
#1 0x6e8c75df6343 in ref /builds/worker/workspace/obj-build/dist/include/mozilla/Maybe.h:1012:3
#2 0x6e8c75df6343 in Value /builds/worker/workspace/obj-build/dist/include/mozilla/dom/Nullable.h:65:30
#3 0x6e8c75df6343 in mozilla::layers::AnimationInfo::AddAnimationForProperty(nsIFrame*, mozilla::AnimationProperty const&, mozilla::dom::Animation*, mozilla::Maybe<mozilla::layers::TransformData> const&, mozilla::layers::AnimationInfo::Send) /builds/worker/workspace/obj-build/gfx/layers/./../../../../checkouts/gecko/gfx/layers/AnimationInfo.cpp:470:66
#4 0x6e8c75df73e4 in mozilla::layers::AnimationInfo::AddAnimationsForProperty(nsIFrame*, mozilla::EffectSet const*, nsTArray<RefPtr<mozilla::dom::Animation>> const&, mozilla::Maybe<mozilla::layers::TransformData> const&, NonCustomCSSPropertyId, mozilla::layers::AnimationInfo::Send, mozilla::layers::WebRenderLayerManager*) /builds/worker/workspace/obj-build/gfx/layers/./../../../../checkouts/gecko/gfx/layers/AnimationInfo.cpp:657:5
#5 0x6e8c75dfdc4e in mozilla::layers::AnimationInfo::AddAnimationsForDisplayItem(nsIFrame*, mozilla::nsDisplayListBuilder*, mozilla::nsDisplayItem*, DisplayItemType, mozilla::layers::WebRenderLayerManager*, mozilla::Maybe<mozilla::gfx::PointTyped<mozilla::LayoutDevicePixel, float>> const&) /builds/worker/workspace/obj-build/gfx/layers/./../../../../checkouts/gecko/gfx/layers/AnimationInfo.cpp:1016:18
#6 0x6e8c80303b64 in mozilla::AddAnimationsForWebRender(mozilla::nsDisplayItem*, mozilla::layers::RenderRootStateManager*, mozilla::nsDisplayListBuilder*, mozilla::Maybe<mozilla::gfx::PointTyped<mozilla::LayoutDevicePixel, float>> const&) /builds/worker/workspace/obj-build/layout/painting/./../../../../checkouts/gecko/layout/painting/nsDisplayList.cpp:405:17
#7 0x6e8c8030ff86 in mozilla::nsDisplayOpacity::CreateWebRenderCommands(mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, mozilla::layers::StackingContextHelper const&, mozilla::layers::RenderRootStateManager*, mozilla::nsDisplayListBuilder*) /builds/worker/workspace/obj-build/layout/painting/./../../../../checkouts/gecko/layout/painting/nsDisplayList.cpp:5255:7
#8 0x6e8c7633400f in mozilla::layers::WebRenderCommandBuilder::CreateWebRenderCommands(mozilla::nsDisplayItem*, mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, mozilla::layers::StackingContextHelper const&, mozilla::nsDisplayListBuilder*) /builds/worker/workspace/obj-build/gfx/layers/./../../../../checkouts/gecko/gfx/layers/wr/WebRenderCommandBuilder.cpp:1862:41
#9 0x6e8c76331f0c in mozilla::layers::WebRenderCommandBuilder::CreateWebRenderCommandsFromDisplayList(mozilla::nsDisplayList*, mozilla::nsDisplayItem*, mozilla::nsDisplayListBuilder*, mozilla::layers::StackingContextHelper const&, mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, bool) /builds/worker/workspace/obj-build/gfx/layers/./../../../../checkouts/gecko/gfx/layers/wr/WebRenderCommandBuilder.cpp:2187:7
#10 0x6e8c80320769 in mozilla::nsDisplayTransform::CreateWebRenderCommands(mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, mozilla::layers::StackingContextHelper const&, mozilla::layers::RenderRootStateManager*, mozilla::nsDisplayListBuilder*) /builds/worker/workspace/obj-build/layout/painting/./../../../../checkouts/gecko/layout/painting/nsDisplayList.cpp:6986:30
#11 0x6e8c7633400f in mozilla::layers::WebRenderCommandBuilder::CreateWebRenderCommands(mozilla::nsDisplayItem*, mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, mozilla::layers::StackingContextHelper const&, mozilla::nsDisplayListBuilder*) /builds/worker/workspace/obj-build/gfx/layers/./../../../../checkouts/gecko/gfx/layers/wr/WebRenderCommandBuilder.cpp:1862:41
