Closed
Bug 758577
Opened 12 years ago
Closed 8 years ago
"ASSERTION: Failed to get script global and holder" with nearNativeStackLimit, window.open, iframe
Categories
(Core :: DOM: Navigation, defect)
Tracking
()
RESOLVED
WORKSFORME
People
(Reporter: jruderman, Unassigned, NeedInfo)
References
Details
(4 keywords, Whiteboard: [fuzzblocker])
Attachments
(2 files, 1 obsolete file)
1. Save the testcase 2. Load it from a file: URL 3. Click the button. ###!!! ASSERTION: This is not supposed to fail!: 'Error', file js/xpconnect/src/nsXPConnect.cpp, line 958 ###!!! ASSERTION: Failed to get script global and holder: 'NS_SUCCEEDED(rv) && newInnerWindow->mJSObject && holder', file dom/base/nsGlobalWindow.cpp, line 1829 4. Close the page. ###!!! ASSERTION: bad param: 'aScope', file js/xpconnect/src/nsXPConnect.cpp, line 1274 Crash in JSAutoEnterCompartment::enter The testcase is about as fragile as it looks. I can reproduce with https://ftp.mozilla.org/pub/mozilla.org/firefox/tinderbox-builds/mozilla-central-macosx64-debug/1337940322/ but not with a local debug build. If you want the testcase to not be fragile, please fix bug 735082 or write me a better nearNativeStackLimit gadget ;)
Reporter | ||
Comment 1•12 years ago
|
||
Reporter | ||
Comment 2•12 years ago
|
||
This might be related to bug 714566.
Reporter | ||
Comment 3•12 years ago
|
||
By manually applying the patch in bug 758986 to a Tinderbox build, I was able to get stack traces for the assertions.
Attachment #627188 -
Attachment is obsolete: true
Comment 4•12 years ago
|
||
guessing sec-moderate simply due to fragility, but I really don't know how bad this assertion is.
Keywords: sec-moderate
Reporter | ||
Updated•10 years ago
|
Whiteboard: [fuzzblocker]
Comment 5•10 years ago
|
||
Jesse, I believe that this should be fixed by bug 1053999. Can you confirm?
Flags: needinfo?(jruderman)
Updated•9 years ago
|
Group: core-security → dom-core-security
Comment 6•8 years ago
|
||
I'll just assume this is fixed, per comment 5. Feel free to reopen.
Status: NEW → RESOLVED
Closed: 8 years ago
Resolution: --- → WORKSFORME
Updated•7 years ago
|
Group: dom-core-security
You need to log in
before you can comment on or make changes to this bug.
Description
•