Closed Bug 574884 Opened 16 years ago Closed 16 years ago

[html5] Crash [@ nsHtml5TreeBuilder::eof] with innerHTML on <math></html> in iframe

Categories

(Core :: DOM: HTML Parser, defect, P2)

x86
Windows 7
defect

Tracking

()

RESOLVED FIXED
Tracking Status
blocking2.0 --- final+
status1.9.2 --- unaffected
status1.9.1 --- unaffected

People

(Reporter: martijn.martijn, Assigned: hsivonen)

References

Details

(Keywords: crash, regression, testcase, Whiteboard: [sg:critical?][critsmash:patch])

Crash Data

Attachments

(3 files)

Attached file testcase —
See testcase, which crashes current trunk build on load. http://crash-stats.mozilla.com/report/index/86fed2b7-1d35-4d28-b6e5-a34272100625 0 xul.dll nsHtml5TreeBuilder::eof 1 xul.dll nsGenericHTMLElement::SetInnerHTML content/html/content/src/nsGenericHTMLElement.cpp:738 2 xul.dll nsIDOMNSHTMLElement_SetInnerHTML obj-firefox/js/src/xpconnect/src/dom_quickstubs.cpp:17501 3 mozjs.dll JSScopeProperty::set js/src/jsscope.h:1028 4 mozjs.dll js_SetPropertyHelper js/src/jsobj.cpp:5128 5 mozjs.dll js_Interpret js/src/jsops.cpp:1827 6 mozjs.dll js_Execute js/src/jsinterp.cpp:854 7 mozjs.dll JS_EvaluateUCScriptForPrincipals js/src/jsapi.cpp:4563 8 xul.dll nsJSContext::EvaluateString dom/base/nsJSEnvironment.cpp:1786 9 xul.dll nsScriptLoader::EvaluateScript content/base/src/nsScriptLoader.cpp:752 10 xul.dll nsScriptLoader::ProcessRequest content/base/src/nsScriptLoader.cpp:665 11 xul.dll nsSVGCircleElement::AddRef content/base/src/nsCommentNode.cpp:119 12 xul.dll nsScriptLoader::ProcessScriptElement content/base/src/nsScriptLoader.cpp:614
Attached file testcase2 —
<svg></html> is crash with this stacktrace: http://crash-stats.mozilla.com/report/index/f014c0e2-928f-45d2-8140-f09792100627 0 xul.dll nsHtml5TreeBuilder::eof 1 nspr4.dll nspr4.dll@0x1b3df 2 xul.dll nsHtml5Tokenizer::eof parser/html/nsHtml5Tokenizer.cpp:3701 3 nspr4.dll nspr4.dll@0x1b3df 4 xul.dll nsHtml5StreamParser::ParseAvailableData parser/html/nsHtml5StreamParser.cpp:833 5 xul.dll nsHtml5StreamParser::IsTerminatedOrInterrupted parser/html/nsHtml5StreamParser.h:231 6 xul.dll nsHtml5StreamParser::DoStopRequest parser/html/nsHtml5StreamParser.cpp:615 7 xul.dll nsHtml5RequestStopper::Run parser/html/nsHtml5StreamParser.cpp:629 8 xul.dll nsThread::ProcessNextEvent xpcom/threads/nsThread.cpp:547 9 xul.dll nsThread::ThreadFunc xpcom/threads/nsThread.cpp:263 10 nspr4.dll _PR_NativeRunThread nsprpub/pr/src/threads/combined/pruthr.c:426 11 nspr4.dll pr_root nsprpub/pr/src/md/windows/w95thred.c:122 12 mozcrt19.dll _callthreadstartex obj-firefox/memory/jemalloc/crtsrc/threadex.c:348 13 mozcrt19.dll _threadstartex obj-firefox/memory/jemalloc/crtsrc/threadex.c:326 14 kernel32.dll kernel32.dll@0x51193 15 ntdll.dll __RtlUserThreadStart 16 ntdll.dll _RtlUserThreadStart
Good catch. Further poking revealed serious spec trouble.
Assignee: nobody → hsivonen
Status: NEW → ASSIGNED
Attachment #455108 - Flags: review?(jonas)
Priority: -- → P2
Depends on: 579867
The patch for bug 579867 fixes this one also and obsoletes the patch here.
If I use MallocScribble, the crash address changes from 0x1c to 0xffffffffaaaaaac6. (Tested using a Firefox debug build from Tinderbox in the same harness I use for fuzzing.)
Group: core-security
blocking2.0: --- → ?
Whiteboard: [sg:critical?]
Whiteboard: [sg:critical?] → [sg:critical?][critsmash:patch]
blocking2.0: ? → final+
Seems to have been fixed by the patch in bug 579867.
Status: ASSIGNED → RESOLVED
Closed: 16 years ago
Resolution: --- → FIXED
Group: core-security
Crash Signature: [@ nsHtml5TreeBuilder::eof]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: