Closed Bug 445372 Opened 18 years ago Closed 16 years ago

crash [@ nsCOMPtr_base::assign_with_AddRef]

Categories

(Thunderbird :: General, defect)

x86
Windows XP
defect
Not set
critical

Tracking

(Not tracked)

VERIFIED INVALID

People

(Reporter: wsmwk, Unassigned)

Details

(Keywords: crash)

Crash Data

crash [@ nsCOMPtr_base::assign_with_AddRef] from talkback lots of nsCOMPtr_base::assign_with_AddRef crashes, #34 in crash list. So might be topcrash but hard to say because quick spot check shows considerable variability in stacks. TB47554734 Stack Signature nsCOMPtr_base::assign_with_AddRef b543c9ed Product ID Thunderbird2 Build ID 2008042104 Trigger Time 2008-07-11 01:00:09.0 Platform Win32 Operating System Windows NT 5.1 build 2600 Module xpcom_core.dll + (0000180a) URL visited User Comments Since Last Crash 17 sec Total Uptime 98487 sec Trigger Reason Access violation Source File, Line No. e:/builds/tinderbox/Tb-Mozilla1.8-Release/WINNT_5.0_Depend/mozilla/xpcom/build/nsCOMPtr.cpp, line 89 Stack Trace nsCOMPtr_base::assign_with_AddRef [mozilla/xpcom/build/nsCOMPtr.cpp, line 89] nsBoxFrame::Destroy [mozilla/layout/xul/base/src/nsBoxFrame.cpp, line 1122] nsBoxFrame::Destroy [mozilla/layout/xul/base/src/nsBoxFrame.cpp, line 1122] nsBoxFrame::Destroy [mozilla/layout/xul/base/src/nsBoxFrame.cpp, line 1122] nsBoxFrame::Destroy [mozilla/layout/xul/base/src/nsBoxFrame.cpp, line 1122] nsBoxFrame::Destroy [mozilla/layout/xul/base/src/nsBoxFrame.cpp, line 1122] nsBoxFrame::Destroy [mozilla/layout/xul/base/src/nsBoxFrame.cpp, line 1122] nsBoxFrame::Destroy [mozilla/layout/xul/base/src/nsBoxFrame.cpp, line 1122] nsBoxFrame::Destroy [mozilla/layout/xul/base/src/nsBoxFrame.cpp, line 1122] ViewportFrame::Destroy [mozilla/layout/generic/nsViewportFrame.cpp, line 67] DocumentViewerImpl::Destroy [mozilla/layout/base/nsDocumentViewer.cpp, line 1559] nsDocShell::Destroy [mozilla/docshell/base/nsDocShell.cpp, line 3607] nsXULWindow::Destroy [mozilla/xpfe/appshell/src/nsXULWindow.cpp, line 514] nsWebShellWindow::Destroy [mozilla/xpfe/appshell/src/nsWebShellWindow.cpp, line 850] nsWebShellWindow::HandleEvent [mozilla/xpfe/appshell/src/nsWebShellWindow.cpp, line 408] nsWindow::DispatchEvent [mozilla/widget/src/windows/nsWindow.cpp, line 1319] TB47708070 Stack Signature nsCOMPtr_base::assign_with_AddRef 55b15b3e Product ID Thunderbird2 Build ID 2008042104 Trigger Time 2008-07-15 11:07:20.0 Platform Win32 Operating System Windows NT 5.1 build 2600 Module xpcom_core.dll + (0000180a) URL visited User Comments Since Last Crash 456 sec Total Uptime 111982 sec Trigger Reason Access violation Source File, Line No. e:/builds/tinderbox/Tb-Mozilla1.8-Release/WINNT_5.0_Depend/mozilla/xpcom/build/nsCOMPtr.cpp, line 89 Stack Trace nsCOMPtr_base::assign_with_AddRef [mozilla/xpcom/build/nsCOMPtr.cpp, line 89] nsBoxFrame::Destroy [mozilla/layout/xul/base/src/nsBoxFrame.cpp, line 1122] nsBoxFrame::Destroy [mozilla/layout/xul/base/src/nsBoxFrame.cpp, line 1122] nsBoxFrame::Destroy [mozilla/layout/xul/base/src/nsBoxFrame.cpp, line 1122] nsHTMLScrollFrame::Destroy [mozilla/layout/generic/nsGfxScrollFrame.cpp, line 172] ViewportFrame::Destroy [mozilla/layout/generic/nsViewportFrame.cpp, line 67] DocumentViewerImpl::Destroy [mozilla/layout/base/nsDocumentViewer.cpp, line 1559] nsDocShell::Destroy [mozilla/docshell/base/nsDocShell.cpp, line 3607] nsXULWindow::Destroy [mozilla/xpfe/appshell/src/nsXULWindow.cpp, line 514] nsWebShellWindow::Destroy [mozilla/xpfe/appshell/src/nsWebShellWindow.cpp, line 850] nsAppShellService::DestroyHiddenWindow [mozilla/xpfe/appshell/src/nsAppShellService.cpp, line 209] nsAppStartup::Observe [mozilla/toolkit/components/startup/src/nsAppStartup.cpp, line 527] nsObserverService::NotifyObservers [mozilla/xpcom/ds/nsObserverService.cpp, line 235] nsXULWindow::Destroy [mozilla/xpfe/appshell/src/nsXULWindow.cpp, line 556] nsWebShellWindow::Destroy [mozilla/xpfe/appshell/src/nsWebShellWindow.cpp, line 850] nsWebShellWindow::HandleEvent [mozilla/xpfe/appshell/src/nsWebShellWindow.cpp, line 408] nsWindow::DispatchEvent [mozilla/widget/src/windows/nsWindow.cpp, line 1319] nsWindow::DispatchStandardEvent [mozilla/widget/src/windows/nsWindow.cpp, line 1359] nsWindow::ProcessMessage [mozilla/widget/src/windows/nsWindow.cpp, line 4509] nsWindow::WindowProc [mozilla/widget/src/windows/nsWindow.cpp, line 1507] USER32.dll + 0x8734 (0x7e398734) USER32.dll + 0x8816 (0x7e398816) USER32.dll + 0xb4c0 (0x7e39b4c0) USER32.dll + 0xb50c (0x7e39b50c) ntdll.dll + 0xeae3 (0x7c91eae3) USER32.dll + 0xb3f9 (0x7e39b3f9) uxtheme.dll + 0x3c20 (0x5b093c20)
Wayne, sure this is crashing in TB code?
(In reply to comment #1) > Wayne, sure this is crashing in TB code? i'm guessing in some cases, yes. but given the variability of stacks hard to give more detail without looking at several. And many have only the top frame - so assuming some are bogus stacks. At the time I filed this, the frequency was such that it would be nice to get fixed. We don't know frequency now, because we don't have topcrash stats (bug 499926 and bug 495978) http://talkback-public.mozilla.org/search/start.jsp?search=1&searchby=stacksig&match=contains&searchfor=nsCOMPtr_base%3A%3Aassign_with_AddRef&vendor=MozillaOrg&product=Thunderbird2&platform=All&buildid=&sdate=&stime=&edate=&etime=&sortby=comment&rlimit=100 one frame both have comments TB54275082 TB54664072 TB54358192 opening attachment nsCOMPtr_base::assign_with_AddRef [mozilla/xpcom/build/nsCOMPtr.cpp, line 88] nsXULElement::SetAttrAndNotify [mozilla/content/xul/content/src/nsXULElement.cpp, line 1462] nsXULElement::SetAttr [mozilla/content/xul/content/src/nsXULElement.cpp, line 1442] nsXULElement::SetLeft [mozilla/content/xul/content/src/nsXULElement.cpp, line 2667] XPCWrappedNative::CallMethod [mozilla/js/src/xpconnect/src/xpcwrappednative.cpp, line 2169] XPC_WN_GetterSetter [mozilla/js/src/xpconnect/src/xpcwrappednativejsops.cpp, line 1479] js_Invoke [mozilla/js/src/jsinterp.c, line 1387] js_InternalInvoke [mozilla/js/src/jsinterp.c, line 1481] js_InternalGetOrSet [mozilla/js/src/jsinterp.c, line 1552] js_SetProperty [mozilla/js/src/jsobj.c, line 3729] js_Interpret [mozilla/js/src/jsinterp.c, line 3724] js_Invoke [mozilla/js/src/jsinterp.c, line 1406] js_InternalInvoke [mozilla/js/src/jsinterp.c, line 1481] JS_CallFunctionValue [mozilla/js/src/jsapi.c, line 4389] nsJSContext::CallEventHandler [mozilla/dom/src/base/nsJSEnvironment.cpp, line 1531] TB54461582 opening message nsCOMPtr_base::assign_with_AddRef [mozilla/xpcom/build/nsCOMPtr.cpp, line 88] CSSParserImpl::ParseSingleValueProperty [mozilla/layout/style/nsCSSParser.cpp, line 4683] CSSParserImpl::ParseBoxProperties [mozilla/layout/style/nsCSSParser.cpp, line 4028] CSSParserImpl::ParseMargin [mozilla/layout/style/nsCSSParser.cpp, line 5646] CSSParserImpl::ParseDeclaration [mozilla/layout/style/nsCSSParser.cpp, line 3172] CSSParserImpl::ParseDeclarationBlock [mozilla/layout/style/nsCSSParser.cpp, line 2736] CSSParserImpl::ParseRuleSet [mozilla/layout/style/nsCSSParser.cpp, line 1759] CSSParserImpl::Parse [mozilla/layout/style/nsCSSParser.cpp, line 729] CSSLoaderImpl::ParseSheet [mozilla/layout/style/nsCSSLoader.cpp, line 1392] CSSLoaderImpl::LoadSheet [mozilla/layout/style/nsCSSLoader.cpp, line 1247] CSSLoaderImpl::LoadChildSheet [mozilla/layout/style/nsCSSLoader.cpp, line 1791] CSSParserImpl::ProcessImport [mozilla/layout/style/nsCSSParser.cpp, line 1396] CSSParserImpl::ParseImportRule [mozilla/layout/style/nsCSSParser.cpp, line 1366] CSSParserImpl::ParseAtRule [mozilla/layout/style/nsCSSParser.cpp, line 1207] CSSParserImpl::Parse [mozilla/layout/style/nsCSSParser.cpp, line 726] CSSLoaderImpl::ParseSheet [mozilla/layout/style/nsCSSLoader.cpp, line 1392] CSSLoaderImpl::LoadSheet [mozilla/layout/style/nsCSSLoader.cpp, line 1247] CSSLoaderImpl::InternalLoadAgentSheet [mozilla/layout/style/nsCSSLoader.cpp, line 1873] CSSLoaderImpl::LoadSheetSync [mozilla/layout/style/nsCSSLoader.cpp, line 1801] nsContentDLF::CreateInstanceForDocument [mozilla/layout/build/nsContentDLF.cpp, line 310] nsDocShell::CreateAboutBlankContentViewer [mozilla/docshell/base/nsDocShell.cpp, line 5062]
Version: unspecified → 2.0
nsCOMPtr is a reference-counting pointer wrapper. The bug will never be in nsCOMPtr, it will just be where the crash happens. Ideally crash-stats would filter it out.
yes, please don't lump nsBoxFrame (EEP) with other random callers. Pick one caller and use new bugs for other callers.
I filed bug 522782 for splitting these on the server. It sounds like there's no actual topcrash here for Thunderbird, and I think the same is true for Firefox, but it will be much clearer once bug 522782 is fixed.
Status: NEW → RESOLVED
Closed: 16 years ago
Resolution: --- → INVALID
agree v.invalid
Status: RESOLVED → VERIFIED
Crash Signature: [@ nsCOMPtr_base::assign_with_AddRef]
You need to log in before you can comment on or make changes to this bug.