Closed Bug 2065136 Opened 1 month ago Closed 1 month ago

Crash in [@ nsBlockFrame::RemoveFrame]

Categories

(Core :: Layout: Block and Inline, defect)

Unspecified
Windows 11
defect

Tracking

()

RESOLVED FIXED
156 Branch
Tracking Status
firefox-esr115 --- unaffected
firefox-esr140 --- unaffected
firefox-esr153 --- unaffected
firefox154 --- verified
firefox155 --- verified
firefox156 --- verified

People

(Reporter: aryx, Assigned: emilio)

References

(Regression, )

Details

(Keywords: crash, regression)

Crash Data

Attachments

(5 files)

63 crashes from 35 installs for Firefox 154.0. Isolated crash instances for older versions.

Reproducible with https://hackthepromise.org/ here

Crash report: https://crash-stats.mozilla.org/report/index/7da1c1b2-af5c-4988-ad4f-88b0d0260820

MOZ_CRASH Reason:

MOZ_CRASH(unexpected child list)

Top 10 frames:

0  xul.dll  nsBlockFrame::RemoveFrame(mozilla::FrameDestroyContext&, mozilla::FrameChildL...  layout/generic/nsBlockFrame.cpp:6737
1  xul.dll  nsFrameManager::RemoveFrame(mozilla::FrameDestroyContext&, mozilla::FrameChil...  layout/base/nsFrameManager.cpp:118
1  xul.dll  nsPlaceholderFrame::Destroy(mozilla::FrameDestroyContext&)  layout/generic/nsPlaceholderFrame.cpp:160
2  xul.dll  nsLineBox::DeleteLineList(nsPresContext*, nsLineList&, nsFrameList*, mozilla:...  layout/generic/nsLineBox.cpp:390
2  xul.dll  nsBlockFrame::Destroy(mozilla::FrameDestroyContext&)  layout/generic/nsBlockFrame.cpp:451
3  xul.dll  nsFrameList::DestroyFrames(mozilla::FrameDestroyContext&)  layout/generic/nsFrameList.cpp:33
3  xul.dll  nsContainerFrame::Destroy(mozilla::FrameDestroyContext&)  layout/generic/nsContainerFrame.cpp:194
4  xul.dll  nsFrameList::DestroyFrames(mozilla::FrameDestroyContext&)  layout/generic/nsFrameList.cpp:33
4  xul.dll  nsContainerFrame::Destroy(mozilla::FrameDestroyContext&)  layout/generic/nsContainerFrame.cpp:194
5  xul.dll  nsFrameList::DestroyFrames(mozilla::FrameDestroyContext&)  layout/generic/nsFrameList.cpp:33
Flags: needinfo?(jfkthame)
Severity: -- → S4
Depends on: css-random
Severity: S4 → --
No longer depends on: css-random

With debug build, I get an assert failure:

[21297] Assertion failure: aNewFrame->GetParent() == outOfFlowFrameList->mContainingBlock (Parent of the frame is not the containing block?), at layout/base/nsCSSFrameConstructor.cpp:1078

I see that the frame tree looks like so:

Viewport(-1)@7f8641ac6020 (x=0, y=0, w=0, h=0)[cs=7f863fa10308][MozViewport] <
  ScrollContainer(html)(-1)@7f8641ac6198 parent=7f8641ac6020 (x=0, y=0, w=0, h=0) [content=7f8641907070][cs=7f863fa23908][MozViewportScroll] <
    ScrollbarFrame(scrollbar)(-1)@7f8641ac6430 parent=7f8641ac6198 next=7f8641ac66b0 (x=0, y=0, w=0, h=0) [content=7f864193f3d0][cs=7f863fa23d08] <
      SliderFrame(slider)(-1)@7f8641ac6538 parent=7f8641ac6430 (x=0, y=0, w=0, h=0) [content=7f864193f580][cs=7f863fa24008] <
        Frame(thumb)(0)@7f8641ac6638 parent=7f8641ac6538 (x=0, y=0, w=0, h=0) [content=7f86419272d0][cs=7f863fa24108]
      >
    >
    ScrollbarFrame(scrollbar)(-1)@7f8641ac66b0 parent=7f8641ac6198 next=7f8641ac6930 (x=0, y=0, w=0, h=0) [content=7f864193f460][cs=7f863fa23e08] <
      SliderFrame(slider)(-1)@7f8641ac67b8 parent=7f8641ac66b0 (x=0, y=0, w=0, h=0) [content=7f864193f610][cs=7f863fa24208] <
        Frame(thumb)(0)@7f8641ac68b8 parent=7f8641ac67b8 (x=0, y=0, w=0, h=0) [content=7f8641927380][cs=7f863fa24308]
      >
    >
    Frame(scrollcorner)(-1)@7f8641ac6930 parent=7f8641ac6198 next=7f8641ac60d0 (x=0, y=0, w=0, h=0) [content=7f864193f4f0][cs=7f863fa23f08]
    Canvas(html)(-1)@7f8641ac60d0 parent=7f8641ac6198 (x=0, y=0, w=0, h=0) [content=7f8641907070][cs=7f863fa23b08][MozScrolledContent] <
      Block(html)(-1)@7f8641ac69a8 parent=7f8641ac60d0 (x=0, y=0, w=0, h=0) [content=7f8641907070][cs=7f863fa23a08] <
        line@7f8641ac6b38 count=1 state=block,dirty,prevmarginclean,not-impacted,not-wrapped,no-break,no-trim-start,no-trim-end,clear-before:none,clear-after:none (x=0, y=0, w=0, h=0) <
          Block(body id=htp_wp)(2)@7f8641ac6a70 parent=7f8641ac69a8 (x=0, y=0, w=0, h=0) [content=7f864193f340][cs=7f863fa23c08] <
          >
        >
      >
    >
  >
>

... Which doesn't include frames mentioned in the assertion.

(gdb) print aNewFrame->GetParent()
$9 = (nsBlockFrame *) 0x7f863f723008
(gdb) print aNewFrame->GetParent()->GetParent()
$10 = (mozilla::SVGTextFrame *) 0x7f863f722e28
(gdb) print aNewFrame->GetParent()->GetParent()->GetParent()
$11 = (mozilla::SVGGFrame *) 0x7f863f722468
(gdb) print aNewFrame->GetParent()->GetParent()->GetParent()->GetParent()
$12 = (mozilla::SVGOuterSVGAnonChildFrame *) 0x7f8641ac7b80
(gdb) print aNewFrame->GetParent()->GetParent()->GetParent()->GetParent()->GetParent()
$13 = (mozilla::SVGOuterSVGFrame *) 0x7f8641ac7ab0
(gdb) print aNewFrame->GetParent()->GetParent()->GetParent()->GetParent()->GetParent()->GetParent()
$14 = (mozilla::ViewportFrame *) 0x7f8641ac6020
(gdb) print aNewFrame->GetParent()->GetParent()->GetParent()->GetParent()->GetParent()->GetParent()->GetParent()
$15 = (nsContainerFrame *) 0x0

and

(gdb) print  outOfFlowFrameList->mContainingBlock
$16 = (nsBlockFrame *) 0x7f8641ac70f8
(gdb) print  outOfFlowFrameList->mContainingBlock->GetParent()
$17 = (mozilla::ViewportFrame *) 0x7f8641ac6020
(gdb) print  outOfFlowFrameList->mContainingBlock->GetParent()->GetParent()
$18 = (nsContainerFrame *) 0x0
Flags: needinfo?(jfkthame)
Regressed by: 1850539

With debug run:

 3:02.56 INFO: Narrowed integration regression window from [8964729b, 78cb997a] (4 builds) to [b1f04ff0, 78cb997a] (2 builds) (~1 steps left)
 3:02.56 INFO: No more integration revisions, bisection finished.
 3:02.56 INFO: Last good revision: b1f04ff01acbdcd570ccd3d29610298a53d682d9
 3:02.56 INFO: First bad revision: 78cb997ae3fc6293e86bd7fd70bed27e09dd0eb1
 3:02.56 INFO: Pushlog:
https://hg.mozilla.org/integration/autoland/pushloghtml?fromchange=b1f04ff01acbdcd570ccd3d29610298a53d682d9&tochange=78cb997ae3fc6293e86bd7fd70bed27e09dd0eb1

:emilio, since you are the author of the regressor, bug 1850539, could you take a look? Also, could you set the severity field?

For more information, please visit BugBot documentation.

Flags: needinfo?(emilio)
Attached file Reduced test-case. —
Flags: needinfo?(emilio)
Status: NEW → RESOLVED
Closed: 1 month ago
Resolution: --- → FIXED
Target Milestone: --- → 156 Branch
Assignee: nobody → emilio

The patch landed in nightly and beta is affected.
:emilio, is this bug important enough to require an uplift?

For more information, please visit BugBot documentation.

Flags: needinfo?(emilio)

Restores pre-regression and interoperable behavior.

Pull request: https://github.com/mozilla-firefox/firefox/pull/342

Attachment #9629296 - Flags: approval-mozilla-beta?

firefox-beta Uplift Approval Request

  • User impact if declined/Reason for urgency: Crash
  • Code covered by automated testing?: yes
  • Fix verified in Nightly?: yes
  • Needs manual QE testing?: yes
  • Steps to reproduce for manual QE testing: comment 0
  • Risk associated with taking this patch: low
  • Explanation of risk level: Targeted one-liner
  • String changes made/needed?: none
  • Is Android affected?: yes
Flags: qe-verify+

Restores pre-regression and interoperable behavior.

Pull request: https://github.com/mozilla-firefox/firefox/pull/342

Attachment #9629297 - Flags: approval-mozilla-release?

firefox-release Uplift Approval Request

  • User impact if declined/Reason for urgency: Crash
  • Code covered by automated testing?: yes
  • Fix verified in Nightly?: yes
  • Needs manual QE testing?: yes
  • Steps to reproduce for manual QE testing: comment 0
  • Risk associated with taking this patch: low
  • Explanation of risk level: targeted one-liner
  • String changes made/needed?: none
  • Is Android affected?: yes
Flags: needinfo?(emilio)
Flags: in-testsuite+
Attachment #9629296 - Flags: approval-mozilla-beta? → approval-mozilla-beta+

Created web-platform-tests PR https://github.com/web-platform-tests/wpt/pull/62116 for changes under testing/web-platform/tests

Upstream PR merged by moz-wptsync-bot

Attachment #9629297 - Flags: approval-mozilla-release? → approval-mozilla-release+

This issue is verified as fixed on Firefox for Android Nightly 156 (2026-08-23) on Samsung S24 Ultra (Android 16) and Google Pixel 10 Pro (Android 16). The crash is no longer reproducible when refreshing the https://hackthepromise.org/ page.
Leaving the qe-verify+ fag for FX 155 and 154 verification.

QA Whiteboard: [uplift][qa-ver-needed-c156/b155]

I was able to reproduce the crash (MOZ_CRASH(unexpected child list)) on Win11x64 using Firefox 154.0 and https://hackthepromise.org/
Verified as fixed on Win11x64/Ubuntu 24.004 using Firefox desktop application 156.0a1(20260823213825).
Pending verification on next beta and 154.

QA Contact: mchiorean

Verified as fixed on Win11x64/Ubuntu 24.004/Mac 15.5 using Firefox desktop application 154.0.1 and 155.0b4.
Leaving the qe-verify+ fag for mobile team to verify.

QA Whiteboard: [uplift][qa-ver-needed-c156/b155] → [uplift][qa-ver-done-c156/b155]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: