Closed Bug 625330 Opened 14 years ago Closed 13 years ago

Firefox 4.0b10pre 64-bit crash [@ arena_dalloc | nsTArray_base<nsTArrayDefaultAllocator>::~nsTArray_base<nsTArrayDefaultAllocator>() ][@ ntdll.dll@0x4d036 ][@ arena_dalloc | nsIFrame::GetOffsetToCrossDoc(nsIFrame const*, int) ]

Categories

(Core :: Layout, defect)

x86_64
Windows 7
defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 625247

People

(Reporter: scoobidiver, Unassigned)

Details

(Keywords: crash, regression, topcrash)

Crash Data

It is a new crash signature that first appeared in 4.0b10pre/20110112.
It is #1 top crasher in this build.
It is probably a dupe of bug 625247.

Signature	arena_dalloc | nsTArray_base<nsTArrayDefaultAllocator>::~nsTArray_base<nsTArrayDefaultAllocator>()
UUID	24cfb420-80cb-42e5-9918-44c022110113
Time 	2011-01-13 00:38:46.657026
Uptime	9852
Last Crash	13994 seconds (3.9 hours) before submission
Install Age	19468 seconds (5.4 hours) since version was first installed.
Product	Firefox
Version	4.0b10pre
Build ID	20110112074539
Branch	2.0
OS	Windows NT
OS Version	6.1.7600
CPU	amd64
CPU Info	family 6 model 26 stepping 4
Crash Reason	EXCEPTION_ACCESS_VIOLATION_READ
Crash Address	0x300000
User Comments	
App Notes 	AdapterVendorID: 10de, AdapterDeviceID: 1081

Frame 	Module 	Signature [Expand] 	Source
0 	mozcrt19.dll 	arena_dalloc 	obj-firefox/memory/jemalloc/crtsrc/jemalloc.c:4275
1 	xul.dll 	nsTArray_base<nsTArrayDefaultAllocator>::~nsTArray_base<nsTArrayDefaultAllocator> 	obj-firefox/dist/include/nsTArray-inl.h:52
2 	xul.dll 	nsTArray<nsDisplayListBuilder::PresShellState,nsTArrayDefaultAllocator>::RemoveElementsAt 	obj-firefox/dist/include/nsTArray.h:834
3 	xul.dll 	SnapBounds 	layout/base/nsDisplayList.cpp:900
4 	xul.dll 	nsDisplayWrapList::nsDisplayWrapList 	layout/base/nsDisplayList.cpp:1334
5 	xul.dll 	nsDisplayListBuilder::LeavePresShell 	layout/base/nsDisplayList.cpp:282
6 	xul.dll 	nsDisplayList::DeleteAll 	layout/base/nsDisplayList.cpp:540
7 	xul.dll 	nsSubDocumentFrame::BuildDisplayList 	layout/generic/nsSubDocumentFrame.cpp:436
8 	xul.dll 	ApplyOverflowClipping 	layout/generic/nsFrame.cpp:1255
9 	xul.dll 	nsIFrame::BuildDisplayListForChild 	layout/generic/nsFrame.cpp:1761
10 	xul.dll 	mozilla::FramePropertyTable::Get 	layout/base/FramePropertyTable.cpp:105
11 	xul.dll 	DisplayLine 	layout/generic/nsBlockFrame.cpp:6173

The regression range is:
http://hg.mozilla.org/mozilla-central/pushloghtml?fromchange=4413ed6ba5a5&tochange=c0e05d518f57

More reports at:
http://crash-stats.mozilla.com/report/list?range_value=4&range_unit=weeks&signature=arena_dalloc%20|%20nsTArray_base%3CnsTArrayDefaultAllocator%3E%3A%3A~nsTArray_base%3CnsTArrayDefaultAllocator%3E%28%29&version=Firefox%3A4.0b10pre
Summary: Firefox 4.0b10pre 64-bit crash [@ arena_dalloc | nsTArray_base<nsTArrayDefaultAllocator>::~nsTArray_base<nsTArrayDefaultAllocator>() ] → Firefox 4.0b10pre 64-bit crash [@ arena_dalloc | nsTArray_base<nsTArrayDefaultAllocator>::~nsTArray_base<nsTArrayDefaultAllocator>() ][@ ntdll.dll@0x4d036 ]
Summary: Firefox 4.0b10pre 64-bit crash [@ arena_dalloc | nsTArray_base<nsTArrayDefaultAllocator>::~nsTArray_base<nsTArrayDefaultAllocator>() ][@ ntdll.dll@0x4d036 ] → Firefox 4.0b10pre 64-bit crash [@ arena_dalloc | nsTArray_base<nsTArrayDefaultAllocator>::~nsTArray_base<nsTArrayDefaultAllocator>() ][@ ntdll.dll@0x4d036 ][@ arena_dalloc | nsIFrame::GetOffsetToCrossDoc(nsIFrame const*, int) ]
Keywords: topcrash
I am nominating this since it's a new regression on the trunk and we need to have it looked at.
blocking2.0: --- → ?
The above link only seems to include crashs in builds with date being 2011-01-12. Are there crashes in builds since then?
> I am nominating this since it's a new regression on the trunk and we need to
> have it looked at.
I though we didn't block on the 64-bit build.

> Are there crashes in builds since then?
No, but there has been only one new 64-bit build (2011-01-18) to check for.
Yes, Scoobidiver, you are correct. My bad. We don't block on this one.
blocking2.0: ? → ---
latest build id of this crash is 20110112074539.  So dup of bug 625247.
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → DUPLICATE
Crash Signature: [@ arena_dalloc | nsTArray_base<nsTArrayDefaultAllocator>::~nsTArray_base<nsTArrayDefaultAllocator>() ] [@ ntdll.dll@0x4d036 ] [@ arena_dalloc | nsIFrame::GetOffsetToCrossDoc(nsIFrame const*, int) ]
You need to log in before you can comment on or make changes to this bug.