Closed Bug 356025 Opened 19 years ago Closed 16 years ago

crash when click view in 3-pane [@ nsXULTreeBuilder::RemoveMatchesFor]

Categories

(Core :: XUL, defect)

x86
Windows XP
defect
Not set
critical

Tracking

()

RESOLVED WORKSFORME

People

(Reporter: wsmwk, Unassigned)

Details

(Keywords: crash)

Crash Data

from TB24271221 3-pane, select a (local) saved search XXX from *folder* pane, search appeared fine, clicked folder DROP DOWN to pick a different view, i.e change from XXX to some other folder - it didn't execute (didn't supply a drop down list), clicked again, crash was not able to reproduce nsXULTreeBuilder::RemoveMatchesFor [mozilla/content/xul/templates/src/nsXULTreeBuilder.cpp, line 1738] nsXULTreeBuilder::CloseContainer [mozilla/content/xul/templates/src/nsXULTreeBuilder.cpp, line 1718] nsXULTreeBuilder::ToggleOpenState [mozilla/content/xul/templates/src/nsXULTreeBuilder.cpp, line 867] XPTC_InvokeByIndex [mozilla/xpcom/reflect/xptcall/src/md/win32/xptcinvoke.cpp, line 102] XPCWrappedNative::CallMethod [mozilla/js/src/xpconnect/src/xpcwrappednative.cpp, line 2162] XPC_WN_CallMethod [mozilla/js/src/xpconnect/src/xpcwrappednativejsops.cpp, line 1455] js_Invoke [mozilla/js/src/jsinterp.c, line 1373] js_Interpret [mozilla/js/src/jsinterp.c, line 4115] js_Invoke [mozilla/js/src/jsinterp.c, line 1392] js_InternalInvoke [mozilla/js/src/jsinterp.c, line 1467] JS_CallFunctionValue [mozilla/js/src/jsapi.c, line 4419] nsJSContext::CallEventHandler [mozilla/dom/src/base/nsJSEnvironment.cpp, line 1745] nsJSEventListener::HandleEvent [mozilla/dom/src/events/nsJSEventListener.cpp, line 214] nsXBLPrototypeHandler::ExecuteHandler [mozilla/content/xbl/src/nsXBLPrototypeHandler.cpp, line 511] nsXBLEventHandler::HandleEvent [mozilla/content/xbl/src/nsXBLEventHandler.cpp, line 86] nsEventListenerManager::HandleEventSubType [mozilla/content/events/src/nsEventListenerManager.cpp, line 1646] nsEventListenerManager::HandleEvent [mozilla/content/events/src/nsEventListenerManager.cpp, line 1750] nsEventTargetChainItem::HandleEvent [mozilla/content/events/src/nsEventDispatcher.cpp, line 356] nsEventTargetChainItem::HandleEventTargetChain [mozilla/content/events/src/nsEventDispatcher.cpp, line 433] nsEventDispatcher::Dispatch [mozilla/content/events/src/nsEventDispatcher.cpp, line 643] PresShell::HandleDOMEventWithTarget [mozilla/layout/base/nsPresShell.cpp, line 6306] nsMenuFrame::OnCreate [mozilla/layout/xul/base/src/nsMenuFrame.cpp, line 1743] nsMenuFrame::OpenMenuInternal [mozilla/layout/xul/base/src/nsMenuFrame.cpp, line 801] nsMenuFrame::OpenMenu [mozilla/layout/xul/base/src/nsMenuFrame.cpp, line 785] nsMenuFrame::ToggleMenuState [mozilla/layout/xul/base/src/nsMenuFrame.cpp, line 555] nsMenuFrame::HandleEvent [mozilla/layout/xul/base/src/nsMenuFrame.cpp, line 430] nsPresShellEventCB::HandleEvent [mozilla/layout/base/nsPresShell.cpp, line 1505] nsEventDispatcher::Dispatch [mozilla/content/events/src/nsEventDispatcher.cpp, line 643] PresShell::HandleEventInternal [mozilla/layout/base/nsPresShell.cpp, line 6263] PresShell::HandlePositionedEvent [mozilla/layout/base/nsPresShell.cpp, line 6138] PresShell::HandleEvent [mozilla/layout/base/nsPresShell.cpp, line 5966] nsViewManager::HandleEvent [mozilla/view/src/nsViewManager.cpp, line 1668] nsViewManager::DispatchEvent [mozilla/view/src/nsViewManager.cpp, line 1621] HandleEvent [mozilla/view/src/nsView.cpp, line 174] nsWindow::DispatchEvent [mozilla/widget/src/windows/nsWindow.cpp, line 1108] nsWindow::DispatchMouseEvent [mozilla/widget/src/windows/nsWindow.cpp, line 6110] ChildWindow::DispatchMouseEvent [mozilla/widget/src/windows/nsWindow.cpp, line 6292] nsWindow::WindowProc [mozilla/widget/src/windows/nsWindow.cpp, line 1297] USER32.dll + 0x8734 (0x77d48734) USER32.dll + 0x8816 (0x77d48816) USER32.dll + 0x89cd (0x77d489cd) USER32.dll + 0x8a10 (0x77d48a10) nsAppShell::ProcessNextNativeEvent [mozilla/widget/src/windows/nsAppShell.cpp, line 154] nsBaseAppShell::DoProcessNextNativeEvent [mozilla/widget/src/xpwidgets/nsBaseAppShell.cpp, line 137] 0xc0850845
Assignee: mscott → nobody
Component: Mail Window Front End → XP Toolkit/Widgets: XUL
Product: Thunderbird → Core
QA Contact: front-end → xptoolkit.xul
Summary: click view in 3-pane [@ nsXULTreeBuilder::RemoveMatchesFor] → crash when click view in 3-pane [@ nsXULTreeBuilder::RemoveMatchesFor]
Might be a crash caused by 330776. If it is the same cause, there's a patch there that would fix this.
Neil in comment #1 > Might be a crash caused by 330776. If it is the same cause, there's a patch > there that would fix this. Neil, bug 330776 is marked linux. Is there a testcase for windows? Does patch need review before SR?
confirming based on more recent crashers, although I have not seen it since my first and only crash recent crashers and some examples all trunk, all windows (except TB26363667=linux which I have not listed here): TB29005300 MozillaOrgThunderbirdTrunkWin322007012803 TB28518454 MozillaOrgMozillaTrunkWin322006122608 TB28437895 MozillaOrgFirefoxTrunkWin322007011604 TB28370034 MozillaOrgFirefoxTrunkWin322007011404 TB28518454 (no idea who /nelson is to cc the bug) Stack Signature nsXULTreeBuilder::RemoveMatchesFor 7f2d5f67 Product ID MozillaTrunk Build ID 2006122608 Trigger Time 2007-01-19 12:51:45.0 Platform Win32 Operating System Windows NT 5.1 build 2600 Module gklayout.dll + (001b45ae) URL visited http://www.filmcritic.com/misc/emporium.nsf/2a460f93626cd4678625624c007f2b46/c86e3975ad708f0188257260006449c0?OpenDocument User Comments Did a search for messages in a mail folder for a POP3 account. Then tried to change the foldler being searched. boom. /Nelson Since Last Crash 260086 sec Total Uptime 986697 sec Trigger Reason Access violation Source File, Line No. d:\builds\tinderbox\seamonkeytrunk\winnt_5.2_clobber\mozilla\content\xul\templates\src\nsxultreebuilder.cpp, line 1738 Stack Trace nsXULTreeBuilder::RemoveMatchesFor [mozilla\content\xul\templates\src\nsxultreebuilder.cpp, line 1738] nsXULTreeBuilder::CloseContainer [mozilla\content\xul\templates\src\nsxultreebuilder.cpp, line 1718] 0x012b2230 kDOMSOF_CID nsBaseDOMException::AddRef [mozilla\dom\src\base\nsdomexception.cpp, line 214] 0x57560cec TB28370034 nsXULTreeBuilder::RemoveMatchesFor [mozilla\content\xul\templates\src\nsxultreebuilder.cpp, line 1737] nsXULTreeBuilder::CloseContainer [mozilla\content\xul\templates\src\nsxultreebuilder.cpp, line 1717] 0x01b8ac80 kDOMSOF_CID nsDOMStyleSheetList::AddRef [mozilla\content\base\src\nsdocument.cpp, line 344] 0x57560cec TB27889579 nsxultreebuilder.cpp, line 1738 nsXULTreeBuilder::RemoveMatchesFor nsXULTreeBuilder::CloseContainer InMemoryDataSource::Unassert kDOMSOF_CID TB27636649 nsxultreebuilder.cpp, line 1738 nsXULTreeBuilder::RemoveMatchesFor nsXULTreeBuilder::CloseContainer 0x01a1e208 kDOMSOF_CID nsDetectionAdaptor::AddRef 0x57560cec TB26364962 nsxultreebuilder.cpp, line 1738 Stack Trace nsXULTreeBuilder::RemoveMatchesFor [mozilla\content\xul\templates\src\nsxultreebuilder.cpp, line 1738] nsXULTreeBuilder::CloseContainer [mozilla\content\xul\templates\src\nsxultreebuilder.cpp, line 1718] nsCOMPtr_base::~nsCOMPtr_base [mozilla\xpcom\build\nscomptr.cpp, line 82] (perhaps unrelated) TB28058464 nsXULTreeBuilder::RemoveMatchesFor [mozilla\content\xul\templates\src\nsxultreebuilder.cpp, line 1737] nsXULTreeBuilder::CloseContainer [mozilla\content\xul\templates\src\nsxultreebuilder.cpp, line 1717] nsMsgDBFolder::SetFlag [mozilla\mailnews\base\util\nsmsgdbfolder.cpp, line 3771] nsTableFrame::RemoveFrame [mozilla\layout\tables\nstableframe.cpp, line 2463] 0x10e0835a 0x52c2940f 0x3435ff50 ... bug 330776, mentioned in comment 1 and presumably fixed by bug 367310 on 2007-01-30, seems not likely to be related. But if there are no further crashes of ::RemoveMatchesFor, perhaps? ... it will be shown to have been fixed.