#12 0x6e8c76331f0c in mozilla::layers::WebRenderCommandBuilder::CreateWebRenderCommandsFromDisplayList(mozilla::nsDisplayList*, mozilla::nsDisplayItem*, mozilla::nsDisplayListBuilder*, mozilla::layers::StackingContextHelper const&, mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, bool) /builds/worker/workspace/obj-build/gfx/layers/./../../../../checkouts/gecko/gfx/layers/wr/WebRenderCommandBuilder.cpp:2187:7
#13 0x6e8c80313003 in CreateWebRenderCommandsNewClipListOption /builds/worker/workspace/obj-build/layout/painting/./../../../../checkouts/gecko/layout/painting/nsDisplayList.cpp:4891:30
#14 0x6e8c80313003 in CreateWebRenderCommands /builds/worker/workspace/obj-build/layout/painting/./../../../../checkouts/gecko/layout/painting/nsDisplayList.h:5001:12
#15 0x6e8c80313003 in mozilla::nsDisplayOwnLayer::CreateWebRenderCommands(mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, mozilla::layers::StackingContextHelper const&, mozilla::layers::RenderRootStateManager*, mozilla::nsDisplayListBuilder*, bool) /builds/worker/workspace/obj-build/layout/painting/./../../../../checkouts/gecko/layout/painting/nsDisplayList.cpp:5566:22
#16 0x6e8c80315ad3 in mozilla::nsDisplayOwnLayer::CreateWebRenderCommands(mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, mozilla::layers::StackingContextHelper const&, mozilla::layers::RenderRootStateManager*, mozilla::nsDisplayListBuilder*) /builds/worker/workspace/obj-build/layout/painting/./../../../../checkouts/gecko/layout/painting/nsDisplayList.h:5515:12
#17 0x6e8c7633400f in mozilla::layers::WebRenderCommandBuilder::CreateWebRenderCommands(mozilla::nsDisplayItem*, mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, mozilla::layers::StackingContextHelper const&, mozilla::nsDisplayListBuilder*) /builds/worker/workspace/obj-build/gfx/layers/./../../../../checkouts/gecko/gfx/layers/wr/WebRenderCommandBuilder.cpp:1862:41
#18 0x6e8c76331f0c in mozilla::layers::WebRenderCommandBuilder::CreateWebRenderCommandsFromDisplayList(mozilla::nsDisplayList*, mozilla::nsDisplayItem*, mozilla::nsDisplayListBuilder*, mozilla::layers::StackingContextHelper const&, mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, bool) /builds/worker/workspace/obj-build/gfx/layers/./../../../../checkouts/gecko/gfx/layers/wr/WebRenderCommandBuilder.cpp:2187:7
#19 0x6e8c7632fb21 in mozilla::layers::WebRenderCommandBuilder::BuildWebRenderCommands(mozilla::wr::DisplayListBuilder&, mozilla::wr::IpcResourceUpdateQueue&, mozilla::nsDisplayList*, mozilla::nsDisplayListBuilder*, mozilla::layers::WebRenderScrollData&, WrFiltersHolder&&) /builds/worker/workspace/obj-build/gfx/layers/./../../../../checkouts/gecko/gfx/layers/wr/WebRenderCommandBuilder.cpp:1788:5
#20 0x6e8c763ab10c in mozilla::layers::WebRenderLayerManager::EndTransactionWithoutLayer(mozilla::nsDisplayList*, mozilla::nsDisplayListBuilder*, WrFiltersHolder&&, mozilla::layers::WebRenderBackgroundData*, double, bool) /builds/worker/workspace/obj-build/gfx/layers/./../../../../checkouts/gecko/gfx/layers/wr/WebRenderLayerManager.cpp:373:30
#21 0x6e8c802ea692 in mozilla::nsDisplayList::PaintRoot(mozilla::nsDisplayListBuilder*, gfxContext*, unsigned int, mozilla::Maybe<double>) /builds/worker/workspace/obj-build/layout/painting/./../../../../checkouts/gecko/layout/painting/nsDisplayList.cpp:2355:18
#22 0x6e8c7fbbe954 in nsLayoutUtils::PaintFrame(gfxContext*, nsIFrame*, nsRegion const&, unsigned int, mozilla::nsDisplayListBuilderMode, nsLayoutUtils::PaintFrameFlags) /builds/worker/workspace/obj-build/layout/base/./../../../../checkouts/gecko/layout/base/nsLayoutUtils.cpp:3307:9
#23 0x6e8c7fac793d in mozilla::PresShell::PaintInternal(nsIFrame*, mozilla::WindowRenderer*, mozilla::PaintInternalFlags) /builds/worker/workspace/obj-build/layout/base/./../../../../checkouts/gecko/layout/base/PresShell.cpp:6695:5
#24 0x6e8c7faec1a3 in PaintAndRequestComposite /builds/worker/workspace/obj-build/layout/base/./../../../../checkouts/gecko/layout/base/PresShell.cpp:6557:3
#25 0x6e8c7faec1a3 in mozilla::PresShell::PaintSynchronously() /builds/worker/workspace/obj-build/layout/base/./../../../../checkouts/gecko/layout/base/PresShell.cpp:12552:3
#26 0x6e8c7fa348e8 in nsRefreshDriver::PaintIfNeeded() /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:2671:9
#27 0x6e8c7fa33713 in operator() /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:2586:60
#28 0x6e8c7fa33713 in void nsRefreshDriver::RunRenderingPhaseLegacy<nsRefreshDriver::Tick(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp, nsRefreshDriver::IsExtraTick)::$_14>(mozilla::RenderingPhase, nsRefreshDriver::Tick(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp, nsRefreshDriver::IsExtraTick)::$_14&&) /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:1281:3
#29 0x6e8c7fa2616c in nsRefreshDriver::Tick(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp, nsRefreshDriver::IsExtraTick) /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:2584:3
#30 0x6e8c7fa3c756 in TickDriver /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:365:13
#31 0x6e8c7fa3c756 in mozilla::RefreshDriverTimer::TickRefreshDrivers(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp, nsTArray<RefPtr<nsRefreshDriver>>&) /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:343:7
#32 0x6e8c7fa3c51a in mozilla::RefreshDriverTimer::Tick(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp) /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:359:5
#33 0x6e8c7fa3c191 in mozilla::VsyncRefreshDriverTimer::RunRefreshDrivers(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp) /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:946:5
#34 0x6e8c7fa3b039 in mozilla::VsyncRefreshDriverTimer::TickRefreshDriver(mozilla::layers::BaseTransactionId<mozilla::VsyncIdType>, mozilla::TimeStamp) /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:856:5
#35 0x6e8c7fa39288 in mozilla::VsyncRefreshDriverTimer::RefreshDriverVsyncObserver::NotifyVsyncTimerOnMainThread() /builds/worker/checkouts/gecko/layout/base/nsRefreshDriver.cpp:587:14
#36 0x6e8c7e06882b in mozilla::dom::VsyncMainChild::RecvNotify(mozilla::VsyncEvent const&, float const&) /builds/worker/checkouts/gecko/dom/ipc/VsyncMainChild.cpp:64:15
#37 0x6e8c7e53c7f9 in mozilla::dom::PVsyncChild::OnMessageReceived(IPC::Message const&) /builds/worker/workspace/obj-build/dom/ipc/./../../ipc/ipdl/PVsyncChild.cpp:241:78
#38 0x6e8c74f8e6aa in mozilla::ipc::PBackgroundChild::OnMessageReceived(IPC::Message const&) /builds/worker/workspace/obj-build/ipc/glue/./../ipdl/PBackgroundChild.cpp:4955:32
#39 0x6e8c74ee0815 in mozilla::ipc::MessageChannel::DispatchAsyncMessage(mozilla::ipc::ActorLifecycleProxy*, IPC::Message const&) /builds/worker/workspace/obj-build/ipc/glue/./../../../../checkouts/gecko/ipc/glue/MessageChannel.cpp:1797:25
#40 0x6e8c74edcd0e in mozilla::ipc::MessageChannel::DispatchMessage(mozilla::ipc::ActorLifecycleProxy*, std::unique_ptr<IPC::Message, std::default_delete<IPC::Message>>) /builds/worker/workspace/obj-build/ipc/glue/./../../../../checkouts/gecko/ipc/glue/MessageChannel.cpp:1723:9
