Assertion failure: name, at checkouts/gecko/layout/style/GeckoBindings.cpp:801
Categories
(Core :: CSS Parsing and Computation, defect)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox155 | --- | affected |
People
(Reporter: tsmith, Assigned: boris)
References
(Blocks 1 open bug, )
Details
(Keywords: assertion, pernosco, testcase-wanted)
Found with m-c 20260720-27bb72351e25 (--enable-debug)
This was found by visiting a live website with a debug build.
STR:
- Launch browser and visit site
This issue was triggered by visiting http://faciliteacoches.com/. A Pernosco session is available here: https://pernos.co/debug/f9lWXbpYCwOpfjcjc6XXig/index.html
Assertion failure: name, at checkouts/gecko/layout/style/GeckoBindings.cpp:801
0|0|libxul.so|Gecko_MatchViewTransitionClass|git:github.com/mozilla-firefox/firefox:layout/style/GeckoBindings.cpp:9631bc624c432f094ca05c276e5a5c922407859f|801|0x116
0|1|libxul.so|style::selector_map::SelectorMap<style::stylist::Rule>::get_matching_rules|git:github.com/mozilla-firefox/firefox:servo/components/style/selector_map.rs:9631bc624c432f094ca05c276e5a5c922407859f|340|0x435
0|2|libxul.so|style::rule_collector::RuleCollector<E>::collect_rules_in_map_with_target|git:github.com/mozilla-firefox/firefox:servo/components/style/rule_collector.rs:9631bc624c432f094ca05c276e5a5c922407859f|266|0x99f
0|3|libxul.so|style::rule_collector::RuleCollector<E>::collect_stylist_rules|git:github.com/mozilla-firefox/firefox:servo/components/style/rule_collector.rs:9631bc624c432f094ca05c276e5a5c922407859f|160|0x109
0|4|libxul.so|style::rule_collector::RuleCollector<E>::collect_all|git:github.com/mozilla-firefox/firefox:servo/components/style/rule_collector.rs:9631bc624c432f094ca05c276e5a5c922407859f|540|0x1a22
0|5|libxul.so|style::stylist::Stylist::push_applicable_declarations|git:github.com/mozilla-firefox/firefox:servo/components/style/stylist.rs:9631bc624c432f094ca05c276e5a5c922407859f|1748|0x332
0|6|libxul.so|geckoservo::glue::get_pseudo_style|git:github.com/mozilla-firefox/firefox:servo/ports/geckolib/glue.rs:9631bc624c432f094ca05c276e5a5c922407859f|4802|0x251
0|7|libxul.so|Servo_ResolveStyleLazily|git:github.com/mozilla-firefox/firefox:servo/ports/geckolib/glue.rs:9631bc624c432f094ca05c276e5a5c922407859f|7331|0xdb2
0|8|libxul.so|mozilla::ServoStyleSet::ResolveStyleLazily(mozilla::dom::Element const&, mozilla::PseudoStyleRequest const&, mozilla::StyleRuleInclusion)|git:github.com/mozilla-firefox/firefox:layout/style/ServoStyleSet.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1327|0xf0
0|9|libxul.so|nsComputedDOMStyle::DoGetComputedStyleNoFlush(mozilla::dom::Element const*, mozilla::PseudoStyleRequest const&, mozilla::PresShell*, nsComputedDOMStyle::StyleType)|git:github.com/mozilla-firefox/firefox:layout/style/nsComputedDOMStyle.cpp:9631bc624c432f094ca05c276e5a5c922407859f|590|0x180
0|10|libxul.so|nsComputedDOMStyle::GetComputedStyleNoFlush(mozilla::dom::Element const*, mozilla::PseudoStyleRequest const&, nsComputedDOMStyle::StyleType)|git:github.com/mozilla-firefox/firefox:layout/style/nsComputedDOMStyle.cpp:9631bc624c432f094ca05c276e5a5c922407859f|530|0x31
0|11|libxul.so|mozilla::dom::KeyframeEffect::GetTargetComputedStyle(mozilla::dom::KeyframeEffect::Flush) const|git:github.com/mozilla-firefox/firefox:dom/animation/KeyframeEffect.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1042|0xa7
0|12|libxul.so|mozilla::dom::KeyframeEffect::SetKeyframes(JSContext*, JS::Handle<JSObject*>, mozilla::ErrorResult&)|git:github.com/mozilla-firefox/firefox:dom/animation/KeyframeEffect.cpp:9631bc624c432f094ca05c276e5a5c922407859f|247|0x5c
0|13|libxul.so|mozilla::dom::KeyframeEffect::ConstructKeyframeEffect<mozilla::dom::UnrestrictedDoubleOrKeyframeAnimationOptions>(mozilla::dom::GlobalObject const&, mozilla::dom::Element*, JS::Handle<JSObject*>, mozilla::dom::UnrestrictedDoubleOrKeyframeAnimationOptions const&, mozilla::ErrorResult&)|git:github.com/mozilla-firefox/firefox:dom/animation/KeyframeEffect.cpp:9631bc624c432f094ca05c276e5a5c922407859f|864|0x31f
0|14|libxul.so|mozilla::dom::KeyframeEffect::Constructor(mozilla::dom::GlobalObject const&, mozilla::dom::Element*, JS::Handle<JSObject*>, mozilla::dom::UnrestrictedDoubleOrKeyframeAnimationOptions const&, mozilla::ErrorResult&)|git:github.com/mozilla-firefox/firefox:dom/animation/KeyframeEffect.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1079|0xd
0|15|libxul.so|mozilla::dom::Element::Animate(JSContext*, JS::Handle<JSObject*>, mozilla::dom::UnrestrictedDoubleOrKeyframeAnimationOptions const&, mozilla::ErrorResult&)|git:github.com/mozilla-firefox/firefox:dom/base/Element.cpp:9631bc624c432f094ca05c276e5a5c922407859f|5141|0xc1
0|16|libxul.so|mozilla::dom::Element_Binding::animate(JSContext*, JS::Handle<JSObject*>, void*, JSJitMethodCallArgs const&)|s3:gecko-generated-sources:67153d3aa53da89fb6e420d3d9b2c9b8b279d4e99907f1b463b961b81e42c4905ffce7ef5b0821eb7ae48cf445110214504a930d290e0ed0e0e1eef2c3e23634/dom/bindings/ElementBinding.cpp:|11873|0x21f
0|17|libxul.so|mozilla::dom::binding_detail::GenericMethod<mozilla::dom::binding_detail::NormalThisPolicy, mozilla::dom::binding_detail::ThrowExceptions>(JSContext*, unsigned int, JS::Value*)|git:github.com/mozilla-firefox/firefox:dom/bindings/BindingUtils.cpp:9631bc624c432f094ca05c276e5a5c922407859f|3216|0x1b5
0|18|libxul.so|CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|498|0xf4
0|19|libxul.so|js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|594|0x2bf
0|20|libxul.so|js::jit::DoCallFallback(JSContext*, js::jit::BaselineFrame*, js::jit::ICFallbackStub*, unsigned int, JS::Value*, JS::MutableHandle<JS::Value>)|git:github.com/mozilla-firefox/firefox:js/src/jit/BaselineIC.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1717|0x60e
0|21|||||
0|22|||||
0|23|||||
0|24|||||
0|25|libxul.so|js::jit::EnterBaselineInterpreterAtBranch(JSContext*, js::InterpreterFrame*, unsigned char*)|git:github.com/mozilla-firefox/firefox:js/src/jit/BaselineJIT.cpp:9631bc624c432f094ca05c276e5a5c922407859f|202|0x473
0|26|libxul.so|js::Interpret(JSContext*, js::RunState&)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|2040|0x8ce
0|27|libxul.so|MaybeEnterInterpreterTrampoline(JSContext*, js::RunState&)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|392|0x236
0|28|libxul.so|js::RunScript(JSContext*, js::RunState&)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|468|0x3da
0|29|libxul.so|js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|626|0x2e5
0|30|libxul.so|js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|693|0x12c
0|31|libxul.so|JS::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::HandleValueArray const&, JS::MutableHandle<JS::Value>)|git:github.com/mozilla-firefox/firefox:js/src/vm/CallAndConstruct.cpp:9631bc624c432f094ca05c276e5a5c922407859f|118|0x20b
0|32|libxul.so|mozilla::dom::ViewTransitionUpdateCallback::Call(mozilla::dom::BindingCallContext&, JS::Handle<JS::Value>, mozilla::ErrorResult&)|s3:gecko-generated-sources:426e8f19a322c14107a66612b4cedf4bfd98edff2c422ac72db8908e2aea78c54e20aeee71b63d2a43bb2b79b6cd10c242b900830d9066f0cae79f80e4e25415/dom/bindings/DocumentBinding.cpp:|730|0xde
0|33|libxul.so|mozilla::dom::ViewTransitionUpdateCallback::Call(mozilla::ErrorResult&, char const*, mozilla::dom::CallbackObjectBase::ExceptionHandling, JS::Realm*)|s3:gecko-generated-sources:3fe266a417957ca9ea2f4589f7fc9280691c73974d02e3479f45545d9a5bc76a77c1c8d0441542927338d3ffd112cdd1f597e6319f234d0a5c06622989601cf4/dist/include/mozilla/dom/DocumentBinding.h:|395|0xc3
0|34|libxul.so|mozilla::dom::ViewTransition::CallUpdateCallback(mozilla::ErrorResult&)|git:github.com/mozilla-firefox/firefox:dom/view-transitions/ViewTransition.cpp:9631bc624c432f094ca05c276e5a5c922407859f|508|0x10a
0|35|libxul.so|mozilla::dom::Document::FlushViewTransitionUpdateCallbackQueue()|git:github.com/mozilla-firefox/firefox:dom/base/Document.cpp:9631bc624c432f094ca05c276e5a5c922407859f|17430|0xb1
0|36|libxul.so|mozilla::dom::ViewTransition::MaybeScheduleUpdateCallback()|git:github.com/mozilla-firefox/firefox:dom/view-transitions/ViewTransition.cpp:9631bc624c432f094ca05c276e5a5c922407859f|473|0xcc
0|37|libxul.so|mozilla::detail::RunnableMethodImpl<nsCOMPtr<nsIThread>, nsresult (nsIThread::*)(), true, (mozilla::RunnableKind)0, >::Run()|git:github.com/mozilla-firefox/firefox:xpcom/threads/nsThreadUtils.h:9631bc624c432f094ca05c276e5a5c922407859f|1124|0x26
0|38|libxul.so|mozilla::RunnableTask::Run()|git:github.com/mozilla-firefox/firefox:xpcom/threads/TaskController.cpp:9631bc624c432f094ca05c276e5a5c922407859f|721|0x17
0|39|libxul.so|mozilla::TaskController::DoExecuteNextTaskOnlyMainThreadInternal(mozilla::detail::BaseAutoLock<mozilla::Mutex&> const&)|git:github.com/mozilla-firefox/firefox:xpcom/threads/TaskController.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1360|0x5b4
0|40|libxul.so|mozilla::TaskController::ExecuteNextTaskOnlyMainThreadInternal(mozilla::detail::BaseAutoLock<mozilla::Mutex&> const&)|git:github.com/mozilla-firefox/firefox:xpcom/threads/TaskController.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1183|0x57
0|41|libxul.so|mozilla::TaskController::ProcessPendingMTTask(bool)|git:github.com/mozilla-firefox/firefox:xpcom/threads/TaskController.cpp:9631bc624c432f094ca05c276e5a5c922407859f|657|0x65
0|42|libxul.so|mozilla::detail::RunnableFunction<mozilla::TaskController::TaskController()::$_0>::Run()|git:github.com/mozilla-firefox/firefox:xpcom/threads/nsThreadUtils.h:9631bc624c432f094ca05c276e5a5c922407859f|535|0x16
0|43|libxul.so|nsThread::ProcessNextEvent(bool, bool*)|git:github.com/mozilla-firefox/firefox:xpcom/threads/nsThread.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1180|0x5ca
0|44|libxul.so|NS_ProcessNextEvent(nsIThread*, bool)|git:github.com/mozilla-firefox/firefox:xpcom/threads/nsThreadUtils.cpp:9631bc624c432f094ca05c276e5a5c922407859f|471|0x4f
0|45|libxul.so|mozilla::ipc::MessagePump::Run(base::MessagePump::Delegate*)|git:github.com/mozilla-firefox/firefox:ipc/glue/MessagePump.cpp:9631bc624c432f094ca05c276e5a5c922407859f|83|0xc0
0|46|libxul.so|MessageLoop::Run()|git:github.com/mozilla-firefox/firefox:ipc/chromium/src/base/message_loop.cc:9631bc624c432f094ca05c276e5a5c922407859f|346|0x61
0|47|libxul.so|nsBaseAppShell::Run()|git:github.com/mozilla-firefox/firefox:widget/nsBaseAppShell.cpp:9631bc624c432f094ca05c276e5a5c922407859f|151|0x28
0|48|libxul.so|nsAppShell::Run()|git:github.com/mozilla-firefox/firefox:widget/gtk/nsAppShell.cpp:9631bc624c432f094ca05c276e5a5c922407859f|580|0x114
0|49|libxul.so|XRE_RunAppShell()|git:github.com/mozilla-firefox/firefox:toolkit/xre/nsEmbedFunctions.cpp:9631bc624c432f094ca05c276e5a5c922407859f|652|0x6b
0|50|libxul.so|mozilla::ipc::MessagePumpForChildProcess::Run(base::MessagePump::Delegate*)|git:github.com/mozilla-firefox/firefox:ipc/glue/MessagePump.cpp:9631bc624c432f094ca05c276e5a5c922407859f|233|0x3c
0|51|libxul.so|MessageLoop::Run()|git:github.com/mozilla-firefox/firefox:ipc/chromium/src/base/message_loop.cc:9631bc624c432f094ca05c276e5a5c922407859f|346|0x61
0|52|libxul.so|XRE_InitChildProcess(int, char**, XREChildData const*)|git:github.com/mozilla-firefox/firefox:toolkit/xre/nsEmbedFunctions.cpp:9631bc624c432f094ca05c276e5a5c922407859f|590|0x994
0|53|firefox-bin|main|git:github.com/mozilla-firefox/firefox:browser/app/nsBrowserApp.cpp:9631bc624c432f094ca05c276e5a5c922407859f|467|0x21c
Comment 1•1 month ago
|
||
@Boris: This looks like it's coming from view transitions code. Can you take a look?
Comment 2•23 days ago
|
||
Adding dependency on the bug that added the assertion in question.
The assertion is here:
https://searchfox.org/firefox-main/rev/6cee80f87168d5aabd9e343099e2a8e5535e5320/layout/style/GeckoBindings.cpp#800-801
nsAtom* name = Gecko_GetImplementedPseudoIdentifier(aElement);
MOZ_ASSERT(name);
It looks like Gecko_GetImplementedPseudoIdentifier does have a few early-returns that return nullptr, so presumably we're hitting one of those.
Triaging as S3 given that we appear to handle this issue gracefully in release builds (we proceed to call vt->MatchClassList(name, *aPtNameAndClassSelector); which looks up name in a hashtable and returns false if it's not found.
Updated•23 days ago
|
| Assignee | ||
Comment 3•9 days ago
|
||
Assign to myself. It seems we just need to add the error handling (and I missed some cases when adding this function)
| Assignee | ||
Updated•9 days ago
|
Description
•