Crash in [@ nsBlockFrame::RemoveFrame]
Categories
(Core :: Layout: Block and Inline, defect)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox-esr115 | --- | unaffected |
| firefox-esr140 | --- | unaffected |
| firefox-esr153 | --- | unaffected |
| firefox154 | --- | verified |
| firefox155 | --- | verified |
| firefox156 | --- | verified |
People
(Reporter: aryx, Assigned: emilio)
References
(Regression, )
Details
(Keywords: crash, regression)
Crash Data
Attachments
(5 files)
|
353 bytes,
text/html
|
Details | |
|
[mozilla-firefox/firefox] Bug 2065136 - SVG text shouldn't allow generated content. r=#layout (#342)
51 bytes,
text/x-github-pull-request
|
Details | Review | |
|
48 bytes,
text/x-phabricator-request
|
phab-bot
:
approval-mozilla-beta+
|
Details | Review |
|
48 bytes,
text/x-phabricator-request
|
phab-bot
:
approval-mozilla-release+
|
Details | Review |
|
7.45 MB,
video/mp4
|
Details |
63 crashes from 35 installs for Firefox 154.0. Isolated crash instances for older versions.
Reproducible with https://hackthepromise.org/ here
Crash report: https://crash-stats.mozilla.org/report/index/7da1c1b2-af5c-4988-ad4f-88b0d0260820
MOZ_CRASH Reason:
MOZ_CRASH(unexpected child list)
Top 10 frames:
0 xul.dll nsBlockFrame::RemoveFrame(mozilla::FrameDestroyContext&, mozilla::FrameChildL... layout/generic/nsBlockFrame.cpp:6737
1 xul.dll nsFrameManager::RemoveFrame(mozilla::FrameDestroyContext&, mozilla::FrameChil... layout/base/nsFrameManager.cpp:118
1 xul.dll nsPlaceholderFrame::Destroy(mozilla::FrameDestroyContext&) layout/generic/nsPlaceholderFrame.cpp:160
2 xul.dll nsLineBox::DeleteLineList(nsPresContext*, nsLineList&, nsFrameList*, mozilla:... layout/generic/nsLineBox.cpp:390
2 xul.dll nsBlockFrame::Destroy(mozilla::FrameDestroyContext&) layout/generic/nsBlockFrame.cpp:451
3 xul.dll nsFrameList::DestroyFrames(mozilla::FrameDestroyContext&) layout/generic/nsFrameList.cpp:33
3 xul.dll nsContainerFrame::Destroy(mozilla::FrameDestroyContext&) layout/generic/nsContainerFrame.cpp:194
4 xul.dll nsFrameList::DestroyFrames(mozilla::FrameDestroyContext&) layout/generic/nsFrameList.cpp:33
4 xul.dll nsContainerFrame::Destroy(mozilla::FrameDestroyContext&) layout/generic/nsContainerFrame.cpp:194
5 xul.dll nsFrameList::DestroyFrames(mozilla::FrameDestroyContext&) layout/generic/nsFrameList.cpp:33
Updated•1 month ago
|
Updated•1 month ago
|
Comment 1•1 month ago
|
||
With debug build, I get an assert failure:
[21297] Assertion failure: aNewFrame->GetParent() == outOfFlowFrameList->mContainingBlock (Parent of the frame is not the containing block?), at layout/base/nsCSSFrameConstructor.cpp:1078
I see that the frame tree looks like so:
Viewport(-1)@7f8641ac6020 (x=0, y=0, w=0, h=0)[cs=7f863fa10308][MozViewport] <
ScrollContainer(html)(-1)@7f8641ac6198 parent=7f8641ac6020 (x=0, y=0, w=0, h=0) [content=7f8641907070][cs=7f863fa23908][MozViewportScroll] <
ScrollbarFrame(scrollbar)(-1)@7f8641ac6430 parent=7f8641ac6198 next=7f8641ac66b0 (x=0, y=0, w=0, h=0) [content=7f864193f3d0][cs=7f863fa23d08] <
SliderFrame(slider)(-1)@7f8641ac6538 parent=7f8641ac6430 (x=0, y=0, w=0, h=0) [content=7f864193f580][cs=7f863fa24008] <
Frame(thumb)(0)@7f8641ac6638 parent=7f8641ac6538 (x=0, y=0, w=0, h=0) [content=7f86419272d0][cs=7f863fa24108]
>
>
ScrollbarFrame(scrollbar)(-1)@7f8641ac66b0 parent=7f8641ac6198 next=7f8641ac6930 (x=0, y=0, w=0, h=0) [content=7f864193f460][cs=7f863fa23e08] <
SliderFrame(slider)(-1)@7f8641ac67b8 parent=7f8641ac66b0 (x=0, y=0, w=0, h=0) [content=7f864193f610][cs=7f863fa24208] <
Frame(thumb)(0)@7f8641ac68b8 parent=7f8641ac67b8 (x=0, y=0, w=0, h=0) [content=7f8641927380][cs=7f863fa24308]
>
>
Frame(scrollcorner)(-1)@7f8641ac6930 parent=7f8641ac6198 next=7f8641ac60d0 (x=0, y=0, w=0, h=0) [content=7f864193f4f0][cs=7f863fa23f08]
Canvas(html)(-1)@7f8641ac60d0 parent=7f8641ac6198 (x=0, y=0, w=0, h=0) [content=7f8641907070][cs=7f863fa23b08][MozScrolledContent] <
Block(html)(-1)@7f8641ac69a8 parent=7f8641ac60d0 (x=0, y=0, w=0, h=0) [content=7f8641907070][cs=7f863fa23a08] <
line@7f8641ac6b38 count=1 state=block,dirty,prevmarginclean,not-impacted,not-wrapped,no-break,no-trim-start,no-trim-end,clear-before:none,clear-after:none (x=0, y=0, w=0, h=0) <
Block(body id=htp_wp)(2)@7f8641ac6a70 parent=7f8641ac69a8 (x=0, y=0, w=0, h=0) [content=7f864193f340][cs=7f863fa23c08] <
>
>
>
>
>
>
... Which doesn't include frames mentioned in the assertion.
(gdb) print aNewFrame->GetParent()
$9 = (nsBlockFrame *) 0x7f863f723008
(gdb) print aNewFrame->GetParent()->GetParent()
$10 = (mozilla::SVGTextFrame *) 0x7f863f722e28
(gdb) print aNewFrame->GetParent()->GetParent()->GetParent()
$11 = (mozilla::SVGGFrame *) 0x7f863f722468
(gdb) print aNewFrame->GetParent()->GetParent()->GetParent()->GetParent()
$12 = (mozilla::SVGOuterSVGAnonChildFrame *) 0x7f8641ac7b80
(gdb) print aNewFrame->GetParent()->GetParent()->GetParent()->GetParent()->GetParent()
$13 = (mozilla::SVGOuterSVGFrame *) 0x7f8641ac7ab0
(gdb) print aNewFrame->GetParent()->GetParent()->GetParent()->GetParent()->GetParent()->GetParent()
$14 = (mozilla::ViewportFrame *) 0x7f8641ac6020
(gdb) print aNewFrame->GetParent()->GetParent()->GetParent()->GetParent()->GetParent()->GetParent()->GetParent()
$15 = (nsContainerFrame *) 0x0
and
(gdb) print outOfFlowFrameList->mContainingBlock
$16 = (nsBlockFrame *) 0x7f8641ac70f8
(gdb) print outOfFlowFrameList->mContainingBlock->GetParent()
$17 = (mozilla::ViewportFrame *) 0x7f8641ac6020
(gdb) print outOfFlowFrameList->mContainingBlock->GetParent()->GetParent()
$18 = (nsContainerFrame *) 0x0
Comment 2•1 month ago
|
||
With debug run:
3:02.56 INFO: Narrowed integration regression window from [8964729b, 78cb997a] (4 builds) to [b1f04ff0, 78cb997a] (2 builds) (~1 steps left)
3:02.56 INFO: No more integration revisions, bisection finished.
3:02.56 INFO: Last good revision: b1f04ff01acbdcd570ccd3d29610298a53d682d9
3:02.56 INFO: First bad revision: 78cb997ae3fc6293e86bd7fd70bed27e09dd0eb1
3:02.56 INFO: Pushlog:
https://hg.mozilla.org/integration/autoland/pushloghtml?fromchange=b1f04ff01acbdcd570ccd3d29610298a53d682d9&tochange=78cb997ae3fc6293e86bd7fd70bed27e09dd0eb1
Comment 3•1 month ago
|
||
:emilio, since you are the author of the regressor, bug 1850539, could you take a look? Also, could you set the severity field?
For more information, please visit BugBot documentation.
| Assignee | ||
Comment 4•1 month ago
|
||
| Assignee | ||
Updated•1 month ago
|
Comment 5•1 month ago
|
||
Comment 7•1 month ago
|
||
| bugherder | ||
Updated•1 month ago
|
Comment 8•1 month ago
|
||
The patch landed in nightly and beta is affected.
:emilio, is this bug important enough to require an uplift?
- If yes, please nominate the patch for beta approval.
- See https://wiki.mozilla.org/Release_Management/Requesting_an_Uplift for documentation on how to request an uplift.
- If no, please set
status-firefox155towontfix.
For more information, please visit BugBot documentation.
| Assignee | ||
Comment 9•1 month ago
|
||
Restores pre-regression and interoperable behavior.
Pull request: https://github.com/mozilla-firefox/firefox/pull/342
Updated•1 month ago
|
Comment 10•1 month ago
|
||
firefox-beta Uplift Approval Request
- User impact if declined/Reason for urgency: Crash
- Code covered by automated testing?: yes
- Fix verified in Nightly?: yes
- Needs manual QE testing?: yes
- Steps to reproduce for manual QE testing: comment 0
- Risk associated with taking this patch: low
- Explanation of risk level: Targeted one-liner
- String changes made/needed?: none
- Is Android affected?: yes
| Assignee | ||
Comment 11•1 month ago
|
||
Restores pre-regression and interoperable behavior.
Pull request: https://github.com/mozilla-firefox/firefox/pull/342
Updated•1 month ago
|
Comment 12•1 month ago
|
||
firefox-release Uplift Approval Request
- User impact if declined/Reason for urgency: Crash
- Code covered by automated testing?: yes
- Fix verified in Nightly?: yes
- Needs manual QE testing?: yes
- Steps to reproduce for manual QE testing: comment 0
- Risk associated with taking this patch: low
- Explanation of risk level: targeted one-liner
- String changes made/needed?: none
- Is Android affected?: yes
| Assignee | ||
Updated•1 month ago
|
Updated•1 month ago
|
Updated•1 month ago
|
Updated•1 month ago
|
Comment 13•1 month ago
|
||
| uplift | ||
Created web-platform-tests PR https://github.com/web-platform-tests/wpt/pull/62116 for changes under testing/web-platform/tests
Upstream PR merged by moz-wptsync-bot
Updated•1 month ago
|
Updated•1 month ago
|
Comment 16•1 month ago
|
||
| uplift | ||
Comment 17•1 month ago
|
||
This issue is verified as fixed on Firefox for Android Nightly 156 (2026-08-23) on Samsung S24 Ultra (Android 16) and Google Pixel 10 Pro (Android 16). The crash is no longer reproducible when refreshing the https://hackthepromise.org/ page.
Leaving the qe-verify+ fag for FX 155 and 154 verification.
Updated•1 month ago
|
Updated•1 month ago
|
Comment 18•1 month ago
|
||
I was able to reproduce the crash (MOZ_CRASH(unexpected child list)) on Win11x64 using Firefox 154.0 and https://hackthepromise.org/
Verified as fixed on Win11x64/Ubuntu 24.004 using Firefox desktop application 156.0a1(20260823213825).
Pending verification on next beta and 154.
Comment 19•1 month ago
•
|
||
Verified as fixed on Win11x64/Ubuntu 24.004/Mac 15.5 using Firefox desktop application 154.0.1 and 155.0b4.
Leaving the qe-verify+ fag for mobile team to verify.
Description
•