#41 0x6e8c74eddb27 in mozilla::ipc::MessageChannel::RunMessage(mozilla::ipc::ActorLifecycleProxy*, mozilla::ipc::MessageChannel::MessageTask&) /builds/worker/workspace/obj-build/ipc/glue/./../../../../checkouts/gecko/ipc/glue/MessageChannel.cpp:1512:3
#42 0x6e8c74edf043 in mozilla::ipc::MessageChannel::MessageTask::Run() /builds/worker/workspace/obj-build/ipc/glue/./../../../../checkouts/gecko/ipc/glue/MessageChannel.cpp:1614:14
#43 0x6e8c74c87baa in mozilla::RunnableTask::Run() /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/TaskController.cpp:719:16
#44 0x6e8c74c68619 in mozilla::TaskController::RunTask(mozilla::Task*) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/TaskController.cpp:210:19
#45 0x6e8c74c6fabd in mozilla::TaskController::DoExecuteNextTaskOnlyMainThreadInternal(mozilla::detail::BaseAutoLock<mozilla::Mutex&> const&) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/TaskController.cpp:1358:20
#46 0x6e8c74c6d598 in mozilla::TaskController::ExecuteNextTaskOnlyMainThreadInternal(mozilla::detail::BaseAutoLock<mozilla::Mutex&> const&) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/TaskController.cpp:1181:15
#47 0x6e8c74c6dbb6 in mozilla::TaskController::ProcessPendingMTTask(bool) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/TaskController.cpp:655:36
#48 0x6e8c74c86381 in operator() /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/TaskController.cpp:347:37
#49 0x6e8c74c86381 in mozilla::detail::RunnableFunction<mozilla::TaskController::TaskController()::$_0>::Run() /builds/worker/checkouts/gecko/xpcom/threads/nsThreadUtils.h:536:5
#50 0x6e8c74cab13c in nsThread::ProcessNextEvent(bool, bool*) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/nsThread.cpp:1179:16
#51 0x6e8c74cb5739 in NS_ProcessNextEvent(nsIThread*, bool) /builds/worker/workspace/obj-build/xpcom/threads/./../../../../checkouts/gecko/xpcom/threads/nsThreadUtils.cpp:472:10
#52 0x6e8c74eea72e in mozilla::ipc::MessagePump::Run(base::MessagePump::Delegate*) /builds/worker/workspace/obj-build/ipc/glue/./../../../../checkouts/gecko/ipc/glue/MessagePump.cpp:83:21
#53 0x6e8c74dc1df4 in RunInternal /builds/worker/workspace/obj-build/ipc/chromium/./../../../../checkouts/gecko/ipc/chromium/src/base/message_loop.cc:371:10
#54 0x6e8c74dc1df4 in RunHandler /builds/worker/workspace/obj-build/ipc/chromium/./../../../../checkouts/gecko/ipc/chromium/src/base/message_loop.cc:364:3
#55 0x6e8c74dc1df4 in MessageLoop::Run() /builds/worker/workspace/obj-build/ipc/chromium/./../../../../checkouts/gecko/ipc/chromium/src/base/message_loop.cc:346:3
#56 0x6e8c7f1f2226 in nsBaseAppShell::Run() /builds/worker/workspace/obj-build/widget/./../../../checkouts/gecko/widget/nsBaseAppShell.cpp:151:27
#57 0x6e8c7f3fac0b in nsAppShell::Run() /builds/worker/workspace/obj-build/widget/gtk/./../../../../checkouts/gecko/widget/gtk/nsAppShell.cpp:575:33
#58 0x6e8c8156f3cd in XRE_RunAppShell() /builds/worker/checkouts/gecko/toolkit/xre/nsEmbedFunctions.cpp:656:20
#59 0x6e8c74dc1df4 in RunInternal /builds/worker/workspace/obj-build/ipc/chromium/./../../../../checkouts/gecko/ipc/chromium/src/base/message_loop.cc:371:10
#60 0x6e8c74dc1df4 in RunHandler /builds/worker/workspace/obj-build/ipc/chromium/./../../../../checkouts/gecko/ipc/chromium/src/base/message_loop.cc:364:3
#61 0x6e8c74dc1df4 in MessageLoop::Run() /builds/worker/workspace/obj-build/ipc/chromium/./../../../../checkouts/gecko/ipc/chromium/src/base/message_loop.cc:346:3
#62 0x6e8c8156e261 in XRE_InitChildProcess(int, char**, XREChildData const*) /builds/worker/checkouts/gecko/toolkit/xre/nsEmbedFunctions.cpp:594:34
#63 0x6083fdd2e13a in main /builds/worker/checkouts/gecko/browser/app/nsBrowserApp.cpp:466:22
Flags: in-testsuite?
Severity: -- → S3

Verified bug as reproducible on mozilla-central 20260707211043-969c51e9686e.
The bug appears to have been introduced in the following build range:

Start: cd5c8ea47a94fe0baa60d3a3af9dd69446f216c1 (20260514030841)
End: 3710783bfb55cfe094adb9a5ba79603f27ae4d4b (20260514091837)
Pushlog: https://hg.mozilla.org/integration/autoland/pushloghtml?fromchange=cd5c8ea47a94fe0baa60d3a3af9dd69446f216c1&tochange=3710783bfb55cfe094adb9a5ba79603f27ae4d4b

Keywords: regression
Whiteboard: [bugmon:bisected,confirmed]
Crash Signature: [@ mozilla::Maybe<T>::ref | mozilla::dom::Nullable<T>::Value ]
See Also: → 2039708

I guess this is caused by Bug 2039214, from the bisect.

Regressions: 2039214
Regressed by: 2039214
No longer regressions: 2039214

Set release status flags based on info from the regressing bug 2039214

:hiro, since you are the author of the regressor, bug 2039214, could you take a look?

For more information, please visit BugBot documentation.

Flags: needinfo?(hikezoe.birchill)

We are trying to send a scroll driven animation that the timeline has no mCachedCurrentTime. The reason why no mCachedCurrentTime is the scroll range is not scrollable at that moment.

https://searchfox.org/firefox-main/rev/0088392ab4ccab730743ed188ddec62d04e578b7/dom/animation/ScrollTimeline.cpp#401-406

// If there is no scrollable overflow, then the ScrollTimeline is inactive.
// https://drafts.csswg.org/scroll-animations-1/#scrolltimeline-interface
if (!scrollContainerFrame->GetAvailableScrollingDirections().contains(
        orientation)) {
  return prevCachedCurrentTime.isSome();
}

On the other hand in IsMatchForCompositor

https://searchfox.org/firefox-main/rev/0088392ab4ccab730743ed188ddec62d04e578b7/dom/animation/KeyframeEffect.cpp#2065,2069

// 4. the scrolling direction is not available (i.e. no scroll range).
...
    !state.ScrollingDirectionIsAvailable() ||

And https://searchfox.org/firefox-main/rev/0088392ab4ccab730743ed188ddec62d04e578b7/dom/animation/ScrollTimeline.cpp#336-341

bool ScrollTimeline::State::ScrollingDirectionIsAvailable() const {
  const ScrollContainerFrame* scrollContainerFrame = GetScrollContainerFrame();
  MOZ_ASSERT(scrollContainerFrame);
  return scrollContainerFrame->GetAvailableScrollingDirections().contains(
      Axis());
}

So I am almost 100% sure that when IsMatchForCompositor gets called, the scroll timeline is stale, hasn't yet properly updated. :/

See Also: → 2040244

Mayank, I wonder why you added bug 2039708 into "See Also"?

I am going to drop the bug since it's indirectly related to this bug, ScrollTimeline animations, but fundamentally it's unrelated.

See Also: 2039708
Attached file More reduced test case

This is tricky.

The scroll range is changed by the other animation. If the scroll timeline is stale and the timeline's
container was no scroll range at the time we call UpdateStaleTimelines() in DetermineProximityToViewportAndNotifyResizeObservers(), then it triggers an additional style flush here:

https://searchfox.org/firefox-main/rev/0088392ab4ccab730743ed188ddec62d04e578b7/dom/base/Document.cpp#19394-19396

if (mTimelinesController.UpdateStaleTimelines()) {
  FlushPendingNotifications(ctf);
}

Then because of the style flush, the scroll container now has a valid scroll range, then we try to send the animation to the compositor since now state.ScrollingDirectionIsAvailable() in IsMatchForCompositor returns true.

There are two questions:

  1. Does the UpdateStaleTimelines() get repeatedly called until there's no stale timeline? -> I don't think so, it will lead an infinite loop
  2. Should the ScrollTimeline state used in IsMatchForCompositor be consistent with the cached state? I think so, yes

For 2), as of now there are four call sites of ScrollTimeline::GetState, two of them are in UpdateCachedCurrentTime, so they don't matter at all. The last call site is in AnimationInfo so it's also related to compositor runnable animations.

Boris, what do you think about ^ . If we take 2) approach, we will have mCachedState in ScrollTimeline, I guess.

Flags: needinfo?(hikezoe.birchill) → needinfo?(boris.chiou)

(In reply to Hiroyuki Ikezoe (:hiro) from comment #6)

Mayank, I wonder why you added bug 2039708 into "See Also"?

The crash was around the same general area of animation, and the crash signature was the same. So the crash-stats page suggested that other bug which had the same signature.

(In reply to Hiroyuki Ikezoe (:hiro) from comment #7)

  1. Does the UpdateStaleTimelines() get repeatedly called until there's no stale timeline? -> I don't think so, it will lead an infinite loop

Agree. We intend to update the timeline once per frame to avoid the cyclic updates, so we shouldn't repeatedly call it.

  1. Should the ScrollTimeline state used in IsMatchForCompositor be consistent with the cached state? I think so, yes

For 2), as of now there are four call sites of ScrollTimeline::GetState, two of them are in UpdateCachedCurrentTime, so they don't matter at all. The last call site is in AnimationInfo so it's also related to compositor runnable animations.

Right. It'd be better to make sure that we use the same scroll state for both the cached current time and OMTA, so I'm fine to cache it if needed (to make sure they are consistent).

Flags: needinfo?(boris.chiou)

Thank you, Boris! Patches are coming.

Rename ScrollTimeline::State to StateSnapshot and capture the frame-derived
scroll state (active, physical axis, available scrolling direction, source
scroll style, APZ activity) up-front in its constructor instead of querying the
scroll container frame lazily from each accessor.

This is a pure refactor with no behavior change: GetSnapshot() (renamed from
GetState()) still builds a fresh snapshot on every call. It prepares for caching
the snapshot so the state used to send compositor animations stays consistent
with the sampled current time.

Assignee: nobody → hikezoe.birchill
Status: NEW → ASSIGNED

Without a paint, the scroll container doesn't have a displayport so that
state.APZIsActiveForSource() check in KeyframeEffect::IsMatchForCompositor
fails with the cached ScrollTimeline state.

Pushed by hikezoe.birchill@mozilla.com: https://github.com/mozilla-firefox/firefox/commit/78047ee65180 https://hg.mozilla.org/integration/autoland/rev/f15ead5f6e63 Make sure each newly created scroll container has been painted once. r=layout-reviewers,layout-scroll-driven-animation-reviewers,firefox-style-system-reviewers,boris https://github.com/mozilla-firefox/firefox/commit/fad3cc026275 https://hg.mozilla.org/integration/autoland/rev/66f1fa3825ec Snapshot ScrollTimeline scroll state eagerly. r=layout-scroll-driven-animation-reviewers,boris https://github.com/mozilla-firefox/firefox/commit/f37856652294 https://hg.mozilla.org/integration/autoland/rev/e04209bf6903 Cache the ScrollTimeline scroll state used for compositor animations. r=layout-scroll-driven-animation-reviewers,boris

Created web-platform-tests PR https://github.com/web-platform-tests/wpt/pull/61242 for changes under testing/web-platform/tests

Whiteboard: [bugmon:bisected,confirmed] → [bugmon:bisected,confirmed], [wptsync upstream]

Upstream PR merged by moz-wptsync-bot

Verified bug as fixed on rev mozilla-central 20260713093315-88b0f8e6a592.
Removing bugmon keyword as no further action possible. Please review the bug and re-add the keyword for further analysis.

Status: RESOLVED → VERIFIED
Keywords: bugmon
Flags: in-testsuite? → in-testsuite+
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: