Closed Bug 97664 Opened 24 years ago Closed 24 years ago

PDT+,Trunk crash [@ nsViewManager::ProcessPendingUpdates]

Categories

(Core :: Web Painting, defect)

x86
Windows NT
defect
Not set
critical

Tracking

()

VERIFIED FIXED
Tracking Status
firefox47 --- affected
firefox48 --- affected
firefox49 --- affected

People

(Reporter: jay, Assigned: kmcclusk)

References

Details

(Keywords: crash, topcrash, Whiteboard: Have review/super-review, Checked fix into the trunk, waiting for approval on the branch)

Crash Data

Attachments

(1 file)

Talkback data is showing a lot of crashes with recent MozillaTrunk builds in nsViewManager::ProcessPendingUpdates 4b3d5b1d http://bonsai.mozilla.org/cvsblame.cgi?file=mozilla/view/src/nsViewManager.cpp line 1638 Here is the latest info from Talkback reports: nsViewManager::ProcessPendingUpdates 30 94546 REOP dcone@netscape.com --- First BBID :34360621 Last BBID :34696599 Min Runtime :22 Max Runtime :83597 First Appearance Date : 2001-08-22 Last Appearance Date : 2001-08-29 First BuildID : 2001082015 Last BuildID : 2001082809 Stack Trace: nsViewManager::ProcessPendingUpdates [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp line 1638] nsViewManager::FlushPendingInvalidates [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp line 3829] nsViewManager::ProcessInvalidateEvent [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp line 3837] nsInvalidateEvent::HandleEvent [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp line 145] PL_HandleEvent [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c line 591] PL_ProcessPendingEvents [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c line 524] _md_EventReceiverProc [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c line 1072] KERNEL32.DLL + 0x24407 (0xbff94407) 0x00688a82 Source File : http://bonsai.mozilla.org/cvsblame.cgi?file=mozilla/view/src/nsViewManager.cpp line : 1638 (34696599) Comments: After clicking ok on the image properties window in composer after I inserted a javascript event I got this error message. (34696500) Comments: I clicked ok on the image properties window while in composer and got this illegal operation (34632132) URL: my.netscape.com (34632132) Comments: canceld a save file as dialog (34619276) Comments: After a download I pressed the "Reveal location" button and while the application was lauching the Windows Explore I pressed the "Close" button on the "Save as" dialog itself.And Mozilla crashed!! (34613842) URL: http://www.pcdirect.be/shop/index.html (34612493) Comments: deleting certificate that was imported. (34593480) Comments: The browser crashes in classic skin while saving the attachment.(commercial trunk: 2001-08-27-06-trunk) (34584077) Comments: deleting certs (34584014) Comments: deleting certs (34580708) Comments: Opened up image properties .. did not put in any text for alternative text clicked ok ... did not click ok to error .. clicked back to image properties. click ok .. got error (34568450) URL: http://www.redhat.co.jp/ (34530768) URL: remix.overclocked.org (34530768) Comments: I was downloading a file I had clicked save and in the save as window Mozilla was running really slow showing like one file coming up per second or even slower.Not sure if its repeatable yet... (34429906) Comments: same damn composer crasher (34426152) URL: http://www.home.netscape.com (34425960) Comments: inserted an image the alt text warning box came up disregarded that box and entered text into the text properties box on the image property box and clicked ok on the image properties box instant crash also happens on windows xp (34425727) Comments: 96649 (34424374) Comments: I was using Composer I was adding an image. I did not put in a alternative text. I did not click ok to the message that comes up to tell me that it is recomended to put in an alternative text I just clicked on the image properties window and put in an (34424374) Comments: altervative text click ok ... and then tried to click ok on the message to put in an alternative text . I have already tried plugging in these latest crashes into bugs 96649 and 94546, but was told this is a new crash in the view system. Hopefully someone will be able to differentiate the latest crashes after 8/24 from the crashes in those other 2 bugs.
Adding crash, topcrash keywords and Trunk [@ nsViewManager::ProcessPendingUpdates] to summary for tracking.
Keywords: crash, topcrash
This is a topcrasher with recent M094/N620 branch builds also. It might be worth looking into for the upcoming release. Here are some recent crashes: Incident ID 35289680 Stack Signature nsViewManager::ProcessPendingUpdates 4b3d5b1d Bug ID Trigger Time 2001-09-12 09:17:45 Email Address marina@netscape.com User Comments quitting send Build ID 2001091205 Product ID Netscape6.20 Platform ID Win32 Trigger Reason Access violation Stack Trace nsViewManager::ProcessPendingUpdates [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 1638] nsViewManager::FlushPendingInvalidates [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 3829] nsViewManager::ProcessInvalidateEvent [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 3837] nsInvalidateEvent::HandleEvent [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 145] PL_HandleEvent [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 591] PL_ProcessPendingEvents [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 524] _md_EventReceiverProc [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 1072] ------------------------------- Incident ID 35259229 Stack Signature nsViewManager::ProcessPendingUpdates f080b377 Bug ID Trigger Time 2001-09-11 14:58:57 Email Address User Comments spell checked automatic, exited the spell chech dialog and immediately tried to close compose window before it sent. crash when clicking on Canel Build ID 2001091006 Product ID Netscape6.20 Platform ID Win32 Trigger Reason Access violation Stack Trace nsViewManager::ProcessPendingUpdates [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 1638] nsViewManager::FlushPendingInvalidates [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 3829] nsViewManager::ProcessInvalidateEvent [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 3837] nsInvalidateEvent::HandleEvent [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 145] PL_HandleEvent [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 591] PL_ProcessPendingEvents [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 524] _md_EventReceiverProc [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 1072] USER32.dll + 0x3d61 (0x77d43d61) USER32.dll + 0x4381 (0x77d44381) nsWebShellWindow::ShowModal [d:\builds\seamonkey\mozilla\xpfe\appshell\src\nsWebShellWindow.cpp, line 1041] nsContentTreeOwner::ShowAsModal [d:\builds\seamonkey\mozilla\xpfe\appshell\src\nsContentTreeOwner.cpp, line 415] nsWindowWatcher::OpenWindowJS [d:\builds\seamonkey\mozilla\embedding\components\windowwatcher\src\nsWindowWatcher.cpp, line 702] nsWindowWatcher::OpenWindow [d:\builds\seamonkey\mozilla\embedding\components\windowwatcher\src\nsWindowWatcher.cpp, line 439] nsPromptService::DoDialog [d:\builds\seamonkey\mozilla\embedding\components\windowwatcher\src\nsPromptService.cpp, line 615] nsPromptService::ConfirmEx [d:\builds\seamonkey\mozilla\embedding\components\windowwatcher\src\nsPromptService.cpp, line 332] XPTC_InvokeByIndex [d:\builds\seamonkey\mozilla\xpcom\reflect\xptcall\src\md\win32\xptcinvoke.cpp, line 139] XPCWrappedNative::CallMethod [d:\builds\seamonkey\mozilla\js\src\xpconnect\src\xpcwrappednative.cpp, line 1954] XPC_WN_CallMethod [d:\builds\seamonkey\mozilla\js\src\xpconnect\src\xpcwrappednativejsops.cpp, line 1263] js_Invoke [d:\builds\seamonkey\mozilla\js\src\jsinterp.c, line 809] js_Interpret [d:\builds\seamonkey\mozilla\js\src\jsinterp.c, line 2720] js_Invoke [d:\builds\seamonkey\mozilla\js\src\jsinterp.c, line 825] js_InternalInvoke [d:\builds\seamonkey\mozilla\js\src\jsinterp.c, line 900] JS_CallFunctionValue [d:\builds\seamonkey\mozilla\js\src\jsapi.c, line 3362] nsJSContext::CallEventHandler [d:\builds\seamonkey\mozilla\dom\src\base\nsJSEnvironment.cpp, line 956] nsJSEventListener::HandleEvent [d:\builds\seamonkey\mozilla\dom\src\events\nsJSEventListener.cpp, line 140] nsEventListenerManager::HandleEventSubType [d:\builds\seamonkey\mozilla\content\events\src\nsEventListenerManager.cpp, line 1197] nsEventListenerManager::HandleEvent [d:\builds\seamonkey\mozilla\content\events\src\nsEventListenerManager.cpp, line 2189] GlobalWindowImpl::HandleDOMEvent [d:\builds\seamonkey\mozilla\dom\src\base\nsGlobalWindow.cpp, line 604] nsWebShellWindow::ExecuteCloseHandler [d:\builds\seamonkey\mozilla\xpfe\appshell\src\nsWebShellWindow.cpp, line 1450] nsWebShellWindow::HandleEvent [d:\builds\seamonkey\mozilla\xpfe\appshell\src\nsWebShellWindow.cpp, line 407] nsWindow::DispatchEvent [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 732] nsWindow::DispatchWindowEvent [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 749] nsWindow::DispatchStandardEvent [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 770] nsWindow::ProcessMessage [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 3004] nsWindow::WindowProc [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 997] USER32.dll + 0x3a50 (0x77d43a50) USER32.dll + 0x3c06 (0x77d43c06) USER32.dll + 0x518d (0x77d4518d) USER32.dll + 0x51c5 (0x77d451c5) ntdll.dll + 0x108f (0x77f5108f) USER32.dll + 0x7287 (0x77d47287) uxtheme.dll + 0x3c0e (0x5ad93c0e) nsWindow::DefaultWindowProc [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 1023] USER32.dll + 0x3a50 (0x77d43a50) USER32.dll + 0x3c06 (0x77d43c06) USER32.dll + 0x57d5 (0x77d457d5) USER32.dll + 0x1c4a1 (0x77d5c4a1) nsWindow::WindowProc [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 1008] USER32.dll + 0x3a50 (0x77d43a50) USER32.dll + 0x3c06 (0x77d43c06) USER32.dll + 0x518d (0x77d4518d) USER32.dll + 0x51c5 (0x77d451c5) ntdll.dll + 0x108f (0x77f5108f) USER32.dll + 0x598b (0x77d4598b) uxtheme.dll + 0x1d942 (0x5adad942) uxtheme.dll + 0x1a71 (0x5ad91a71) uxtheme.dll + 0x3c0e (0x5ad93c0e) nsWindow::DefaultWindowProc [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 1023] USER32.dll + 0x3a50 (0x77d43a50) USER32.dll + 0x3c06 (0x77d43c06) USER32.dll + 0x57d5 (0x77d457d5) USER32.dll + 0x1c4a1 (0x77d5c4a1) nsWindow::WindowProc [d:\builds\seamonkey\mozilla\widget\src\windows\nsWindow.cpp, line 1008] USER32.dll + 0x3a50 (0x77d43a50) ------------------------------------- Incident ID 35218241 Stack Signature nsViewManager::ProcessPendingUpdates 4b3d5b1d Bug ID Trigger Time 2001-09-10 17:00:14 Email Address ssaux@netscape.com User Comments delete a cert Build ID 2001091006 Product ID Netscape6.20 Platform ID Win32 Trigger Reason Access violation Stack Trace nsViewManager::ProcessPendingUpdates [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 1638] nsViewManager::FlushPendingInvalidates [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 3829] nsViewManager::ProcessInvalidateEvent [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 3837] nsInvalidateEvent::HandleEvent [d:\builds\seamonkey\mozilla\view\src\nsViewManager.cpp, line 145] PL_HandleEvent [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 591] PL_ProcessPendingEvents [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 524] _md_EventReceiverProc [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 1072]
cc'ing those that crashes recently for more info.
Note that this is probably related to 95873 which is nsbranch+ I'm able to reproduce 95873 pretty consistently using an existing profile, but not using a brand new profile. Still trying to.
*** Bug 99362 has been marked as a duplicate of this bug. ***
scott, You had nsbranch+ on the bug I just duped with this bug. I am adding nsbranch to the keyword. You might have to + it again. Sorry about that.
Keywords: nsbranch
if we can, I think we want to nail this one on the 0.9.4 branch for the next nscp release.
Keywords: nsbranchnsbranch+
We seem to be trigging a case where all of the views (including the root view) have been destroyed but the viewmanager still exists and pending updates need to be processed. If the viewmanager were destroyed along with the views then the pending updates would have been cancelled. The patch I added simply protects against this by ignoring the request to process the pending updates if the views are gone.
Status: NEW → ASSIGNED
Updated status
Whiteboard: Waiting for review/super-review
Comment on attachment 49407 [details] [diff] [review] Protect against null view in ProcessPendingUpdates r/sr=mscott...which ever one you need. Thanks for the fix Kevin!
*** Bug 95873 has been marked as a duplicate of this bug. ***
*** Bug 91070 has been marked as a duplicate of this bug. ***
Comment on attachment 49407 [details] [diff] [review] Protect against null view in ProcessPendingUpdates r=peterl
Attachment #49407 - Flags: review+
Checked fix into the trunk.
Whiteboard: Waiting for review/super-review → Checked fix into the trunk, waiting for approval on the branch
Comment on attachment 49407 [details] [diff] [review] Protect against null view in ProcessPendingUpdates sr=attinasi for the null-check, but something tells me that it would be better to let the callers check this, and assert that aView is not null. Calling ProcessPendingUpdates with a null view makes no sense.
Attachment #49407 - Flags: superreview+
PDT: The patch is very low risk. Simple check for null pointer before accessing.
Updated status.
Whiteboard: Checked fix into the trunk, waiting for approval on the branch → Have review/superreivew, Checked fix into the trunk, waiting for approval on the branch
Whiteboard: Have review/superreivew, Checked fix into the trunk, waiting for approval on the branch → Have review/super-review, Checked fix into the trunk, waiting for approval on the branch
get is in today - PDT
Summary: Trunk crash [@ nsViewManager::ProcessPendingUpdates] → PDT+,Trunk crash [@ nsViewManager::ProcessPendingUpdates]
Checked fix into Mozilla0.9.4 branch
Status: ASSIGNED → RESOLVED
Closed: 24 years ago
Resolution: --- → FIXED
Verified on 9/19 WinNT branch.
Status: RESOLVED → VERIFIED
*** Bug 97526 has been marked as a duplicate of this bug. ***
*** Bug 101933 has been marked as a duplicate of this bug. ***
Crash Signature: [@ nsViewManager::ProcessPendingUpdates]
Crash volume for signature 'nsViewManager::ProcessPendingUpdates': - nightly(version 50):0 crashes from 2016-06-06. - aurora (version 49):1 crash from 2016-06-07. - beta (version 48):13 crashes from 2016-06-06. - release(version 47):19 crashes from 2016-05-31. - esr (version 45):0 crashes from 2016-04-07. Crash volume on the last weeks: W. N-1 W. N-2 W. N-3 W. N-4 W. N-5 W. N-6 W. N-7 - nightly 0 0 0 0 0 0 0 - aurora 0 0 1 0 0 0 0 - beta 3 2 2 2 1 1 1 - release 2 2 4 2 3 0 3 - esr 0 0 0 0 0 0 0 Affected platform: Windows
Component: Layout: View Rendering → Layout: Web Painting
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: