DrawTargetD2D::CreateGradientTexture crash EXCEPTION_ACCESS_VIOLATION_READ

RESOLVED INCOMPLETE

Status

()

Core
Graphics
--
critical
RESOLVED INCOMPLETE
6 years ago
11 months ago

People

(Reporter: Atte Kettunen, Unassigned)

Tracking

({crash, testcase})

Trunk
x86
Windows 7
crash, testcase
Points:
---

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: [gfx-noted], crash signature)

Attachments

(1 attachment)

(Reporter)

Description

6 years ago
Created attachment 570663 [details]
reprofile for crash.

EXCEPTION_ACCESS_VIOLATION_READ @ mozilla::gfx::DrawTargetD2D::CreateGradientTexture(mozilla::gfx::GradientStopsD2D const*)

So far have been able to reproduce only on Windows tested version 8.0 and 9.0a2. Open attached file to reproduce.

From the attached file editing last value into smaller one in command ctx.createRadialGradient will prevent the crash.

Related bug reports:
https://crash-stats.mozilla.com/report/index/bp-cf17252c-7945-47e5-9c26-e61b92111031(9.0a)
https://crash-stats.mozilla.com/report/index/bp-c6114ba8-4132-4b11-9471-500562111031(8.0)
(Reporter)

Updated

6 years ago
Attachment #570663 - Attachment mime type: text/plain → text/html

Comment 1

6 years ago
The URLs got wrong, here are working versions:
https://crash-stats.mozilla.com/report/index/bp-cf17252c-7945-47e5-9c26-e61b92111031
https://crash-stats.mozilla.com/report/index/bp-c6114ba8-4132-4b11-9471-500562111031

Frame 	Module 	Signature [Expand] 	Source
0 	xul.dll 	mozilla::gfx::DrawTargetD2D::CreateGradientTexture 	gfx/2d/DrawTargetD2D.cpp:1763
1 	xul.dll 	mozilla::gfx::DrawTargetD2D::SetupEffectForRadialGradient 	gfx/2d/DrawTargetD2D.cpp:1836
2 	xul.dll 	mozilla::gfx::DrawTargetD2D::FinalizeRTForOperation 	gfx/2d/DrawTargetD2D.cpp:1438
3 	xul.dll 	mozilla::gfx::DrawTargetD2D::FillRect 	gfx/2d/DrawTargetD2D.cpp:728
4 	xul.dll 	nsCanvasRenderingContext2DAzure::FillRect 	content/canvas/src/nsCanvasRenderingContext2DAzure.cpp:2125
5 	xul.dll 	nsIDOMCanvasRenderingContext2D_FillRect 	obj-firefox/js/src/xpconnect/src/dom_quickstubs.cpp:2438
6 	mozjs.dll 	js::InvokeKernel 	js/src/jsinterp.cpp:660
7 	mozjs.dll 	js::Interpret 	js/src/jsinterp.cpp:4036
8 	mozjs.dll 	js::ContextStack::pushInvokeFrame 	js/src/vm/Stack.cpp:691
9 	mozjs.dll 	js::InvokeKernel 	js/src/jsinterp.cpp:678
10 	mozjs.dll 	JS_CallFunctionValue 	js/src/jsapi.cpp:5039
11 	xul.dll 	nsJSContext::CallEventHandler 	dom/base/nsJSEnvironment.cpp:1929
Crash Signature: [@ mozilla::gfx::DrawTargetD2D::CreateGradientTexture(mozilla::gfx::GradientStopsD2D const*) ]
Component: General → Canvas: 2D
Product: Firefox → Core
QA Contact: general → canvas.2d

Updated

6 years ago
Severity: normal → critical
Keywords: crash
Hardware: x86_64 → x86

Updated

5 years ago
Status: UNCONFIRMED → NEW
Ever confirmed: true
Keywords: testcase
Version: 9 Branch → Trunk

Comment 2

5 years ago
From crash-stats:
* Several crashes per day with this signature
* Affects http://www.coloradovacationrentals.com/Vail-vacation-rentals.htm
I suspect this is because the gradient cache passes in a none-D2D Gradient. We need to make sure the gradient cache checks a gradient's backend type.
(In reply to Bas Schouten (:bas) from comment #3)
> I suspect this is because the gradient cache passes in a none-D2D Gradient.
> We need to make sure the gradient cache checks a gradient's backend type.

Argh, this is not the right crash or bug to mention this on. Let me make a correct one.

Comment 5

5 years ago
This signature appears to have been introduced to Aurora by the uplift of 18 to that channel.
(In reply to Robert Kaiser (:kairo@mozilla.com) from comment #5)
> This signature appears to have been introduced to Aurora by the uplift of 18
> to that channel.

That's bug 800319 I believe.

Comment 7

5 years ago
(In reply to Robert Kaiser (:kairo@mozilla.com) from comment #5)
> This signature appears to have been introduced to Aurora by the uplift of 18
> to that channel.
It started spiking from 18.0a1/20120924. The regression range for the spike might be:
http://hg.mozilla.org/mozilla-central/pushloghtml?fromchange=9d285bedbc1f&tochange=b2867d82dcad
@Bas what you suggested seemed to have been fixed by bug 800319 but the crash is still there, ideas about possible solutions. I would like to work on this.

Updated

4 years ago
Component: Canvas: 2D → Graphics

Updated

2 years ago
Crash Signature: [@ mozilla::gfx::DrawTargetD2D::CreateGradientTexture(mozilla::gfx::GradientStopsD2D const*) ] → [@ mozilla::gfx::DrawTargetD2D::CreateGradientTexture(mozilla::gfx::GradientStopsD2D const*) ] [@ mozilla::gfx::DrawTargetD2D::CreateGradientTexture ]
I am closing this as incomplete as this crash is no longer being reported with current Firefox versions.
Status: NEW → RESOLVED
Last Resolved: 11 months ago
Resolution: --- → INCOMPLETE
Whiteboard: [gfx-noted]
You need to log in before you can comment on or make changes to this bug.