Closed
Bug 983590
Opened 12 years ago
Closed 12 years ago
[Bluetooth] Phone reboots when turning on Bluedroid
Categories
(Firefox OS Graveyard :: Bluetooth, defect)
Tracking
(Not tracked)
RESOLVED
DUPLICATE
of bug 985949
People
(Reporter: tzimmermann, Assigned: tzimmermann)
References
Details
Attachments
(1 file, 1 obsolete file)
|
218.28 KB,
text/plain
|
Details |
We observed crashes when turning on Bluetooth on the Nexus 4. It doesn't happen very often and is hard to reproduce. The rough STR is
- start Nexus 4
- open Settings app
- turn on Bluetooth and touch button at bottom of the screen
Expected:
- BT turns on, Settings app minimized, App switcher is shown
Actual result
- Phone hangs for a second, then reboots
Gecko rev: 173493:f073b3d6db1f
| Assignee | ||
Comment 1•12 years ago
|
||
I managed to get a logcat of the crash, but there isn't anything special happening near the EOF. The crash might either not be related to BT, or happen in the BT libraries.
| Assignee | ||
Comment 2•12 years ago
|
||
I also had gdb attached to the process, but it didn't detect an error.
| Assignee | ||
Comment 3•12 years ago
|
||
Bug 979370 is about to land and changes the initialization of Bluedroid. We should check if the crash is still observable with these patches.
Depends on: 979370
(In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #2)
> I also had gdb attached to the process, but it didn't detect an error.
Or can you enable minidump if gdb always fail to work to catch the crash?
Flags: needinfo?(tzimmermann)
| Assignee | ||
Comment 5•12 years ago
|
||
(In reply to Shawn Huang [:shuang] [:shawnjohnjr] from comment #4)
> (In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #2)
> > I also had gdb attached to the process, but it didn't detect an error.
> Or can you enable minidump if gdb always fail to work to catch the crash?
I don't know this tool. What do I have to do?
Flags: needinfo?(tzimmermann)
| Assignee | ||
Updated•12 years ago
|
Flags: needinfo?(shuang)
First you can reference, as i told the partner before: https://bugzilla.mozilla.org/show_bug.cgi?id=976883#c33
minidump is under /data/b2g/mozilla/Crash Reports/pending, you can adb pull out.
You can see *.dmp file.
And use minidump_stackwalk to parse dmp file and get backtrace.
Flags: needinfo?(shuang)
(In reply to Shawn Huang [:shuang] [:shawnjohnjr] from comment #6)
> First you can reference, as i told the partner before:
> https://bugzilla.mozilla.org/show_bug.cgi?id=976883#c33
>
> minidump is under /data/b2g/mozilla/Crash Reports/pending, you can adb pull
> out.
> You can see *.dmp file.
> And use minidump_stackwalk to parse dmp file and get backtrace.
Sometimes optimization can cause minidump_stackwalk points to wrong place, this is why B2G_NOOPT=1
| Assignee | ||
Comment 8•12 years ago
|
||
Hmm, nothing there. I have a debug build (DEBUG=1, NOOPT=0, PROF=0). Do I need to enabled it specifically?
Well, let's see if dmp file will be created and see if we can parse minidump or not. If we can't parse it, we might need to NOOPT=1. Do I need to turn on/off Bluetooth very fast? I also want to reproduce this bug here.
(In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #8)
> Hmm, nothing there. I have a debug build (DEBUG=1, NOOPT=0, PROF=0). Do I
> need to enabled it specifically?
Ya. MOZ_CRASHREPORTER="1" /system/bin/b2g.sh
You can refer to https://bugzilla.mozilla.org/show_bug.cgi?id=976883#c33
| Assignee | ||
Comment 11•12 years ago
|
||
(In reply to Shawn Huang [:shuang] [:shawnjohnjr] from comment #9)
> Well, let's see if dmp file will be created and see if we can parse minidump
> or not. If we can't parse it, we might need to NOOPT=1. Do I need to turn
> on/off Bluetooth very fast? I also want to reproduce this bug here.
'Very fast'? I don't know for sure. I tried to, but I can't say if it's really necessary. It seems necessary to have other things happening as well though. gwagner mentioned in bug 981239 that garbage collection can have an impact.
| Assignee | ||
Comment 12•12 years ago
|
||
(In reply to Shawn Huang [:shuang] [:shawnjohnjr] from comment #10)
> (In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #8)
> > Hmm, nothing there. I have a debug build (DEBUG=1, NOOPT=0, PROF=0). Do I
> > need to enabled it specifically?
> Ya. MOZ_CRASHREPORTER="1" /system/bin/b2g.sh
>
> You can refer to https://bugzilla.mozilla.org/show_bug.cgi?id=976883#c33
Oh, I see! Thanks for the info. Will try.
| Assignee | ||
Comment 13•12 years ago
|
||
When I switch on Bluetooth on the Nexus 4, I see a segmentation fault. The stack trace is:
Program received signal SIGSEGV, Segmentation fault.
0xb52c7ea2 in CrashReporter::GetPendingDir (dir=0xbeef2ea0) at ../../../../mozilla-central/toolkit/crashreporter/nsExceptionHandler.cpp:2167
2167 MOZ_ASSERT(OOPInitialized());
(gdb) bt
#0 0xb52c7ea2 in CrashReporter::GetPendingDir (dir=0xbeef2ea0) at ../../../../mozilla-central/toolkit/crashreporter/nsExceptionHandler.cpp:2167
#1 0xb52c7f7c in CrashReporter::MoveToPending (dumpFile=0xaeecb080, extraFile=0xaeecb110) at ../../../../mozilla-central/toolkit/crashreporter/nsExceptionHandler.cpp:2386
#2 0xb52c8230 in CrashReporter::CheckForLastRunCrash () at ../../../../mozilla-central/toolkit/crashreporter/nsExceptionHandler.cpp:2699
#3 0xb52c82f4 in CrashReporter::GetLastRunCrashID (id=...) at ../../../../mozilla-central/toolkit/crashreporter/nsExceptionHandler.cpp:2711
#4 0xb52b9f14 in nsXULAppInfo::GetLastRunCrashID (this=<optimized out>, aLastRunCrashID=<optimized out>) at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:864
#5 0xb42f533e in NS_InvokeByIndex (that=<optimized out>, methodIndex=14, paramCount=<optimized out>, params=<optimized out>)
at ../../../../../../../../mozilla-central/xpcom/reflect/xptcall/src/md/unix/xptcinvoke_arm.cpp:164
#6 0xb4a6dbb4 in Invoke (this=0xbeef3028) at ../../../../../mozilla-central/js/xpconnect/src/XPCWrappedNative.cpp:2407
#7 CallMethodHelper::Call (this=0xbeef3028) at ../../../../../mozilla-central/js/xpconnect/src/XPCWrappedNative.cpp:1748
#8 0xb4a6dec0 in XPCWrappedNative::CallMethod (ccx=..., mode=<optimized out>) at ../../../../../mozilla-central/js/xpconnect/src/XPCWrappedNative.cpp:1715
#9 0xb4a70a52 in GetAttribute (ccx=...) at ../../../../../mozilla-central/js/xpconnect/src/xpcprivate.h:2085
#10 XPC_WN_GetterSetter (cx=0xb05db380, argc=0, vp=0xbeef3588) at ../../../../../mozilla-central/js/xpconnect/src/XPCWrappedNativeJSOps.cpp:1316
#11 0xb580015e in js::CallJSNative (cx=0xb05db380, native=0xb4a708e5 <XPC_WN_GetterSetter(JSContext*, unsigned int, JS::Value*)>, args=...)
at ../../../../mozilla-central/js/src/jscntxtinlines.h:239
#12 0xb58015e6 in js::Invoke (cx=0xb05db380, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:476
#13 0xb580cc8a in js::Invoke (cx=0xb05db380, thisv=..., fval=..., argc=<optimized out>, argv=0x0, rval=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:532
#14 0xb580ce76 in js::InvokeGetterOrSetter (cx=<optimized out>, obj=0xafc383a0, fval=..., argc=0, argv=0x0, rval=...)
at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:604
#15 0xb5757450 in js::Shape::get (this=0xae62eec8, cx=0xb05db380, receiver=..., obj=<optimized out>, pobj=0xafc383a0, vp=...)
at ../../../../mozilla-central/js/src/vm/Shape-inl.h:46
#16 0xb5757516 in NativeGetInline<(js::AllowGC)1> (cx=0xb05db380, obj=..., receiver=..., pobj=..., shape=..., vp=...) at ../../../../mozilla-central/js/src/jsobj.cpp:4344
#17 0xb575776c in GetPropertyHelperInline<(js::AllowGC)1> (cx=<optimized out>, obj=..., receiver=..., id=..., vp=...) at ../../../../mozilla-central/js/src/jsobj.cpp:4541
#18 0xb5807ade in getGeneric (vp=<optimized out>, id=<optimized out>, receiver=<optimized out>, obj=..., cx=<optimized out>)
at ../../../../mozilla-central/js/src/jsobj.h:1001
#19 GetPropertyOperation (vp=..., lval=<optimized out>, pc=<optimized out>, script=<optimized out>, fp=<optimized out>, cx=<optimized out>)
at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:266
#20 Interpret (cx=0xb05db380, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:2409
#21 0xb580c3c6 in js::RunScript (cx=0xb05db380, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:423
#22 0xb580154c in RunScript (state=..., cx=0xb05db380) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:390
#23 js::Invoke (cx=0xb05db380, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:495
#24 0xb580cc8a in js::Invoke (cx=0xb05db380, thisv=..., fval=..., argc=<optimized out>, argv=0xbeef40f0, rval=...)
at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:532
#25 0xb56df198 in JS::Call (cx=0xb05db380, thisv=..., fval=..., args=<optimized out>, rval=...) at ../../../../mozilla-central/js/src/jsapi.cpp:4901
#26 0xb483f354 in mozilla::dom::EventListener::HandleEvent (this=<optimized out>, cx=0xb05db380, aThisVal=<optimized out>, event=..., aRv=...) at EventListenerBinding.cpp:44
#27 0xb4b68d24 in mozilla::dom::EventListener::HandleEvent<mozilla::dom::EventTarget*> (this=0xadc8b820, thisObjPtr=<optimized out>, event=..., aRv=...,
aExceptionHandling=mozilla::dom::CallbackObject::eReportExceptions) at ../../dist/include/mozilla/dom/EventListenerBinding.h:53
#28 0xb4b68de4 in mozilla::EventListenerManager::HandleEventSubType (this=0xae1eabe0, aListener=<optimized out>, aDOMEvent=0xaf591e80, aCurrentTarget=0xae4c3c10)
at ../../../../mozilla-central/dom/events/EventListenerManager.cpp:969
#29 0xb4b68f5a in mozilla::EventListenerManager::HandleEventInternal (this=0xae1eabe0, aPresContext=0xafedac00, aEvent=0xaf5b6560, aDOMEvent=0xbeef43d8,
aCurrentTarget=0xae4c3c10, aEventStatus=0xbeef43dc) at ../../../../mozilla-central/dom/events/EventListenerManager.cpp:1033
#30 0xb4b64774 in HandleEvent (aEventStatus=0xbeef43dc, aCurrentTarget=0xae4c3c10, aDOMEvent=0xbeef43d8, aEvent=<optimized out>, aPresContext=<optimized out>,
this=<optimized out>) at ../../dist/include/mozilla/EventListenerManager.h:328
---Type <return> to continue, or q <return> to quit---
#31 mozilla::EventTargetChainItem::HandleEvent (this=<optimized out>, aVisitor=..., aCd=<optimized out>) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:197
#32 0xb4b652b4 in mozilla::EventTargetChainItem::HandleEventTargetChain (aChain=..., aVisitor=..., aCallback=0x0, aCd=...)
