If you think a bug might affect users in the 57 release, please set the correct tracking and status flags for Release Management.

crash in mozilla::layers::AutoResolveRefLayers::WalkTheTree

VERIFIED FIXED in Firefox 21

Status

Firefox OS
General
--
critical
VERIFIED FIXED
5 years ago
5 years ago

People

(Reporter: m1, Assigned: cjones)

Tracking

({crash})

unspecified
B2G C4 (2jan on)
ARM
Gonk (Firefox OS)
crash

Firefox Tracking Flags

(blocking-b2g:tef+, firefox19 wontfix, firefox20 wontfix, firefox21 fixed, b2g18 fixed, b2g18-v1.0.0 fixed)

Details

(Whiteboard: [b2g-crash][BTG-997], crash signature)

Attachments

(2 attachments)

Created attachment 703704 [details]
decoded minidump of crash

Crash found on AU177.

Reported STR.kk
1. Go to videos and play a video.
2. Try to delete a video from videos.
3. Open the gallery from the camera application.
4. Goto 1

Top frames:
Crash reason:  SIGSEGV
Crash address: 0xc

Thread 10 (crashed)
 0  libxul.so!mozilla::layers::AutoResolveRefLayers::WalkTheTree<(mozilla::layers::AutoResolveRefLayers::Op)0u> [Layers.h : 1006 + 0x0]
     r4 = 0x493bb090    r5 = 0x00000000    r6 = 0x493bb090    r7 = 0x449ced08
     r8 = 0x449ced78    r9 = 0x43830150   r10 = 0x00000001    fp = 0x00000001
     sp = 0x449ce990    lr = 0x411cbfcd    pc = 0x411cc056
    Found by: given as instruction pointer in context
 1  libxul.so!mozilla::layers::AutoResolveRefLayers::WalkTheTree<(mozilla::layers::AutoResolveRefLayers::Op)0u> [CompositorParent.cpp : 497 + 0x9]
     r4 = 0x493bb090    r5 = 0x449ced08    r6 = 0x490dcc90    r7 = 0x449ced08
     r8 = 0x449ced78    r9 = 0x43830150   r10 = 0x00000001    fp = 0x00000001
     sp = 0x449cea10    pc = 0x411cc201
    Found by: call frame info
 2  libxul.so!mozilla::layers::AutoResolveRefLayers::WalkTheTree<(mozilla::layers::AutoResolveRefLayers::Op)0u> [CompositorParent.cpp : 497 + 0x9]
     r4 = 0x490dcc90    r5 = 0x449ced08    r6 = 0x485d2c90    r7 = 0x449ced08
     r8 = 0x449ced78    r9 = 0x43830150   r10 = 0x00000001    fp = 0x00000001
     sp = 0x449cea90    pc = 0x411cc201
    Found by: call frame info
 3  libxul.so!mozilla::layers::AutoResolveRefLayers::WalkTheTree<(mozilla::layers::AutoResolveRefLayers::Op)0u> [CompositorParent.cpp : 497 + 0x9]
     r4 = 0x485d2c90    r5 = 0x449ced08    r6 = 0x4a448490    r7 = 0x449ced08
     r8 = 0x449ced78    r9 = 0x43830150   r10 = 0x00000001    fp = 0x00000001
     sp = 0x449ceb10    pc = 0x411cc201
    Found by: call frame info
 4  libxul.so!mozilla::layers::AutoResolveRefLayers::WalkTheTree<(mozilla::layers::AutoResolveRefLayers::Op)0u> [CompositorParent.cpp : 497 + 0x9]
     r4 = 0x4a448490    r5 = 0x449ced08    r6 = 0x494cd090    r7 = 0x449ced08
     r8 = 0x449ced78    r9 = 0x43830150   r10 = 0x00000001    fp = 0x00000001
     sp = 0x449ceb90    pc = 0x411cc201
    Found by: call frame info
 5  libxul.so!mozilla::layers::AutoResolveRefLayers::WalkTheTree<(mozilla::layers::AutoResolveRefLayers::Op)0u> [CompositorParent.cpp : 497 + 0x9]
     r4 = 0x494cd090    r5 = 0x449ced08    r6 = 0x4945e890    r7 = 0x449ced08
     r8 = 0x449ced78    r9 = 0x43830150   r10 = 0x00000001    fp = 0x00000001
     sp = 0x449cec10    pc = 0x411cc201
    Found by: call frame info
 6  libxul.so!mozilla::layers::CompositorParent::Composite [CompositorParent.cpp : 455 + 0x3]
     r4 = 0x4a0d5c00    r5 = 0x449ced08    r6 = 0x449ced0c    r7 = 0x00000000
     r8 = 0x449ced78    r9 = 0x43830150   r10 = 0x00000001    fp = 0x00000001
     sp = 0x449cec90    pc = 0x411cc27d
    Found by: call frame info
Duplicate of this bug: 829966
Created attachment 703714 [details] [diff] [review]
Check that the referent root is nonnull

It's not illegal for a subtree root to be null.
Assignee: nobody → jones.chris.g
Attachment #703714 - Flags: review?(roc)
blocking-b2g: tef? → tef+
Attachment #703714 - Flags: review?(roc) → review+
https://hg.mozilla.org/integration/mozilla-inbound/rev/765fb43a17a0
https://hg.mozilla.org/releases/mozilla-b2g18/rev/570a64393b8a
Status: NEW → RESOLVED
Last Resolved: 5 years ago
status-b2g18: --- → fixed
status-firefox20: --- → wontfix
status-firefox21: --- → fixed
Resolution: --- → FIXED

Updated

5 years ago
Severity: normal → critical
Crash Signature: [@ mozilla::layers::AutoResolveRefLayers::WalkTheTree<(mozilla::layers::AutoResolveRefLayers::Op)0u>]
Keywords: crash
Whiteboard: [BTG-997] → [b2g-crash][BTG-997]
https://hg.mozilla.org/mozilla-central/rev/765fb43a17a0
status-firefox19: --- → wontfix
Target Milestone: --- → B2G C4 (2jan on)
Landed on mozilla-b2g18/gaia master prior to the 1/25 branching to mozilla-b2g18_v1_0_0/v1.0.0, updating status-b2g-v1.0.0 to fixed.
status-b2g18-v1.0.0: --- → fixed

Comment 7

5 years ago
Unagi Build ID: 20130313070202
Gecko: http://hg.mozilla.org/releases/mozilla-b2g18_v1_0_1/rev/e74dafa6b2d9
Gaia: b34e726147f8e671ad8c538b50900ccfbffcb084
Kernel: Dec 5th

Issue does not reproduce. Crash does not occur.
Status: RESOLVED → VERIFIED
You need to log in before you can comment on or make changes to this bug.