User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.6a) Gecko/20031020 Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.6a) Gecko/20031020 Whenever I load www.vnunet.com mozilla either crashes or locks-up. If it locks-up browser is still responsive, but clicking on any link does nothing and new windows can not be opened. It happens with todays build (2003102004) and the site was working fine few days ago. Reproducible: Always Steps to Reproduce: 1. Visit www.vnunet.com 2. 3. Actual Results: Browser crashes or locks up Expected Results: Load the page. Talkback ID: TB24607740Y
crash for me to on XPProf. Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.6a) Gecko/20031020 Firebird/0.7+
No dupes found, marking NEW. Can you attach full stack (using 'backtrace' when in GDB and Mozilla has crashed) via "create a new attachment" ?
Seems to be okay with 1.5 (Win2k)
Created attachment 133754 [details] Stack trace Here's the stack trace you requested. BTW, only gtk2 version is affected.
I just had a crash using Trunk BuildID 2003102004. DocWatson came up, but there was no talkback in the sea.exe-package. Stack summary of DocWatson was showing 37 calls to GKLAYOUT.DLL and one call to XPCOM, no others. WFM Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.5) Gecko/20031007 WFM Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.5) Gecko/20031007 Firebird/0.7 Didn´t find Flash on this page.
Checked this out on recent nightlies on WIN XP... 20031017 : no crash 20031018 and later: crash
Charles, great info, can you even reduce more by mentioning the build ID (like "2003101705") in the title bar ?
Oliver: 2003101704 and 2003101804 Looking at CVS checkins, BZ touched mozilla/ layout/ html/ base/ src/ nsHTMLReflowState.cpp a few times during that time period.
TB24618351G Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.6a) Gecko/20031019
Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.6a) Gecko/20031018 BuildID 2003101804 TB24618983G crash on loading URL TB24618895X crash on loading local copy of URL saved with BuildID 2003101704 tested Build ID2003101704 only once, to save the page, no crash all later builds are crashing, some don´t have talkback, though I selected complete install (SEA.EXE).
bz, see comments in bug 223017 isolating this to recent nsHTMLReflowState.cpp checkins.
*** Bug 223171 has been marked as a duplicate of this bug. ***
Rolling back nsHTMLReflowState.cpp to -r1.174 makes the crash disappear so the culprit is the checkin for bug 94468. I think the real problem is in the frame splitting code in nsCSSFrameConstructor.cpp though, it has a lot of concerned comments  about not handling abs.pos. blocks (and floats) correctly. I think this could lead to the situation where the placeholder has a different parent than the block where the frame is on the abs.pos. list. (So the assertion on line 870 triggers and we will dereference null on line 872).  e.g. read XXX_kin comments in AdjustOutOfFlowFrameParentPtrs()
Created attachment 133807 [details] [diff] [review] Patch rev. 1 This fixes the crash without regressing bug 94468.
Comment on attachment 133807 [details] [diff] [review] Patch rev. 1 r+sr=bzbarsky. This even leads to correct positioning of positioned blocks-inside-inlines, since they have to start a new line normally and since the placeholder remains in the first line.
I just checked this in, and the tree was even still open for 1.6a. ;) Mats, thanks a ton for debugging this and for the patch!
*** Bug 223070 has been marked as a duplicate of this bug. ***
I just wanted to comment that this bug report is impressive in the way it features: - crash report with an URL and Talkback ID, - fix in less than 24hr, - reduced testcase, - stacks and verification on multiple OS, - regression window, - debugging explanation in comment 15, - and, of course, the patch, from someone else than where the regression came from, - teamwork: all of these were provided by different people, PS: Sorry for the spam, let's not start a discussion here, I simply wanted to express my happy feelings on bugzilla today :)
Crashtest added as part of http://hg.mozilla.org/mozilla-central/rev/afc662d52ab1