Open Bug 2056642 Opened 1 month ago Updated 9 days ago

Assertion failure: name, at checkouts/gecko/layout/style/GeckoBindings.cpp:801

Categories

(Core :: CSS Parsing and Computation, defect)

defect

Tracking

()

Tracking Status
firefox155 --- affected

People

(Reporter: tsmith, Assigned: boris)

References

(Blocks 1 open bug, )

Details

(Keywords: assertion, pernosco, testcase-wanted)

Found with m-c 20260720-27bb72351e25 (--enable-debug)

This was found by visiting a live website with a debug build.

STR:

  • Launch browser and visit site

This issue was triggered by visiting http://faciliteacoches.com/. A Pernosco session is available here: https://pernos.co/debug/f9lWXbpYCwOpfjcjc6XXig/index.html

Assertion failure: name, at checkouts/gecko/layout/style/GeckoBindings.cpp:801

0|0|libxul.so|Gecko_MatchViewTransitionClass|git:github.com/mozilla-firefox/firefox:layout/style/GeckoBindings.cpp:9631bc624c432f094ca05c276e5a5c922407859f|801|0x116
0|1|libxul.so|style::selector_map::SelectorMap<style::stylist::Rule>::get_matching_rules|git:github.com/mozilla-firefox/firefox:servo/components/style/selector_map.rs:9631bc624c432f094ca05c276e5a5c922407859f|340|0x435
0|2|libxul.so|style::rule_collector::RuleCollector<E>::collect_rules_in_map_with_target|git:github.com/mozilla-firefox/firefox:servo/components/style/rule_collector.rs:9631bc624c432f094ca05c276e5a5c922407859f|266|0x99f
0|3|libxul.so|style::rule_collector::RuleCollector<E>::collect_stylist_rules|git:github.com/mozilla-firefox/firefox:servo/components/style/rule_collector.rs:9631bc624c432f094ca05c276e5a5c922407859f|160|0x109
0|4|libxul.so|style::rule_collector::RuleCollector<E>::collect_all|git:github.com/mozilla-firefox/firefox:servo/components/style/rule_collector.rs:9631bc624c432f094ca05c276e5a5c922407859f|540|0x1a22
0|5|libxul.so|style::stylist::Stylist::push_applicable_declarations|git:github.com/mozilla-firefox/firefox:servo/components/style/stylist.rs:9631bc624c432f094ca05c276e5a5c922407859f|1748|0x332
0|6|libxul.so|geckoservo::glue::get_pseudo_style|git:github.com/mozilla-firefox/firefox:servo/ports/geckolib/glue.rs:9631bc624c432f094ca05c276e5a5c922407859f|4802|0x251
0|7|libxul.so|Servo_ResolveStyleLazily|git:github.com/mozilla-firefox/firefox:servo/ports/geckolib/glue.rs:9631bc624c432f094ca05c276e5a5c922407859f|7331|0xdb2
0|8|libxul.so|mozilla::ServoStyleSet::ResolveStyleLazily(mozilla::dom::Element const&, mozilla::PseudoStyleRequest const&, mozilla::StyleRuleInclusion)|git:github.com/mozilla-firefox/firefox:layout/style/ServoStyleSet.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1327|0xf0
0|9|libxul.so|nsComputedDOMStyle::DoGetComputedStyleNoFlush(mozilla::dom::Element const*, mozilla::PseudoStyleRequest const&, mozilla::PresShell*, nsComputedDOMStyle::StyleType)|git:github.com/mozilla-firefox/firefox:layout/style/nsComputedDOMStyle.cpp:9631bc624c432f094ca05c276e5a5c922407859f|590|0x180
0|10|libxul.so|nsComputedDOMStyle::GetComputedStyleNoFlush(mozilla::dom::Element const*, mozilla::PseudoStyleRequest const&, nsComputedDOMStyle::StyleType)|git:github.com/mozilla-firefox/firefox:layout/style/nsComputedDOMStyle.cpp:9631bc624c432f094ca05c276e5a5c922407859f|530|0x31
0|11|libxul.so|mozilla::dom::KeyframeEffect::GetTargetComputedStyle(mozilla::dom::KeyframeEffect::Flush) const|git:github.com/mozilla-firefox/firefox:dom/animation/KeyframeEffect.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1042|0xa7
0|12|libxul.so|mozilla::dom::KeyframeEffect::SetKeyframes(JSContext*, JS::Handle<JSObject*>, mozilla::ErrorResult&)|git:github.com/mozilla-firefox/firefox:dom/animation/KeyframeEffect.cpp:9631bc624c432f094ca05c276e5a5c922407859f|247|0x5c
0|13|libxul.so|mozilla::dom::KeyframeEffect::ConstructKeyframeEffect<mozilla::dom::UnrestrictedDoubleOrKeyframeAnimationOptions>(mozilla::dom::GlobalObject const&, mozilla::dom::Element*, JS::Handle<JSObject*>, mozilla::dom::UnrestrictedDoubleOrKeyframeAnimationOptions const&, mozilla::ErrorResult&)|git:github.com/mozilla-firefox/firefox:dom/animation/KeyframeEffect.cpp:9631bc624c432f094ca05c276e5a5c922407859f|864|0x31f
0|14|libxul.so|mozilla::dom::KeyframeEffect::Constructor(mozilla::dom::GlobalObject const&, mozilla::dom::Element*, JS::Handle<JSObject*>, mozilla::dom::UnrestrictedDoubleOrKeyframeAnimationOptions const&, mozilla::ErrorResult&)|git:github.com/mozilla-firefox/firefox:dom/animation/KeyframeEffect.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1079|0xd
0|15|libxul.so|mozilla::dom::Element::Animate(JSContext*, JS::Handle<JSObject*>, mozilla::dom::UnrestrictedDoubleOrKeyframeAnimationOptions const&, mozilla::ErrorResult&)|git:github.com/mozilla-firefox/firefox:dom/base/Element.cpp:9631bc624c432f094ca05c276e5a5c922407859f|5141|0xc1
0|16|libxul.so|mozilla::dom::Element_Binding::animate(JSContext*, JS::Handle<JSObject*>, void*, JSJitMethodCallArgs const&)|s3:gecko-generated-sources:67153d3aa53da89fb6e420d3d9b2c9b8b279d4e99907f1b463b961b81e42c4905ffce7ef5b0821eb7ae48cf445110214504a930d290e0ed0e0e1eef2c3e23634/dom/bindings/ElementBinding.cpp:|11873|0x21f
0|17|libxul.so|mozilla::dom::binding_detail::GenericMethod<mozilla::dom::binding_detail::NormalThisPolicy, mozilla::dom::binding_detail::ThrowExceptions>(JSContext*, unsigned int, JS::Value*)|git:github.com/mozilla-firefox/firefox:dom/bindings/BindingUtils.cpp:9631bc624c432f094ca05c276e5a5c922407859f|3216|0x1b5
0|18|libxul.so|CallJSNative(JSContext*, bool (*)(JSContext*, unsigned int, JS::Value*), js::CallReason, JS::CallArgs const&)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|498|0xf4
0|19|libxul.so|js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|594|0x2bf
0|20|libxul.so|js::jit::DoCallFallback(JSContext*, js::jit::BaselineFrame*, js::jit::ICFallbackStub*, unsigned int, JS::Value*, JS::MutableHandle<JS::Value>)|git:github.com/mozilla-firefox/firefox:js/src/jit/BaselineIC.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1717|0x60e
0|21|||||
0|22|||||
0|23|||||
0|24|||||
0|25|libxul.so|js::jit::EnterBaselineInterpreterAtBranch(JSContext*, js::InterpreterFrame*, unsigned char*)|git:github.com/mozilla-firefox/firefox:js/src/jit/BaselineJIT.cpp:9631bc624c432f094ca05c276e5a5c922407859f|202|0x473
0|26|libxul.so|js::Interpret(JSContext*, js::RunState&)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|2040|0x8ce
0|27|libxul.so|MaybeEnterInterpreterTrampoline(JSContext*, js::RunState&)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|392|0x236
0|28|libxul.so|js::RunScript(JSContext*, js::RunState&)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|468|0x3da
0|29|libxul.so|js::InternalCallOrConstruct(JSContext*, JS::CallArgs const&, js::MaybeConstruct, js::CallReason)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|626|0x2e5
0|30|libxul.so|js::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, js::AnyInvokeArgs const&, JS::MutableHandle<JS::Value>, js::CallReason)|git:github.com/mozilla-firefox/firefox:js/src/vm/Interpreter.cpp:9631bc624c432f094ca05c276e5a5c922407859f|693|0x12c
0|31|libxul.so|JS::Call(JSContext*, JS::Handle<JS::Value>, JS::Handle<JS::Value>, JS::HandleValueArray const&, JS::MutableHandle<JS::Value>)|git:github.com/mozilla-firefox/firefox:js/src/vm/CallAndConstruct.cpp:9631bc624c432f094ca05c276e5a5c922407859f|118|0x20b
0|32|libxul.so|mozilla::dom::ViewTransitionUpdateCallback::Call(mozilla::dom::BindingCallContext&, JS::Handle<JS::Value>, mozilla::ErrorResult&)|s3:gecko-generated-sources:426e8f19a322c14107a66612b4cedf4bfd98edff2c422ac72db8908e2aea78c54e20aeee71b63d2a43bb2b79b6cd10c242b900830d9066f0cae79f80e4e25415/dom/bindings/DocumentBinding.cpp:|730|0xde
0|33|libxul.so|mozilla::dom::ViewTransitionUpdateCallback::Call(mozilla::ErrorResult&, char const*, mozilla::dom::CallbackObjectBase::ExceptionHandling, JS::Realm*)|s3:gecko-generated-sources:3fe266a417957ca9ea2f4589f7fc9280691c73974d02e3479f45545d9a5bc76a77c1c8d0441542927338d3ffd112cdd1f597e6319f234d0a5c06622989601cf4/dist/include/mozilla/dom/DocumentBinding.h:|395|0xc3
0|34|libxul.so|mozilla::dom::ViewTransition::CallUpdateCallback(mozilla::ErrorResult&)|git:github.com/mozilla-firefox/firefox:dom/view-transitions/ViewTransition.cpp:9631bc624c432f094ca05c276e5a5c922407859f|508|0x10a
0|35|libxul.so|mozilla::dom::Document::FlushViewTransitionUpdateCallbackQueue()|git:github.com/mozilla-firefox/firefox:dom/base/Document.cpp:9631bc624c432f094ca05c276e5a5c922407859f|17430|0xb1
0|36|libxul.so|mozilla::dom::ViewTransition::MaybeScheduleUpdateCallback()|git:github.com/mozilla-firefox/firefox:dom/view-transitions/ViewTransition.cpp:9631bc624c432f094ca05c276e5a5c922407859f|473|0xcc
0|37|libxul.so|mozilla::detail::RunnableMethodImpl<nsCOMPtr<nsIThread>, nsresult (nsIThread::*)(), true, (mozilla::RunnableKind)0, >::Run()|git:github.com/mozilla-firefox/firefox:xpcom/threads/nsThreadUtils.h:9631bc624c432f094ca05c276e5a5c922407859f|1124|0x26
0|38|libxul.so|mozilla::RunnableTask::Run()|git:github.com/mozilla-firefox/firefox:xpcom/threads/TaskController.cpp:9631bc624c432f094ca05c276e5a5c922407859f|721|0x17
0|39|libxul.so|mozilla::TaskController::DoExecuteNextTaskOnlyMainThreadInternal(mozilla::detail::BaseAutoLock<mozilla::Mutex&> const&)|git:github.com/mozilla-firefox/firefox:xpcom/threads/TaskController.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1360|0x5b4
0|40|libxul.so|mozilla::TaskController::ExecuteNextTaskOnlyMainThreadInternal(mozilla::detail::BaseAutoLock<mozilla::Mutex&> const&)|git:github.com/mozilla-firefox/firefox:xpcom/threads/TaskController.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1183|0x57
0|41|libxul.so|mozilla::TaskController::ProcessPendingMTTask(bool)|git:github.com/mozilla-firefox/firefox:xpcom/threads/TaskController.cpp:9631bc624c432f094ca05c276e5a5c922407859f|657|0x65
0|42|libxul.so|mozilla::detail::RunnableFunction<mozilla::TaskController::TaskController()::$_0>::Run()|git:github.com/mozilla-firefox/firefox:xpcom/threads/nsThreadUtils.h:9631bc624c432f094ca05c276e5a5c922407859f|535|0x16
0|43|libxul.so|nsThread::ProcessNextEvent(bool, bool*)|git:github.com/mozilla-firefox/firefox:xpcom/threads/nsThread.cpp:9631bc624c432f094ca05c276e5a5c922407859f|1180|0x5ca
0|44|libxul.so|NS_ProcessNextEvent(nsIThread*, bool)|git:github.com/mozilla-firefox/firefox:xpcom/threads/nsThreadUtils.cpp:9631bc624c432f094ca05c276e5a5c922407859f|471|0x4f
0|45|libxul.so|mozilla::ipc::MessagePump::Run(base::MessagePump::Delegate*)|git:github.com/mozilla-firefox/firefox:ipc/glue/MessagePump.cpp:9631bc624c432f094ca05c276e5a5c922407859f|83|0xc0
0|46|libxul.so|MessageLoop::Run()|git:github.com/mozilla-firefox/firefox:ipc/chromium/src/base/message_loop.cc:9631bc624c432f094ca05c276e5a5c922407859f|346|0x61
0|47|libxul.so|nsBaseAppShell::Run()|git:github.com/mozilla-firefox/firefox:widget/nsBaseAppShell.cpp:9631bc624c432f094ca05c276e5a5c922407859f|151|0x28
0|48|libxul.so|nsAppShell::Run()|git:github.com/mozilla-firefox/firefox:widget/gtk/nsAppShell.cpp:9631bc624c432f094ca05c276e5a5c922407859f|580|0x114
0|49|libxul.so|XRE_RunAppShell()|git:github.com/mozilla-firefox/firefox:toolkit/xre/nsEmbedFunctions.cpp:9631bc624c432f094ca05c276e5a5c922407859f|652|0x6b
0|50|libxul.so|mozilla::ipc::MessagePumpForChildProcess::Run(base::MessagePump::Delegate*)|git:github.com/mozilla-firefox/firefox:ipc/glue/MessagePump.cpp:9631bc624c432f094ca05c276e5a5c922407859f|233|0x3c
0|51|libxul.so|MessageLoop::Run()|git:github.com/mozilla-firefox/firefox:ipc/chromium/src/base/message_loop.cc:9631bc624c432f094ca05c276e5a5c922407859f|346|0x61
0|52|libxul.so|XRE_InitChildProcess(int, char**, XREChildData const*)|git:github.com/mozilla-firefox/firefox:toolkit/xre/nsEmbedFunctions.cpp:9631bc624c432f094ca05c276e5a5c922407859f|590|0x994
0|53|firefox-bin|main|git:github.com/mozilla-firefox/firefox:browser/app/nsBrowserApp.cpp:9631bc624c432f094ca05c276e5a5c922407859f|467|0x21c

@Boris: This looks like it's coming from view transitions code. Can you take a look?

Flags: needinfo?(boris.chiou)

Adding dependency on the bug that added the assertion in question.

The assertion is here:
https://searchfox.org/firefox-main/rev/6cee80f87168d5aabd9e343099e2a8e5535e5320/layout/style/GeckoBindings.cpp#800-801

nsAtom* name = Gecko_GetImplementedPseudoIdentifier(aElement);
MOZ_ASSERT(name);

It looks like Gecko_GetImplementedPseudoIdentifier does have a few early-returns that return nullptr, so presumably we're hitting one of those.

Triaging as S3 given that we appear to handle this issue gracefully in release builds (we proceed to call vt->MatchClassList(name, *aPtNameAndClassSelector); which looks up name in a hashtable and returns false if it's not found.

Severity: -- → S3
Depends on: 1964949

Assign to myself. It seems we just need to add the error handling (and I missed some cases when adding this function)

Assignee: nobody → boris.chiou
Flags: needinfo?(boris.chiou)
You need to log in before you can comment on or make changes to this bug.