Crash [@ nsListBoxBodyFrame::GetAvailableHeight] with fake listboxbody

RESOLVED FIXED

Status

()

defect
--
critical
RESOLVED FIXED
12 years ago
8 years ago

People

(Reporter: jruderman, Assigned: smaug)

Tracking

(Blocks 2 bugs, {crash, testcase})

Trunk
x86
macOS
Points:
---
Dependency tree / graph
Bug Flags:
in-testsuite +

Firefox Tracking Flags

(Not tracked)

Details

(crash signature)

Attachments

(2 attachments)

Reporter

Description

12 years ago
Loading the testcase crashes Firefox.
Reporter

Comment 1

12 years ago
The frame constructor checks for a tag name "listboxbody" without checking for a XUL namespace:

http://bonsai.mozilla.org/cvsblame.cgi?file=mozilla/layout/base/nsCSSFrameConstructor.cpp&rev=1.1402#5959

Is that the only problem, or would there still be a way to crash if that were fixed?
That would still be a problem.  You could have "naked" XUL listboxbody like this and it would crash.  You could stick it in a grid with unscrollable overflow, and it would crash.  Etc, etc.

nsListBoxBodyFrame::GetAvailableHeight needs to null-check the return value of nsLayoutUtils::GetScrollableFrameFor like the other callers in that file, imo.
Flags: blocking1.9?
Reporter

Updated

12 years ago
Severity: normal → critical
Assignee

Comment 3

12 years ago
Like this. Handling namespaces properly in CSSFC is a different bug.
I noticed there are several cases where namespace should be checked but
it isn't.
Attachment #282096 - Flags: superreview?(bzbarsky)
Attachment #282096 - Flags: review?(bzbarsky)
Attachment #282096 - Flags: superreview?(bzbarsky)
Attachment #282096 - Flags: superreview+
Attachment #282096 - Flags: review?(bzbarsky)
Attachment #282096 - Flags: review+
Assignee

Updated

12 years ago
Attachment #282096 - Flags: approval1.9?
Assignee

Updated

12 years ago
Assignee: nobody → Olli.Pettay
Assignee

Updated

12 years ago
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → FIXED
Assignee

Updated

12 years ago
Flags: blocking1.9?
Reporter

Comment 4

12 years ago
Crashtest checked in.
Flags: in-testsuite+

Updated

11 years ago
Component: XP Toolkit/Widgets: XUL → XUL
QA Contact: xptoolkit.xul → xptoolkit.widgets
Crash Signature: [@ nsListBoxBodyFrame::GetAvailableHeight]
You need to log in before you can comment on or make changes to this bug.