Last Comment Bug 743767 - Firefox crash @ memcpy | GlyphBufferAzure::Flush
: Firefox crash @ memcpy | GlyphBufferAzure::Flush
Status: RESOLVED FIXED
: crash, regression
Product: Core
Classification: Components
Component: Graphics (show other bugs)
: Trunk
: x86 Windows 7
: -- critical (vote)
: mozilla14
Assigned To: Jonathan Kew (:jfkthame)
:
Mentors:
Depends on:
Blocks: 738691 742727
  Show dependency treegraph
 
Reported: 2012-04-09 12:00 PDT by Marcia Knous [:marcia - use ni]
Modified: 2012-04-11 13:45 PDT (History)
4 users (show)
See Also:
Crash Signature:
QA Whiteboard:
Iteration: ---
Points: ---
Has Regression Range: ---
Has STR: ---


Attachments
patch (untested) - fix the pattern matrix issues (1.90 KB, patch)
2012-04-09 12:31 PDT, Jonathan Kew (:jfkthame)
bas: review+
Details | Diff | Review

Description Marcia Knous [:marcia - use ni] 2012-04-09 12:00:13 PDT
Seen while looking at trunk crash stats. Crashes started showing up in crash stats using the 2012040603 build. Fairly small volume but looks like different users based on driver versions.

Comments: "Browsing the list of official components for Foobar2000 media player."

Possible regression range based on crash stats: http://hg.mozilla.org/mozilla-central/pushloghtml?fromchange=ed9cbe6a817e&tochange=da0d07b5ca1e

https://crash-stats.mozilla.com/report/index/be348524-39fb-402d-8781-737652120409

Frame 	Module 	Signature 	Source
0 	msvcr100.dll 	memcpy 	f:\\dd\\vctools\\crt_bld\\SELF_64_amd64\\crt\\src\\amd64\\memcpy.asm:274
1 	xul.dll 	GlyphBufferAzure::Flush 	gfx/thebes/gfxFont.cpp:1517
2 	mozglue.dll 	choose_arena 	memory/jemalloc/jemalloc.c:2969
3 	uxtheme.dll 	_InternalSystemParametersInfo 	
4 	uxtheme.dll 	ThemeSystemParametersInfoA 	
5 	xul.dll 	gfxFont::Draw 	gfx/thebes/gfxFont.cpp:1922
Comment 1 Jonathan Kew (:jfkthame) 2012-04-09 12:29:21 PDT
I see a couple of issues with the code in GlyphBufferAzure::Flush:

(a) incorrect casts, so that it'll look at the wrong location for the matrix in radial-gradient and surface patterns;

(b) it doesn't check whether the pattern may be one (color) that doesn't have a matrix at all.

(This code landed in bug 738691.)
Comment 2 Jonathan Kew (:jfkthame) 2012-04-09 12:31:52 PDT
Created attachment 613360 [details] [diff] [review]
patch (untested) - fix the pattern matrix issues
Comment 3 Bas Schouten (:bas.schouten) 2012-04-09 18:58:15 PDT
Comment on attachment 613360 [details] [diff] [review]
patch (untested) - fix the pattern matrix issues

Review of attachment 613360 [details] [diff] [review]:
-----------------------------------------------------------------

I'm ashamed.
Comment 5 :Ehsan Akhgari (busy, don't ask for review please) 2012-04-10 13:07:08 PDT
https://hg.mozilla.org/mozilla-central/rev/ca10513eff60

Note You need to log in before you can comment on or make changes to this bug.