ASan detected heap-use-after free while running attached test-case. One have to wait ~3 seconds until crash. Crashes both for Linux and Windows. ASan log for rev 3c3a8eed0578.
This feels like a dup.
It looks similar-ish to bug 815500.
Yeah, I was thinking that bug couldn't find the right bug.
Apparently not a dupe of bug 815500, nor bug 815276, since it still crashes in a build with the patches from those bugs.
Assignee: nobody → smontagu
When appending a new textnode to an element which already has its direction determined by some other textnode, we weren't removing the entry in nsTextNodeDirectionalityMap for the old textnode.
Attachment #686694 - Flags: review?(peterv)
is this a Fx20 regression from bug 548206 like bug 815500 and bug 815477? Or is it an older pre-existing problem?
(In reply to Daniel Veditz [:dveditz] from comment #8) > is this a Fx20 regression from bug 548206 like bug 815500 and bug 815477? Yes
Simon is there someone else who could review this patch? I get the feeling Peter is swamped.
Attachment #686694 - Flags: review?(peterv) → review+
marking unaffected for 19 & both esrs as per comment 9
Whiteboard: [asan][adv-main20+] → [asan][adv-main20-]
You need to log in before you can comment on or make changes to this bug.