Open Bug 700840 Opened 13 years ago Updated 2 years ago

EXCEPTION_ACCESS_VIOLATION_WRITE crash @ RtlEnterCriticalSection

Categories

(Core :: General, defect)

8 Branch
x86
Windows 7
defect

Tracking

()

People

(Reporter: epinal99-bugzilla2, Unassigned)

References

Details

(Keywords: crash)

Crash Data

User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
Build ID: 20111104165243

Steps to reproduce:

2 crash reports about Firefox 8.0 Crash Report [@ RtlEnterCriticalSection ]:
https://crash-stats.mozilla.com/report/index/bp-aa7b68e3-f06c-46fe-9f5f-319f22111108
https://crash-stats.mozilla.com/report/index/bp-2e0d69e1-8d3b-424a-bdf3-3c8fb2111108

The user disabled the Hardware Acceleration in Firefox and the issue seemed to be gone. His computer has Nvidia SLI technology (Q6600, Win 7 x64 and SLI of GTX460), surely the culprit...

Signature	RtlEnterCriticalSection
UUID	2e0d69e1-8d3b-424a-bdf3-3c8fb2111108
Date Processed	2011-11-08 14:34:16.507615
Uptime	22
Last Crash	24 seconds before submission
Install Age	1.2 hours since version was first installed.
Install Time	2011-11-08 21:22:33
Product	Firefox
Version	8.0
Build ID	20111104165243
Release Channel	release
OS	Windows NT
OS Version	6.1.7601 Service Pack 1
Build Architecture	x86
Build Architecture Info	GenuineIntel family 6 model 15 stepping 11
Crash Reason	EXCEPTION_ACCESS_VIOLATION_WRITE
Crash Address	0x63500b80
User Comments	
App Notes 	AdapterVendorID: 10de, AdapterDeviceID: 0e22, AdapterDriverVersion: 8.17.12.8562
Has dual GPUs. GPU #2: AdapterVendorID2: 10de, AdapterDeviceID2: 0e22, AdapterDriverVersion2: 8.17.12.8562D2D? D2D+
DWrite? DWrite+
D3D10 Layers? D3D10 Layers+
Processor Notes 	Priority Job
EMCheckCompatibility	True
Winsock LSP	MSAFD Tcpip [TCP/IP] : 2 : 1 : %SystemRoot%\system32\mswsock.dll MSAFD Tcpip [UDP/IP] : 2 : 2 : MSAFD Tcpip [RAW/IP] : 2 : 3 : %SystemRoot%\system32\mswsock.dll MSAFD Tcpip [TCP/IPv6] : 2 : 1 : MSAFD Tcpip [UDP/IPv6] : 2 : 2 : %SystemRoot%\system32\mswsock.dll MSAFD Tcpip [RAW/IPv6] : 2 : 3 : Fournisseur de services RSVP TCPv6 : 2 : 1 : %SystemRoot%\system32\mswsock.dll Fournisseur de services RSVP TCP : 2 : 1 : Fournisseur de services RSVP UDPv6 : 2 : 2 : %SystemRoot%\system32\mswsock.dll Fournisseur de services RSVP UDP : 2 : 2 :
Adapter Vendor ID	
Adapter Device ID	

Frame 	Module 	Signature [Expand] 	Source
0 	ntdll.dll 	RtlEnterCriticalSection 	
1 	mozcrt19.dll 	arena_dalloc 	obj-firefox/memory/jemalloc/crtsrc/jemalloc.c:4280
2 	mozcrt19.dll 	free 	obj-firefox/memory/jemalloc/crtsrc/jemalloc.c:6200
3 	xul.dll 	nsTArray_base<nsTArrayDefaultAllocator>::ShrinkCapacity 	obj-firefox/dist/include/nsTArray-inl.h:142
4 	xul.dll 	nsTHashtable<mozilla::FrameLayerBuilder::ThebesLayerItemsEntry>::s_ClearEntry 	
5 	xul.dll 	PL_DHashTableFinish 	obj-firefox/xpcom/build/pldhash.cpp:410
6 	xul.dll 	nsLayoutUtils::PaintFrame 	layout/base/nsLayoutUtils.cpp:1721
Crash Signature: [@ RtlEnterCriticalSection ]
Severity: normal → critical
Status: UNCONFIRMED → NEW
Component: General → Layout
Ever confirmed: true
Keywords: crash
Product: Firefox → Core
QA Contact: general → layout
Hardware: x86_64 → x86
Still pretty high on releases. The #30 top crash on 8.0 over the past week.
Keywords: topcrash
Depends on: 720655
Crash Signature: [@ RtlEnterCriticalSection ] → [@ RtlEnterCriticalSection ] [@ RtlEnterCriticalSection | arena_dalloc | free | nsTArray_base<nsTArrayDefaultAllocator>::ShrinkCapacity(unsigned int unsigned int) | nsTHashtable<mozilla::FrameLayerBuilder::ThebesLayerItemsEntry>::s_ClearEntry(PLDHashTabl…
Keywords: topcrash
Summary: EXCEPTION_ACCESS_VIOLATION_WRITE Crash [@ RtlEnterCriticalSection ] in nsTArray_base<nsTArrayDefaultAllocator>::ShrinkCapacity → EXCEPTION_ACCESS_VIOLATION_WRITE crash in nsLayoutUtils::PaintFrame @ RtlEnterCriticalSection
Crash Signature: , unsigned int) | nsTHashtable<mozilla::FrameLayerBuilder::ThebesLayerItemsEntry>::s_ClearEntry(PLDHashTable*, PLDHashEntryHdr*)] → , unsigned int) | nsTHashtable<mozilla::FrameLayerBuilder::ThebesLayerItemsEntry>::s_ClearEntry(PLDHashTable*, PLDHashEntryHdr*)] [@ RtlEnterCriticalSection | arena_dalloc | free | nsTArray_base<T>::ShrinkCapacity | nsTHashtable<T>::s_ClearEntry]
Crash Signature: [@ RtlEnterCriticalSection ] [@ RtlEnterCriticalSection | arena_dalloc | free | nsTArray_base<nsTArrayDefaultAllocator>::ShrinkCapacity(unsigned int, unsigned int) | nsTHashtable<mozilla::FrameLayerBuilder::ThebesLayerItemsEntry>::s_ClearEntry(PLDHashTab… → [@ RtlEnterCriticalSection ]
Component: Layout → General
Summary: EXCEPTION_ACCESS_VIOLATION_WRITE crash in nsLayoutUtils::PaintFrame @ RtlEnterCriticalSection → EXCEPTION_ACCESS_VIOLATION_WRITE crash @ RtlEnterCriticalSection
QA Whiteboard: qa-not-actionable

Since the crash volume is low (less than 5 per week), the severity is downgraded to S3. Feel free to change it back if you think the bug is still critical.

For more information, please visit auto_nag documentation.

Severity: critical → S3
You need to log in before you can comment on or make changes to this bug.