[ANGLE] WebGLES shader crash [@IncLineNumber]

VERIFIED FIXED

Status

()

Core
Canvas: WebGL
--
critical
VERIFIED FIXED
7 years ago
7 years ago

People

(Reporter: posidron, Assigned: bjacob)

Tracking

(Blocks: 1 bug, {crash, regression, testcase})

Trunk
x86_64
Mac OS X
crash, regression, testcase
Points:
---

Firefox Tracking Flags

(firefox5 unaffected, firefox6 unaffected, blocking2.0 final+, status1.9.2 unaffected, status1.9.1 unaffected)

Details

(Whiteboard: [sg:critical?][hardblocker][fx4-fixed-bugday] , crash signature)

Attachments

(2 attachments)

(Reporter)

Description

7 years ago
Created attachment 504869 [details]
testcase

I haven't analyzed this bug yet but rax looks interesting and we have a write to rbp instruction in the second place. That's why I have marked it as a security issue.

OpenGL LayerManager Initialized Succesfully.
Version: 2.1 NVIDIA-1.6.26
Vendor: NVIDIA Corporation
Renderer: NVIDIA GeForce GT 330M OpenGL Engine
FBO Texture Target: TEXTURE_2D

Build identifier: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:2.0b10pre) Gecko/20110115 Firefox/4.0b10pre
(Reporter)

Comment 1

7 years ago
Created attachment 504870 [details]
callstack
(Reporter)

Updated

7 years ago
Summary: [ANGLE] WebGLES shader crash [@IncLineNumber()] → [ANGLE] WebGLES shader crash [@IncLineNumber]

Comment 2

7 years ago
I think I've got a fix for this one.

Comment 3

7 years ago
This should be fixed in ANGLE r540.
Are we likely to get an updated ANGLE library for Firefox 4 ship?
blocking2.0: --- → ?
status1.9.1: --- → unaffected
status1.9.2: --- → unaffected
Whiteboard: [sg:critical?]
Yes, absolutely.  Bug 629538 tracks it, benoit's working on it.
Assignee: nobody → bjacob
blocking2.0: ? → final+
Keywords: regression
Whiteboard: [sg:critical?] → [sg:critical?][hardblocker]
(Assignee)

Comment 6

7 years ago
Updated to ANGLE r550. Reopen if you can still reproduce the issue.
Status: NEW → RESOLVED
Last Resolved: 7 years ago
Resolution: --- → FIXED
Verified fixed in beta 11 with Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6;
rv:2.0b11) Gecko/20100101 Firefox/4.0b11 using testcase. Crash reproduces in
beta 10.
Status: RESOLVED → VERIFIED
Whiteboard: [sg:critical?][hardblocker] → [sg:critical?][hardblocker][fx4-fixed-bugday]
(Reporter)

Updated

7 years ago
Blocks: 658170
Crash Signature: [@IncLineNumber]
Group: core-security
status-firefox5: --- → unaffected
status-firefox6: --- → unaffected
You need to log in before you can comment on or make changes to this bug.