Last Comment Bug 743767 - Firefox crash @ memcpy | GlyphBufferAzure::Flush
: Firefox crash @ memcpy | GlyphBufferAzure::Flush
: crash, regression
Product: Core
Classification: Components
Component: Graphics (show other bugs)
: Trunk
: x86 Windows 7
-- critical (vote)
: mozilla14
Assigned To: Jonathan Kew (:jfkthame)
: Milan Sreckovic [:milan]
Depends on:
Blocks: 738691 742727
  Show dependency treegraph
Reported: 2012-04-09 12:00 PDT by Marcia Knous [:marcia - use ni]
Modified: 2012-04-11 13:45 PDT (History)
4 users (show)
See Also:
Crash Signature:
QA Whiteboard:
Iteration: ---
Points: ---
Has Regression Range: ---
Has STR: ---

patch (untested) - fix the pattern matrix issues (1.90 KB, patch)
2012-04-09 12:31 PDT, Jonathan Kew (:jfkthame)
bas: review+
Details | Diff | Splinter Review

Description User image Marcia Knous [:marcia - use ni] 2012-04-09 12:00:13 PDT
Seen while looking at trunk crash stats. Crashes started showing up in crash stats using the 2012040603 build. Fairly small volume but looks like different users based on driver versions.

Comments: "Browsing the list of official components for Foobar2000 media player."

Possible regression range based on crash stats:

Frame 	Module 	Signature 	Source
0 	msvcr100.dll 	memcpy 	f:\\dd\\vctools\\crt_bld\\SELF_64_amd64\\crt\\src\\amd64\\memcpy.asm:274
1 	xul.dll 	GlyphBufferAzure::Flush 	gfx/thebes/gfxFont.cpp:1517
2 	mozglue.dll 	choose_arena 	memory/jemalloc/jemalloc.c:2969
3 	uxtheme.dll 	_InternalSystemParametersInfo 	
4 	uxtheme.dll 	ThemeSystemParametersInfoA 	
5 	xul.dll 	gfxFont::Draw 	gfx/thebes/gfxFont.cpp:1922
Comment 1 User image Jonathan Kew (:jfkthame) 2012-04-09 12:29:21 PDT
I see a couple of issues with the code in GlyphBufferAzure::Flush:

(a) incorrect casts, so that it'll look at the wrong location for the matrix in radial-gradient and surface patterns;

(b) it doesn't check whether the pattern may be one (color) that doesn't have a matrix at all.

(This code landed in bug 738691.)
Comment 2 User image Jonathan Kew (:jfkthame) 2012-04-09 12:31:52 PDT
Created attachment 613360 [details] [diff] [review]
patch (untested) - fix the pattern matrix issues
Comment 3 User image Bas Schouten (:bas.schouten) 2012-04-09 18:58:15 PDT
Comment on attachment 613360 [details] [diff] [review]
patch (untested) - fix the pattern matrix issues

Review of attachment 613360 [details] [diff] [review]:

I'm ashamed.

Note You need to log in before you can comment on or make changes to this bug.