Closed Bug 429585 Opened 18 years ago Closed 17 years ago

Crash [@ XPCNativeInterface::GetName] or [@ XPCNativeScriptableInfo::~XPCNativeScriptableInfo]

Categories

(Core :: XPConnect, defect)

x86
macOS
defect
Not set
critical

Tracking

()

RESOLVED WORKSFORME

People

(Reporter: gkw, Unassigned)

Details

(Keywords: crash, testcase, Whiteboard: [sg:critical?])

Crash Data

Attachments

(9 files)

Attached file stacktrace 1
I found this bug using Jesse's DOM fuzzer, and he is working on a reduced testcase because this crash is highly unreproducible and fairly inconsistent. The first type of crash stacktraces occur on yesterday's compiled debug Firefox trunk on the Mac, while the second and third types started occurring on today's build. Will be attaching 2 stacktraces of each type of crashes.
Attachment #316319 - Attachment mime type: application/octet-stream → text/plain
Flags: blocking1.9?
Keywords: testcase
Whiteboard: [sg:critical]
This testcase does not demonstrate a crash, but just a strange exception. (It also explains why the subsequent testcases use setTimeout.) document.getElementById somehow manages to throw NS_ERROR_FILE_NOT_FOUND.
(Only when the testcase is local, I guess.)
With MallocScribble enabled, this testcase always triggers a crash [@ XPCNativeInterface::GetName]. Without MallocScribble, it usually doesn't crash.
This crashes if you quit after loading it. It can crash even without MallocScribble.
Wouldn't hold back the release for this. Please re-nom if you disagree.
Flags: wanted1.9.0.x+
Flags: blocking1.9?
Flags: blocking1.9-
I can not get the "immediate crash" testcase to crash, even with MallocScribble turned on. Please reopen if you can.
Status: NEW → RESOLVED
Closed: 18 years ago
Resolution: --- → WORKSFORME
Still crashes for me. Note that it must be local in order to request the privileges needed to force a garbage collection.
Status: RESOLVED → REOPENED
Resolution: WORKSFORME → ---
Adding sayrer to help get this scheduled.
Whiteboard: [sg:critical] → [sg:critical?]
Comment on attachment 316337 [details] testcase 1: immediate crash [@ XPCNativeInterface::GetName] Can't reproduce on OSX with MallocScribble using a trunk build.
Comment on attachment 316338 [details] testcase 2: shutdown crash [@ XPCNativeScriptableInfo::~XPCNativeScriptableInfo] Can't reproduce this either.
WFM using TM branch (with mallocscribble and with JIT off to avoid bug 458857). I even tried the original testcase and the partially-reduced testcases I saved off while I was reducing it.
Status: REOPENED → RESOLVED
Closed: 18 years ago17 years ago
Resolution: --- → WORKSFORME
Flags: wanted1.9.0.x+ → wanted1.9.0.x?
Flags: in-testsuite?
Crash Signature: [@ XPCNativeInterface::GetName] [@ XPCNativeScriptableInfo::~XPCNativeScriptableInfo]
Group: core-security → core-security-release
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: