Open Bug 781594 Opened 8 years ago Updated 6 years ago

ABORT: not reached: ipc/ipdl/PLayers.cpp, line 4069


(Core :: IPC, defect, critical)

Gonk (Firefox OS)
blocking-basecamp -


(Reporter: posidron, Assigned: cyu)


(Blocks 1 open bug)


(Keywords: crash)


Attached file callstack
This crash occurred while launching Firefox on B2G and intercepting the pickle Write|Datatype| functions.

An interception only happened when XRE_GetProcessType() == GeckoProcessType_Content

Let me know if you need further information.
Is this reproducible?
Should this block?
I will look at it in the next days, currently a bit busy with other projects.
But at that time the crash was reproducible.
New IPDL calls have been added to B2G since the last time so the SEED is not correct anymore for this bug. 

Have tried to trigger the bug with new fuzzing runs but were not able to reproduce this particular crash.
Thanks for the update, Christoph.  We can always re-nom this for B2G blocking status if the crash reappears.
Is there a test case for this?
I can reproduce this crash in gdb by modifying mozilla::layers::Edit::mType. I think we need to call FatalError() instead of NS_RUNTIMEABORT() in mozilla::layers::Edit::MaybeDestroy().
