Closed
Bug 574884
Opened 16 years ago
Closed 16 years ago
[html5] Crash [@ nsHtml5TreeBuilder::eof] with innerHTML on <math></html> in iframe
Categories
(Core :: DOM: HTML Parser, defect, P2)
Tracking
()
RESOLVED
FIXED
| Tracking | Status | |
|---|---|---|
| blocking2.0 | --- | final+ |
| status1.9.2 | --- | unaffected |
| status1.9.1 | --- | unaffected |
People
(Reporter: martijn.martijn, Assigned: hsivonen)
References
Details
(Keywords: crash, regression, testcase, Whiteboard: [sg:critical?][critsmash:patch])
Crash Data
Attachments
(3 files)
See testcase, which crashes current trunk build on load.
http://crash-stats.mozilla.com/report/index/86fed2b7-1d35-4d28-b6e5-a34272100625
0 xul.dll nsHtml5TreeBuilder::eof
1 xul.dll nsGenericHTMLElement::SetInnerHTML content/html/content/src/nsGenericHTMLElement.cpp:738
2 xul.dll nsIDOMNSHTMLElement_SetInnerHTML obj-firefox/js/src/xpconnect/src/dom_quickstubs.cpp:17501
3 mozjs.dll JSScopeProperty::set js/src/jsscope.h:1028
4 mozjs.dll js_SetPropertyHelper js/src/jsobj.cpp:5128
5 mozjs.dll js_Interpret js/src/jsops.cpp:1827
6 mozjs.dll js_Execute js/src/jsinterp.cpp:854
7 mozjs.dll JS_EvaluateUCScriptForPrincipals js/src/jsapi.cpp:4563
8 xul.dll nsJSContext::EvaluateString dom/base/nsJSEnvironment.cpp:1786
9 xul.dll nsScriptLoader::EvaluateScript content/base/src/nsScriptLoader.cpp:752
10 xul.dll nsScriptLoader::ProcessRequest content/base/src/nsScriptLoader.cpp:665
11 xul.dll nsSVGCircleElement::AddRef content/base/src/nsCommentNode.cpp:119
12 xul.dll nsScriptLoader::ProcessScriptElement content/base/src/nsScriptLoader.cpp:614
| Reporter | ||
Comment 1•16 years ago
|
||
<svg></html> is crash with this stacktrace:
http://crash-stats.mozilla.com/report/index/f014c0e2-928f-45d2-8140-f09792100627
0 xul.dll nsHtml5TreeBuilder::eof
1 nspr4.dll nspr4.dll@0x1b3df
2 xul.dll nsHtml5Tokenizer::eof parser/html/nsHtml5Tokenizer.cpp:3701
3 nspr4.dll nspr4.dll@0x1b3df
4 xul.dll nsHtml5StreamParser::ParseAvailableData parser/html/nsHtml5StreamParser.cpp:833
5 xul.dll nsHtml5StreamParser::IsTerminatedOrInterrupted parser/html/nsHtml5StreamParser.h:231
6 xul.dll nsHtml5StreamParser::DoStopRequest parser/html/nsHtml5StreamParser.cpp:615
7 xul.dll nsHtml5RequestStopper::Run parser/html/nsHtml5StreamParser.cpp:629
8 xul.dll nsThread::ProcessNextEvent xpcom/threads/nsThread.cpp:547
9 xul.dll nsThread::ThreadFunc xpcom/threads/nsThread.cpp:263
10 nspr4.dll _PR_NativeRunThread nsprpub/pr/src/threads/combined/pruthr.c:426
11 nspr4.dll pr_root nsprpub/pr/src/md/windows/w95thred.c:122
12 mozcrt19.dll _callthreadstartex obj-firefox/memory/jemalloc/crtsrc/threadex.c:348
13 mozcrt19.dll _threadstartex obj-firefox/memory/jemalloc/crtsrc/threadex.c:326
14 kernel32.dll kernel32.dll@0x51193
15 ntdll.dll __RtlUserThreadStart
16 ntdll.dll _RtlUserThreadStart
| Assignee | ||
Comment 2•16 years ago
|
||
Good catch. Further poking revealed serious spec trouble.
| Assignee | ||
Comment 3•16 years ago
|
||
| Assignee | ||
Updated•16 years ago
|
Priority: -- → P2
Attachment #455108 -
Flags: review?(jonas) → review+
| Assignee | ||
Comment 4•16 years ago
|
||
The patch for bug 579867 fixes this one also and obsoletes the patch here.
Comment 5•16 years ago
|
||
If I use MallocScribble, the crash address changes from 0x1c to 0xffffffffaaaaaac6. (Tested using a Firefox debug build from Tinderbox in the same harness I use for fuzzing.)
Group: core-security
blocking2.0: --- → ?
Whiteboard: [sg:critical?]
Updated•16 years ago
|
Whiteboard: [sg:critical?] → [sg:critical?][critsmash:patch]
Updated•16 years ago
|
blocking2.0: ? → final+
Comment 6•16 years ago
|
||
Seems to have been fixed by the patch in bug 579867.
Status: ASSIGNED → RESOLVED
Closed: 16 years ago
Resolution: --- → FIXED
Updated•15 years ago
|
Updated•15 years ago
|
Crash Signature: [@ nsHtml5TreeBuilder::eof]
You need to log in
before you can comment on or make changes to this bug.
Description
•