Status: UNCONFIRMED → NEW
Ever confirmed: true
same problem, different steps? crash immediately after clicking OK to rename of subfolder. Had moved and deleted about a total of 10 folders prior to the crash. bp-82d93fe3-ee3f-11dc-8804-001a4bd43ef6 0 nsXULTreeBuilder::RemoveMatchesFor(nsTreeRows::Subtree&) mozilla/content/xul/templates/src/nsXULTreeBuilder.cpp:1736 1 nsXULTreeBuilder::CloseContainer(int) mozilla/content/xul/templates/src/nsXULTreeBuilder.cpp:1713 2 nsXULTreeBuilder::ToggleOpenState(int) mozilla/content/xul/templates/src/nsXULTreeBuilder.cpp:864 3 NS_InvokeByIndex_P mozilla/xpcom/reflect/xptcall/src/md/win32/xptcinvoke.cpp:101 4 XPCWrappedNative::CallMethod(XPCCallContext&, XPCWrappedNative::CallMode) mozilla/js/src/xpconnect/src/xpcwrappednative.cpp:2339 5 XPC_WN_CallMethod(JSContext*, JSObject*, unsigned int, long*, long*) mozilla/js/src/xpconnect/src/xpcwrappednativejsops.cpp:1470 only two crashes found on talkback! But, 15 plus mine on trunk.
Here's another, more like original report. - last click was select view drop down - it didn't show drop down. - second last click was folder change. nothing in between. had not edited any views, folders etc. Version 3.0a1pre Build ID 2008031202 bp-ad3bf32e-f1d9-11dc-8685-001a4bd43e5c 0 nsXULTreeBuilder::RemoveMatchesFor(nsTreeRows::Subtree&) mozilla/content/xul/templates/src/nsXULTreeBuilder.cpp:1736 1 nsXULTreeBuilder::CloseContainer(int) mozilla/content/xul/templates/src/nsXULTreeBuilder.cpp:1713 2 nsXULTreeBuilder::ToggleOpenState(int) mozilla/content/xul/templates/src/nsXULTreeBuilder.cpp:864 3 NS_InvokeByIndex_P mozilla/xpcom/reflect/xptcall/src/md/win32/xptcinvoke.cpp:101 4 XPCWrappedNative::CallMethod(XPCCallContext&, XPCWrappedNative::CallMode) mozilla/js/src/xpconnect/src/xpcwrappednative.cpp:2369 5 XPC_WN_CallMethod(JSContext*, JSObject*, unsigned int, long*, long*) mozilla/js/src/xpconnect/src/xpcwrappednativejsops.cpp:1470
Component: XP Toolkit/Widgets: XUL → XUL
QA Contact: xptoolkit.xul → xptoolkit.widgets
I can consistently get this by dragging and dropping a folder between two folder panes, see: 52f14297-1684-4d8c-95a7-e79252090127 d0abb47f-ba29-46ed-bf80-be7062090127 66df0c42-695f-45ff-a932-8d2642090127 815e0e83-4e8c-46a8-9acd-3056a2090127 5ab441e6-e8ba-44d3-9e16-432f12090127 ea0d659f-ac96-45d2-9086-af2702090127 268d34b9-4896-4392-8365-a95ac2090127
Ian Neal, can you describe that as a sequence of steps to reproduce? Preferably detailed enough that someone who isn't a Thunderbird user would be able to follow?
(In reply to comment #7) > Ian Neal, can you describe that as a sequence of steps to reproduce? > Preferably detailed enough that someone who isn't a Thunderbird user would be > able to follow? Well, just tried with a recently nightly and I don't seem to be getting it on my home PC. I will try at work too, see if that crashes or not.
Ian, did you get a chance to try this on your work box?
Status: NEW → RESOLVED
Closed: 16 years ago
Resolution: --- → WORKSFORME
Ian, are you still unable to reproduce this? a full signature currently reported by crash-status may be nsXULTreeBuilder::RemoveMatchesFor(nsTreeRows::Subtree&), which occurs in some numbers for SM 2.0, and a little for firefox. I can't pull up any of the crashes of comment 6. Will do a more research before deciding whether to file a new bug or reopen this one FF http://crash-stats.mozilla.com/report/index/9b67cbd6-8fc9-4aa5-8aac-703262091008 SM http://crash-stats.mozilla.com/report/index/fa3ec6cf-a540-4eef-a024-cc8642091118
I do keep trying but have not succeeded, as yet, in reproducing it.
(In reply to comment #11) > I do keep trying but have not succeeded, as yet, in reproducing it. Note, this is trying to reproduce using folder drag and drop in a mail window, not using a browser window / bookmark manager / etc.
Crash Signature: [@ nsXULTreeBuilder::RemoveMatchesFor]
You need to log in before you can comment on or make changes to this bug.