Last Comment Bug 744077 - Startup crash - PR_Free in ProcessBodyAsAttachment
: Startup crash - PR_Free in ProcessBodyAsAttachment
: crash, regression
Product: MailNews Core
Classification: Components
Component: MIME (show other bugs)
: Trunk
: x86 All
: -- critical (vote)
: Thunderbird 17.0
Assigned To: Hiroyuki Ikezoe (:hiro)
Depends on:
Blocks: 679476
  Show dependency treegraph
Reported: 2012-04-10 10:44 PDT by Mike Conley (:mconley)
Modified: 2012-08-21 06:31 PDT (History)
6 users (show)
See Also:
Crash Signature:
QA Whiteboard:
Iteration: ---
Points: ---

possible fix (1.34 KB, patch)
2012-08-20 17:29 PDT, Hiroyuki Ikezoe (:hiro)
standard8: review+
standard8: approval‑comm‑aurora+
standard8: approval‑comm‑beta+
Details | Diff | Splinter Review

Description User image Mike Conley (:mconley) 2012-04-10 10:44:04 PDT
On my latest build of comm-central, after startup, I have about 5 seconds before I crash, with the following backtrace:

#0  0xb78a9424 in __kernel_vsyscall ()
#1  0xb767a8b6 in nanosleep () from /lib/i386-linux-gnu/
#2  0xb767a6af in sleep () from /lib/i386-linux-gnu/
#3  0xb387239f in ah_crap_handler (signum=6) at /media/Projects/mozilla/thunderbird/mozilla/toolkit/xre/nsSigHandlers.cpp:121
#4  0xb3877f4e in nsProfileLock::FatalSignalHandler (signo=6, info=0xbfd6363c, context=0xbfd636bc) at /media/Projects/mozilla/objdir-thunderbird-patches/mozilla/toolkit/profile/nsProfileLock.cpp:227
#5  <signal handler called>
#6  0xb78a9424 in __kernel_vsyscall ()
#7  0xb75f61ef in raise () from /lib/i386-linux-gnu/
#8  0xb75f9835 in abort () from /lib/i386-linux-gnu/
#9  0x080579fc in arena_run_reg_dalloc (run=0xa4113000, bin=0xb74995ec, ptr=0xa4116ef4, size=272) at /media/Projects/mozilla/thunderbird/mozilla/memory/jemalloc/jemalloc.c:3288
#10 0x0805c2bd in arena_dalloc_small (arena=0xb7499040, chunk=0xa4100000, ptr=0xa4116ef4, mapelm=0xa4100118) at /media/Projects/mozilla/thunderbird/mozilla/memory/jemalloc/jemalloc.c:4486
#11 0x0805cb5d in arena_dalloc (ptr=0xa4116ef4, offset=93940) at /media/Projects/mozilla/thunderbird/mozilla/memory/jemalloc/jemalloc.c:4614
#12 0x0805ffc5 in free (ptr=0xa4116ef4) at /media/Projects/mozilla/thunderbird/mozilla/memory/jemalloc/jemalloc.c:6541
#13 0xb72d4505 in PR_Free () from /usr/lib/i386-linux-gnu/
#14 0xb5199368 in ProcessBodyAsAttachment (obj=0xac1a5f00, data=0xbfd63e94) at /media/Projects/mozilla/thunderbird/mailnews/mime/src/mimemoz2.cpp:213
#15 0xb519aaa6 in MimeGetAttachmentList (tobj=0xa80a1c90, aMessageURL=0x98ffed30 "imap://", 
    data=0xbfd63e94) at /media/Projects/mozilla/thunderbird/mailnews/mime/src/mimemoz2.cpp:611
#16 0xb519bd55 in mime_display_stream_complete (stream=0xa6f5c960) at /media/Projects/mozilla/thunderbird/mailnews/mime/src/mimemoz2.cpp:1027
#17 0xb51a80e7 in nsStreamConverter::OnStopRequest (this=0xa48f9e20, request=0x991a2d60, ctxt=0xac005144, status=0) at /media/Projects/mozilla/thunderbird/mailnews/mime/src/nsStreamConverter.cpp:1090
#18 0xb507a4a7 in nsImapCacheStreamListener::OnStopRequest (this=0xa6f5c7e0, request=0xae3deac0, aCtxt=0xac005144, aStatus=0) at /media/Projects/mozilla/thunderbird/mailnews/imap/src/nsImapProtocol.cpp:8627
#19 0xb38b7c54 in nsInputStreamPump::OnStateStop (this=0xae3deac0) at /media/Projects/mozilla/thunderbird/mozilla/netwerk/base/src/nsInputStreamPump.cpp:583
#20 0xb38b748f in nsInputStreamPump::OnInputStreamReady (this=0xae3deac0, stream=0xa6bd595c) at /media/Projects/mozilla/thunderbird/mozilla/netwerk/base/src/nsInputStreamPump.cpp:405
#21 0xb541d562 in nsInputStreamReadyEvent::Run (this=0xa6f5c9a0) at /media/Projects/mozilla/thunderbird/mozilla/xpcom/io/nsStreamUtils.cpp:114
#22 0xb543e4f1 in nsThread::ProcessNextEvent (this=0xb734ef20, mayWait=false, result=0xbfd640df) at /media/Projects/mozilla/thunderbird/mozilla/xpcom/threads/nsThread.cpp:656
#23 0xb53d6b72 in NS_ProcessNextEvent_P (thread=0xb734ef20, mayWait=false) at /media/Projects/mozilla/objdir-thunderbird-patches/mozilla/xpcom/build/nsThreadUtils.cpp:245
#24 0xb5280d70 in mozilla::ipc::MessagePump::Run (this=0xb19193d0, aDelegate=0xb731daa0) at /media/Projects/mozilla/thunderbird/mozilla/ipc/glue/MessagePump.cpp:110
#25 0xb548ac78 in MessageLoop::RunInternal (this=0xb731daa0) at /media/Projects/mozilla/thunderbird/mozilla/ipc/chromium/src/base/
#26 0xb548ac03 in MessageLoop::RunHandler (this=0xb731daa0) at /media/Projects/mozilla/thunderbird/mozilla/ipc/chromium/src/base/
#27 0xb548abe5 in MessageLoop::Run (this=0xb731daa0) at /media/Projects/mozilla/thunderbird/mozilla/ipc/chromium/src/base/
#28 0xb4c9ce69 in nsBaseAppShell::Run (this=0xb0552240) at /media/Projects/mozilla/thunderbird/mozilla/widget/xpwidgets/nsBaseAppShell.cpp:189
#29 0xb49e31c2 in nsAppStartup::Run (this=0xb057f8b0) at /media/Projects/mozilla/thunderbird/mozilla/toolkit/components/startup/nsAppStartup.cpp:295
#30 0xb3864a4c in XREMain::XRE_mainRun (this=0xbfd64470) at /media/Projects/mozilla/thunderbird/mozilla/toolkit/xre/nsAppRunner.cpp:3772
#31 0xb3864d31 in XREMain::XRE_main (this=0xbfd64470, argc=1, argv=0xbfd65754, aAppData=0xb7315900) at /media/Projects/mozilla/thunderbird/mozilla/toolkit/xre/nsAppRunner.cpp:3849
#32 0xb3864f50 in XRE_main (argc=1, argv=0xbfd65754, aAppData=0xb7315900) at /media/Projects/mozilla/thunderbird/mozilla/toolkit/xre/nsAppRunner.cpp:3925
#33 0x08049714 in do_main (exePath=0xbfd646ac "/media/Projects/mozilla/objdir-thunderbird-patches/mozilla/dist/bin/", argc=1, argv=0xbfd65754) at /media/Projects/mozilla/thunderbird/mail/app/nsMailApp.cpp:144
#34 0x0804995b in main (argc=1, argv=0xbfd65754) at /media/Projects/mozilla/thunderbird/mail/app/nsMailApp.cpp:233
Comment 1 User image David :Bienvenu 2012-04-10 11:07:40 PDT
we're trying to stream an imap message, perhaps for gloda or the junk filter. So your crash is probably specific to a particular message in your inbox or other imap folder. You could start up offline, and try clicking on messages until you crash, since I suspect you would crash trying to display the message.
Comment 2 User image David :Bienvenu 2012-04-10 15:23:43 PDT
I tried this on the mac on a self-built trunk build. no crash. I also tried explicitly enabling jemalloc, in case it's not on by default on the mac, no luck. And this doesn't crash on windows.
Comment 3 User image Mike Conley (:mconley) 2012-04-17 08:37:06 PDT
This problem mysteriously vanished for me.
Comment 4 User image Mike Conley (:mconley) 2012-04-30 15:44:47 PDT
And now it's back.  :/
Comment 5 User image Mike Conley (:mconley) 2012-05-01 07:48:31 PDT
Argh, and with a rebuild this morning, it's gone again.

Comment 6 User image Mike Conley (:mconley) 2012-05-10 06:02:24 PDT
Still hasn't resurfaced yet. I'll close this until it does.
Comment 8 User image Wayne Mery (:wsmwk, NI for questions) 2012-08-13 12:05:50 PDT
TB15 bp-81e21c6a-dc0e-4a63-b924-835542120730 :)
TB16 bp-ab19419d-555c-42c4-b48c-44e052120810
Comment 9 User image Hiroyuki Ikezoe (:hiro) 2012-08-20 17:29:56 PDT
Created attachment 653590 [details] [diff] [review]
possible fix

delete should be used for the memory allocated with 'new'.
Comment 10 User image Mark Banner (:standard8) 2012-08-21 00:50:48 PDT
Comment on attachment 653590 [details] [diff] [review]
possible fix

r=me by inspection.
Comment 11 User image Mark Banner (:standard8) 2012-08-21 02:53:54 PDT
Interestingly introduced by bug 679476, but didn't seem to show up until the 15 cycle.
Comment 12 User image Mark Banner (:standard8) 2012-08-21 02:54:29 PDT
Comment on attachment 653590 [details] [diff] [review]
possible fix

[Triage Comment]
I want to take this given its a regression, and a simple fix.
Comment 14 User image Mark Banner (:standard8) 2012-08-21 06:31:12 PDT
And bustage fixes for the branches as the nsnull -> nullptr transition hasn't taken place there yet:

Note You need to log in before you can comment on or make changes to this bug.