at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:287
#33 0xb4b65bb8 in mozilla::EventDispatcher::Dispatch (aTarget=<optimized out>, aPresContext=0xafedac00, aEvent=0xaf5b6560, aDOMEvent=0xaf591e80, aEventStatus=0xbeef447c,
aCallback=0x0, aTargets=0x0) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:598
#34 0xb4b65e26 in mozilla::EventDispatcher::DispatchDOMEvent (aTarget=0xae4c3c10, aEvent=<optimized out>, aDOMEvent=0xaf591e80, aPresContext=0xafedac00,
aEventStatus=0xbeef447c) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:665
#35 0xb4d4227a in nsINode::DispatchEvent (this=0xae4c3c10, aEvent=0xaf591e80, aRetVal=0xbeef449f) at ../../../../../mozilla-central/content/base/src/nsINode.cpp:1165
#36 0xb4d407f8 in mozilla::dom::EventTarget::DispatchEvent (this=<optimized out>, aEvent=<optimized out>, aRv=...)
at ../../../../../mozilla-central/content/base/src/nsINode.cpp:2639
#37 0xb4839f68 in dispatchEvent (args=..., self=0xae4c3c10, cx=0xb6ad2240, obj=<optimized out>) at EventTargetBinding.cpp:167
#38 mozilla::dom::EventTargetBinding::dispatchEvent (cx=0xb6ad2240, obj=<optimized out>, self=0xae4c3c10, args=...) at EventTargetBinding.cpp:146
#39 0xb483a15c in mozilla::dom::EventTargetBinding::genericMethod (cx=0xb6ad2240, argc=<optimized out>, vp=<optimized out>) at EventTargetBinding.cpp:344
#40 0xb580015e in js::CallJSNative (cx=0xb6ad2240, native=0xb4839ffd <mozilla::dom::EventTargetBinding::genericMethod(JSContext*, unsigned int, JS::Value*)>, args=...)
at ../../../../mozilla-central/js/src/jscntxtinlines.h:239
#41 0xb58015e6 in js::Invoke (cx=0xb6ad2240, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:476
#42 0xb580cc8a in js::Invoke (cx=0xb6ad2240, thisv=..., fval=..., argc=<optimized out>, argv=0xb1f1f0e8, rval=...)
at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:532
#43 0xb577c818 in js::DirectProxyHandler::call (this=<optimized out>, cx=<optimized out>, proxy=<optimized out>, args=...)
at ../../../../mozilla-central/js/src/jsproxy.cpp:465
#44 0xb57c0260 in js::CrossCompartmentWrapper::call (this=0xb6543518, cx=0xb6ad2240, wrapper=..., args=...) at ../../../../mozilla-central/js/src/jswrapper.cpp:465
#45 0xb577c0b2 in js::Proxy::call (cx=<optimized out>, proxy=..., args=...) at ../../../../mozilla-central/js/src/jsproxy.cpp:2637
#46 0xb577c164 in js::proxy_Call (cx=0xb6ad2240, argc=<optimized out>, vp=<optimized out>) at ../../../../mozilla-central/js/src/jsproxy.cpp:3040
#47 0xb580015e in js::CallJSNative (cx=0xb6ad2240, native=0xb577c10d <js::proxy_Call(JSContext*, unsigned int, JS::Value*)>, args=...)
at ../../../../mozilla-central/js/src/jscntxtinlines.h:239
#48 0xb58016b0 in js::Invoke (cx=0xb6ad2240, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:469
#49 0xb5802908 in Interpret (cx=0xb6ad2240, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:2614
#50 0xb580c3c6 in js::RunScript (cx=0xb6ad2240, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:423
#51 0xb580154c in RunScript (state=..., cx=0xb6ad2240) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:390
#52 js::Invoke (cx=0xb6ad2240, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:495
#53 0xb5719b34 in js_fun_apply (cx=0xb6ad2240, argc=<optimized out>, vp=0xb1f1f058) at ../../../../mozilla-central/js/src/jsfun.cpp:1010
#54 0xb580015e in js::CallJSNative (cx=0xb6ad2240, native=0xb5719a19 <js_fun_apply(JSContext*, unsigned int, JS::Value*)>, args=...)
at ../../../../mozilla-central/js/src/jscntxtinlines.h:239
#55 0xb58015e6 in js::Invoke (cx=0xb6ad2240, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:476
#56 0xb5802908 in Interpret (cx=0xb6ad2240, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:2614
#57 0xb580c3c6 in js::RunScript (cx=0xb6ad2240, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:423
#58 0xb580154c in RunScript (state=..., cx=0xb6ad2240) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:390
#59 js::Invoke (cx=0xb6ad2240, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:495
#60 0xb580cc8a in js::Invoke (cx=0xb6ad2240, thisv=..., fval=..., argc=<optimized out>, argv=0xbeef6698, rval=...)
at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:532
#61 0xb56df094 in JS_CallFunctionValue (cx=0xb6ad2240, obj=<optimized out>, fval=..., args=..., rval=...) at ../../../../mozilla-central/js/src/jsapi.cpp:4889
#62 0xb4d38356 in nsFrameMessageManager::ReceiveMessage (this=0xae1eab20, aTarget=0xae4c3c10, aMessage=..., aIsSync=<optimized out>, aCloneData=0xbeef6748,
---Type <return> to continue, or q <return> to quit---
aCpows=0xbeef6754, aPrincipal=0x0, aJSONRetVal=0x0) at ../../../../../mozilla-central/content/base/src/nsFrameMessageManager.cpp:1046
#63 0xb4d38fee in nsSameProcessAsyncMessageBase::ReceiveMessage (this=0xaf591b0c, aTarget=0xae4c3c10, aManager=0xae1eab20)
at ../../../../../mozilla-central/content/base/src/nsFrameMessageManager.cpp:1958
#64 0xb4d466ca in Run (this=0xaf591b00) at ../../../../../mozilla-central/content/base/src/nsInProcessTabChildGlobal.cpp:77
#65 nsAsyncMessageToParent::Run (this=0xaf591b00) at ../../../../../mozilla-central/content/base/src/nsInProcessTabChildGlobal.cpp:69
#66 0xb42f086a in ProcessNextEvent (result=0xbeef67f7, mayWait=false, this=0xb6a34780) at ../../../../mozilla-central/xpcom/threads/nsThread.cpp:694
#67 nsThread::ProcessNextEvent (this=0xb6a34780, mayWait=<optimized out>, result=0xbeef67f7) at ../../../../mozilla-central/xpcom/threads/nsThread.cpp:618
#68 0xb42aa8b8 in NS_ProcessNextEvent (thread=0xb6a34780, mayWait=<optimized out>) at ../../../../mozilla-central/xpcom/glue/nsThreadUtils.cpp:263
#69 0xb449dd14 in mozilla::ipc::MessagePump::Run (this=0xb6a01e80, aDelegate=0xb6a4e1a0) at ../../../../mozilla-central/ipc/glue/MessagePump.cpp:95
#70 0xb448b292 in MessageLoop::RunInternal (this=0xb6a4e1a0) at ../../../../mozilla-central/ipc/chromium/src/base/message_loop.cc:226
#71 0xb448b2aa in RunHandler (this=0xb6a4e1a0) at ../../../../mozilla-central/ipc/chromium/src/base/message_loop.cc:219
#72 MessageLoop::Run (this=0xb6a4e1a0) at ../../../../mozilla-central/ipc/chromium/src/base/message_loop.cc:193
#73 0xb4a17f3a in nsBaseAppShell::Run (this=0xb1f49940) at ../../../../mozilla-central/widget/xpwidgets/nsBaseAppShell.cpp:164
#74 0xb52ecb6e in nsAppStartup::Run (this=0xb6aedca0) at ../../../../../mozilla-central/toolkit/components/startup/nsAppStartup.cpp:276
#75 0xb52bec2e in XREMain::XRE_mainRun (this=0xbeef698c) at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:4010
#76 0xb52beea4 in XREMain::XRE_main (this=0xbeef698c, argc=<optimized out>, argv=<optimized out>, aAppData=<optimized out>)
at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:4079
#77 0xb52bf014 in XRE_main (argc=1, argv=0xbeef8b44, aAppData=0x26908, aFlags=<optimized out>) at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:4291
#78 0x0000a4ec in do_main (argv=0xbeef8b44, argc=1) at ../../../../mozilla-central/b2g/app/nsBrowserApp.cpp:163
#79 main (argc=<optimized out>, argv=<optimized out>) at ../../../../mozilla-central/b2g/app/nsBrowserApp.cpp:256
(gdb)
This is known issue. See bug 820716
(In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #13)
> When I switch on Bluetooth on the Nexus 4, I see a segmentation fault. The
> stack trace is:
> Program received signal SIGSEGV, Segmentation fault.
> 0xb52c7ea2 in CrashReporter::GetPendingDir (dir=0xbeef2ea0) at
> ../../../../mozilla-central/toolkit/crashreporter/nsExceptionHandler.cpp:2167
> 2167 MOZ_ASSERT(OOPInitialized());
This is known issue. See bug 820716. I can still hit this bug all the time. :(
| Assignee | ||
Comment 16•12 years ago
|
||
Program received signal SIGSEGV, Segmentation fault.
0xb4a39f52 in ~already_AddRefed (this=<optimized out>, __in_chrg=<optimized out>) at ../../dist/include/nsCOMPtr.h:177
177 MOZ_ASSERT(!mRawPtr);
(gdb) bt
#0 0xb4a39f52 in ~already_AddRefed (this=<optimized out>, __in_chrg=<optimized out>) at ../../dist/include/nsCOMPtr.h:177
#1 mozilla::dom::bluetooth::BluetoothServiceBluedroid::GetDefaultAdapterPathInternal (this=<optimized out>, aRunnable=<optimized out>)
at ../../../../mozilla-central/dom/bluetooth/bluedroid/BluetoothServiceBluedroid.cpp:804
#2 0xb4a2c6b0 in mozilla::dom::bluetooth::BluetoothManager::GetDefaultAdapter (this=<optimized out>, aRv=...)
at ../../../../mozilla-central/dom/bluetooth/BluetoothManager.cpp:157
#3 0xb46baee8 in mozilla::dom::BluetoothManagerBinding::getDefaultAdapter (cx=0xae7de2e0, obj=<optimized out>, self=<optimized out>, args=...)
at BluetoothManagerBinding.cpp:283
#4 0xb48af570 in mozilla::dom::GenericBindingMethod (cx=0xae7de2e0, argc=<optimized out>, vp=<optimized out>)
at ../../../../mozilla-central/dom/bindings/BindingUtils.cpp:2276
#5 0xb570015e in js::CallJSNative (cx=0xae7de2e0, native=0xb48af4b5 <mozilla::dom::GenericBindingMethod(JSContext*, unsigned int, JS::Value*)>, args=...)
at ../../../../mozilla-central/js/src/jscntxtinlines.h:239
#6 0xb57015e6 in js::Invoke (cx=0xae7de2e0, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:476
#7 0xb5702908 in Interpret (cx=0xae7de2e0, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:2614
#8 0xb570c3c6 in js::RunScript (cx=0xae7de2e0, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:423
#9 0xb570154c in RunScript (state=..., cx=0xae7de2e0) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:390
#10 js::Invoke (cx=0xae7de2e0, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:495
#11 0xb570cc8a in js::Invoke (cx=0xae7de2e0, thisv=..., fval=..., argc=<optimized out>, argv=0xbefabf80, rval=...)
at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:532
#12 0xb55df198 in JS::Call (cx=0xae7de2e0, thisv=..., fval=..., args=<optimized out>, rval=...) at ../../../../mozilla-central/js/src/jsapi.cpp:4901
#13 0xb473f354 in mozilla::dom::EventListener::HandleEvent (this=<optimized out>, cx=0xae7de2e0, aThisVal=<optimized out>, event=..., aRv=...) at EventListenerBinding.cpp:44
#14 0xb4a68d24 in mozilla::dom::EventListener::HandleEvent<mozilla::dom::EventTarget*> (this=0xaf5f4ea0, thisObjPtr=<optimized out>, event=..., aRv=...,
aExceptionHandling=mozilla::dom::CallbackObject::eReportExceptions) at ../../dist/include/mozilla/dom/EventListenerBinding.h:53
#15 0xb4a68de4 in mozilla::EventListenerManager::HandleEventSubType (this=0xadf45580, aListener=<optimized out>, aDOMEvent=0xad589e00, aCurrentTarget=0xae220d80)
at ../../../../mozilla-central/dom/events/EventListenerManager.cpp:969
#16 0xb4a68f5a in mozilla::EventListenerManager::HandleEventInternal (this=0xadf45580, aPresContext=0xaeb92800, aEvent=0xadb665b0, aDOMEvent=0xbefac268,
aCurrentTarget=0xae220d80, aEventStatus=0xbefac26c) at ../../../../mozilla-central/dom/events/EventListenerManager.cpp:1033
#17 0xb4a64774 in HandleEvent (aEventStatus=0xbefac26c, aCurrentTarget=0xae220d80, aDOMEvent=0xbefac268, aEvent=<optimized out>, aPresContext=<optimized out>,
this=<optimized out>) at ../../dist/include/mozilla/EventListenerManager.h:328
#18 mozilla::EventTargetChainItem::HandleEvent (this=<optimized out>, aVisitor=..., aCd=<optimized out>) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:197
#19 0xb4a652b4 in mozilla::EventTargetChainItem::HandleEventTargetChain (aChain=..., aVisitor=..., aCallback=0x0, aCd=...)
at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:287
#20 0xb4a65bb8 in mozilla::EventDispatcher::Dispatch (aTarget=<optimized out>, aPresContext=0xaeb92800, aEvent=0xadb665b0, aDOMEvent=0xad589e00, aEventStatus=0xbefac30c,
aCallback=0x0, aTargets=0x0) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:598
#21 0xb4a65e26 in mozilla::EventDispatcher::DispatchDOMEvent (aTarget=0xae21fad0, aEvent=<optimized out>, aDOMEvent=0xad589e00, aPresContext=0xaeb92800,
aEventStatus=0xbefac30c) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:665
#22 0xb49d5474 in DispatchEvent (aRetVal=0xbefac32f, aEvent=0xad589e00, this=0xae220d80) at ../../../../mozilla-central/dom/base/nsGlobalWindow.cpp:9198
#23 nsGlobalWindow::DispatchEvent (this=0xae220d80, aEvent=0xad589e00, aRetVal=0xbefac32f) at ../../../../mozilla-central/dom/base/nsGlobalWindow.cpp:9173
#24 0xb4c407f8 in mozilla::dom::EventTarget::DispatchEvent (this=<optimized out>, aEvent=<optimized out>, aRv=...)
at ../../../../../mozilla-central/content/base/src/nsINode.cpp:2639
#25 0xb4739f68 in dispatchEvent (args=..., self=0xae220d80, cx=0xae7de2e0, obj=<optimized out>) at EventTargetBinding.cpp:167
#26 mozilla::dom::EventTargetBinding::dispatchEvent (cx=0xae7de2e0, obj=<optimized out>, self=0xae220d80, args=...) at EventTargetBinding.cpp:146
#27 0xb473a15c in mozilla::dom::EventTargetBinding::genericMethod (cx=0xae7de2e0, argc=<optimized out>, vp=<optimized out>) at EventTargetBinding.cpp:344
---Type <return> to continue, or q <return> to quit---
#28 0xb570015e in js::CallJSNative (cx=0xae7de2e0, native=0xb4739ffd <mozilla::dom::EventTargetBinding::genericMethod(JSContext*, unsigned int, JS::Value*)>, args=...)
at ../../../../mozilla-central/js/src/jscntxtinlines.h:239
#29 0xb57015e6 in js::Invoke (cx=0xae7de2e0, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:476
#30 0xb5702908 in Interpret (cx=0xae7de2e0, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:2614
#31 0xb570c3c6 in js::RunScript (cx=0xae7de2e0, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:423
#32 0xb570154c in RunScript (state=..., cx=0xae7de2e0) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:390
#33 js::Invoke (cx=0xae7de2e0, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:495
#34 0xb570cc8a in js::Invoke (cx=0xae7de2e0, thisv=..., fval=..., argc=<optimized out>, argv=0xbefad0c0, rval=...)
at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:532
#35 0xb55df198 in JS::Call (cx=0xae7de2e0, thisv=..., fval=..., args=<optimized out>, rval=...) at ../../../../mozilla-central/js/src/jsapi.cpp:4901
#36 0xb473f81a in mozilla::dom::EventHandlerNonNull::Call (this=0xaf50d200, cx=0xae7de2e0, aThisVal=..., event=..., aRv=...) at EventHandlerBinding.cpp:36
#37 0xb4a76ec2 in mozilla::dom::EventHandlerNonNull::Call<nsISupports*> (this=0xaf50d200, thisObjPtr=<optimized out>, event=..., aRv=...,
aExceptionHandling=mozilla::dom::CallbackObject::eReportExceptions) at ../../dist/include/mozilla/dom/EventHandlerBinding.h:62
#38 0xb4a772be in nsJSEventListener::HandleEvent (this=0xaf50d220, aEvent=0xad5a3a30) at ../../../../mozilla-central/dom/events/nsJSEventListener.cpp:235
#39 0xb4a68dfc in mozilla::EventListenerManager::HandleEventSubType (this=0xaf233400, aListener=<optimized out>, aDOMEvent=0xad5a3a30, aCurrentTarget=0xad58f040)
at ../../../../mozilla-central/dom/events/EventListenerManager.cpp:972
#40 0xb4a68f5a in mozilla::EventListenerManager::HandleEventInternal (this=0xaf233400, aPresContext=0x0, aEvent=0xadb66560, aDOMEvent=0xbefad4d8, aCurrentTarget=0xad58f040,
aEventStatus=0xbefad4dc) at ../../../../mozilla-central/dom/events/EventListenerManager.cpp:1033
#41 0xb4a64774 in HandleEvent (aEventStatus=0xbefad4dc, aCurrentTarget=0xad58f040, aDOMEvent=0xbefad4d8, aEvent=<optimized out>, aPresContext=<optimized out>,
this=<optimized out>) at ../../dist/include/mozilla/EventListenerManager.h:328
#42 mozilla::EventTargetChainItem::HandleEvent (this=<optimized out>, aVisitor=..., aCd=<optimized out>) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:197
#43 0xb4a652b4 in mozilla::EventTargetChainItem::HandleEventTargetChain (aChain=..., aVisitor=..., aCallback=0x0, aCd=...)
at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:287
#44 0xb4a65bb8 in mozilla::EventDispatcher::Dispatch (aTarget=<optimized out>, aPresContext=0x0, aEvent=0xadb66560, aDOMEvent=0xad5a3a30, aEventStatus=0xbefad57c,
aCallback=0x0, aTargets=0x0) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:598
#45 0xb4a65e26 in mozilla::EventDispatcher::DispatchDOMEvent (aTarget=0xad58f040, aEvent=<optimized out>, aDOMEvent=0xad5a3a30, aPresContext=0x0, aEventStatus=0xbefad57c)
at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:665
#46 0xb4a26438 in nsWindowRoot::DispatchEvent (this=<optimized out>, aEvt=0xad5a3a30, aRetVal=0xbefad597) at ../../../../mozilla-central/dom/base/nsWindowRoot.cpp:80
#47 0xb4a759a4 in nsDOMEventTargetHelper::DispatchTrustedEvent (this=0xad58f040, event=0xad5a3a30) at ../../../../mozilla-central/dom/events/nsDOMEventTargetHelper.cpp:268
#48 0xb4a76334 in nsDOMEventTargetHelper::DispatchTrustedEvent (this=0xad58f040, aEventName=...) at ../../../../mozilla-central/dom/events/nsDOMEventTargetHelper.cpp:259
#49 0xb4a2bf1a in mozilla::dom::bluetooth::BluetoothManager::Notify (this=0xad58f040, aData=...) at ../../../../mozilla-central/dom/bluetooth/BluetoothManager.cpp:206
#50 0xb4a2e9e8 in Broadcast (aParam=<optimized out>, this=<optimized out>) at ../../dist/include/mozilla/Observer.h:67
#51 mozilla::dom::bluetooth::BluetoothService::DistributeSignal (this=<optimized out>, aSignal=...) at ../../../../mozilla-central/dom/bluetooth/BluetoothService.cpp:392
#52 0xb4a2eafe in mozilla::dom::bluetooth::BluetoothService::TryFiringAdapterAdded (this=0xb2088e80) at ../../../../mozilla-central/dom/bluetooth/BluetoothService.cpp:786
#53 0xb4a3834c in SetupAfterEnabledTask::Run (this=<optimized out>) at ../../../../mozilla-central/dom/bluetooth/bluedroid/BluetoothServiceBluedroid.cpp:117
#54 0xb41f086a in ProcessNextEvent (result=0xbefad7f7, mayWait=false, this=0xb6a34780) at ../../../../mozilla-central/xpcom/threads/nsThread.cpp:694
#55 nsThread::ProcessNextEvent (this=0xb6a34780, mayWait=<optimized out>, result=0xbefad7f7) at ../../../../mozilla-central/xpcom/threads/nsThread.cpp:618
#56 0xb41aa8b8 in NS_ProcessNextEvent (thread=0xb6a34780, mayWait=<optimized out>) at ../../../../mozilla-central/xpcom/glue/nsThreadUtils.cpp:263
#57 0xb439dd14 in mozilla::ipc::MessagePump::Run (this=0xb6a01e80, aDelegate=0xb6a4e1a0) at ../../../../mozilla-central/ipc/glue/MessagePump.cpp:95
#58 0xb438b292 in MessageLoop::RunInternal (this=0xb6a4e1a0) at ../../../../mozilla-central/ipc/chromium/src/base/message_loop.cc:226
#59 0xb438b2aa in RunHandler (this=0xb6a4e1a0) at ../../../../mozilla-central/ipc/chromium/src/base/message_loop.cc:219
#60 MessageLoop::Run (this=0xb6a4e1a0) at ../../../../mozilla-central/ipc/chromium/src/base/message_loop.cc:193
---Type <return> to continue, or q <return> to quit---
#61 0xb4917f3a in nsBaseAppShell::Run (this=0xb1e498e0) at ../../../../mozilla-central/widget/xpwidgets/nsBaseAppShell.cpp:164
#62 0xb51ecb6e in nsAppStartup::Run (this=0xb205ddf0) at ../../../../../mozilla-central/toolkit/components/startup/nsAppStartup.cpp:276
#63 0xb51bec2e in XREMain::XRE_mainRun (this=0xbefad98c) at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:4010
#64 0xb51beea4 in XREMain::XRE_main (this=0xbefad98c, argc=<optimized out>, argv=<optimized out>, aAppData=<optimized out>)
at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:4079
#65 0xb51bf014 in XRE_main (argc=1, argv=0xbefafb44, aAppData=0x26908, aFlags=<optimized out>) at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:4291
#66 0x0000a4ec in do_main (argv=0xbefafb44, argc=1) at ../../../../mozilla-central/b2g/app/nsBrowserApp.cpp:163
#67 main (argc=<optimized out>, argv=<optimized out>) at ../../../../mozilla-central/b2g/app/nsBrowserApp.cpp:256
(gdb)
Assignee: nobody → tzimmermann
Status: NEW → ASSIGNED
| Assignee | ||
Comment 17•12 years ago
|
||
This looks like more fallout from bug 967364.
| Assignee | ||
Comment 18•12 years ago
|
||
Gregor, does this fix the crash for you?
Eric, this changes makes the code work as before. But it looks to me as if the forget call should not be there in the first place, and we're currently leaking the runnable.
Attachment #8394676 -
Flags: review?(echou)
Attachment #8394676 -
Flags: feedback?(anygregor)
Comment 19•12 years ago
|
||
(In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #18)
> Created attachment 8394676 [details] [diff] [review]
> [01] Bug 983590: Correctly forget pointer references in Bluedroid backend
>
> Gregor, does this fix the crash for you?
>
> Eric, this changes makes the code work as before. But it looks to me as if
> the forget call should not be there in the first place, and we're currently
> leaking the runnable.
Hm I don't see how this can fix anything. Maybe a compiler warning but that's about it.
Comment 20•12 years ago
|
||
Can you explain what you think is different with your patch?
Comment 21•12 years ago
|
||
Today I got this after opening the settings app:
bt
#0 0xb4b53776 in ~already_AddRefed (this=<optimized out>, __in_chrg=<optimized out>) at ../../dist/include/nsCOMPtr.h:165
#1 mozilla::dom::bluetooth::BluetoothServiceBluedroid::GetDefaultAdapterPathInternal (this=<optimized out>, aRunnable=<optimized out>)
at ../../../dom/bluetooth/bluedroid/BluetoothServiceBluedroid.cpp:804
#2 0xb4b4ab66 in mozilla::dom::bluetooth::BluetoothRequestParent::DoRequest (this=0xad83d310, aRequest=<optimized out>) at ../../../dom/bluetooth/ipc/BluetoothParent.cpp:311
#3 0xb44caefa in mozilla::dom::bluetooth::PBluetoothParent::OnMessageReceived (this=0xad87b220, __msg=<optimized out>) at PBluetoothParent.cpp:413
#4 0xb44f632e in mozilla::dom::PContentParent::OnMessageReceived (this=0xad0c2c00, __msg=...) at PContentParent.cpp:2012
#5 0xb44a0998 in mozilla::ipc::MessageChannel::DispatchAsyncMessage (this=0xad0c2c30, aMsg=...) at ../../../ipc/glue/MessageChannel.cpp:1142
#6 0xb44a3a48 in mozilla::ipc::MessageChannel::OnMaybeDequeueOne (this=0xad0c2c30) at ../../../ipc/glue/MessageChannel.cpp:1039
#7 0xb44a03a4 in DispatchToMethod<mozilla::ipc::MessageChannel, void (mozilla::ipc::MessageChannel::*)()> (method=
(void (mozilla::ipc::MessageChannel::*)(mozilla::ipc::MessageChannel * const)) 0xb44a39b5 <mozilla::ipc::MessageChannel::OnMaybeDequeueOne()>, obj=<optimized out>, arg=<optimized out>)
at ../../../ipc/chromium/src/base/tuple.h:383
#8 RunnableMethod<mozilla::ipc::MessageChannel, void (mozilla::ipc::MessageChannel::*)(), Tuple0>::Run (this=<optimized out>) at ../../../ipc/chromium/src/base/task.h:307
#9 0xb44a0e1c in Run (this=<optimized out>) at ../../dist/include/mozilla/ipc/MessageChannel.h:383
#10 mozilla::ipc::MessageChannel::DequeueTask::Run (this=<optimized out>) at ../../dist/include/mozilla/ipc/MessageChannel.h:400
#11 0xb4492344 in MessageLoop::RunTask (this=0xb6a4e1a0, task=0xadc5bf80) at ../../../ipc/chromium/src/base/message_loop.cc:344
#12 0xb4492c82 in MessageLoop::DeferOrRunPendingTask (this=<optimized out>, pending_task=<optimized out>) at ../../../ipc/chromium/src/base/message_loop.cc:352
#13 0xb4493d7e in DoWork (this=<optimized out>) at ../../../ipc/chromium/src/base/message_loop.cc:430
#14 MessageLoop::DoWork (this=0xb6a4e1a0) at ../../../ipc/chromium/src/base/message_loop.cc:409
#15 0xb44a4a9e in mozilla::ipc::DoWorkRunnable::Run (this=<optimized out>) at ../../../ipc/glue/MessagePump.cpp:228
#16 0xb42f7ca2 in ProcessNextEvent (result=0xbec787f7, mayWait=false, this=0xb6a34680) at ../../../xpcom/threads/nsThread.cpp:694
#17 nsThread::ProcessNextEvent (this=0xb6a34680, mayWait=<optimized out>, result=0xbec787f7) at ../../../xpcom/threads/nsThread.cpp:618
#18 0xb42b1dd0 in NS_ProcessNextEvent (thread=0xb6a34680, mayWait=<optimized out>) at ../../../xpcom/glue/nsThreadUtils.cpp:263
#19 0xb44a4ee8 in mozilla::ipc::MessagePump::Run (this=0xb6a01df0, aDelegate=0xb6a4e1a0) at ../../../ipc/glue/MessagePump.cpp:95
#20 0xb449248a in MessageLoop::RunInternal (this=0xb6a4e1a0) at ../../../ipc/chromium/src/base/message_loop.cc:226
#21 0xb44924a2 in RunHandler (this=0xb6a4e1a0) at ../../../ipc/chromium/src/base/message_loop.cc:219
#22 MessageLoop::Run (this=0xb6a4e1a0) at ../../../ipc/chromium/src/base/message_loop.cc:193
#23 0xb4a30e4a in nsBaseAppShell::Run (this=0xb1f418e0) at ../../../widget/xpwidgets/nsBaseAppShell.cpp:164
#24 0xb5300dae in nsAppStartup::Run (this=0xb214fca0) at ../../../../toolkit/components/startup/nsAppStartup.cpp:276
#25 0xb52da7aa in XREMain::XRE_mainRun (this=0xbec7898c) at ../../../toolkit/xre/nsAppRunner.cpp:4008
#26 0xb52da9aa in XREMain::XRE_main (this=0xbec7898c, argc=<optimized out>, argv=<optimized out>, aAppData=<optimized out>) at ../../../toolkit/xre/nsAppRunner.cpp:4077
#27 0xb52dab00 in XRE_main (argc=1, argv=0xbec7ab44, aAppData=0x26908, aFlags=<optimized out>) at ../../../toolkit/xre/nsAppRunner.cpp:4289
#28 0x0000a4ec in do_main (argv=0xbec7ab44, argc=1) at ../../../b2g/app/nsBrowserApp.cpp:163
#29 main (argc=<optimized out>, argv=<optimized out>) at ../../../b2g/app/nsBrowserApp.cpp:256
(gdb) up
#1 mozilla::dom::bluetooth::BluetoothServiceBluedroid::GetDefaultAdapterPathInternal (this=<optimized out>, aRunnable=<optimized out>)
at ../../../dom/bluetooth/bluedroid/BluetoothServiceBluedroid.cpp:804
804 runnable.forget();
(gdb) p runnable
$1 = {mRawPtr = 0x0}
(gdb)
Comment 22•12 years ago
|
||
Uh STR is opening music app and not settings app.
Comment 23•12 years ago
|
||
Hi Gregor,
(In reply to Gregor Wagner [:gwagner] from comment #20)
> Can you explain what you think is different with your patch?
In fact, last Friday I asked almost the same question to Thomas on irc about why his solution can solve the problem. The following is his answer:
====
tzimmermann> the problem is that forget returns |already_AddRefed|, which immediately gets deconstructed
tzimmermann> it still has it's internal pointer set to the actual object. that makes the destructor assert and crash
tzimmermann> if you look into xpcom/glue/nsCOMPtr.h you'll find already_AddRefed with operator <<
tzimmermann> the operator calls |take|, which clears the internal pointer. when the already_AddRefed gets destructed afterwards, the assertion will be fullfilled
====
I think what Thomas' tried to say is that
http://dxr.mozilla.org/mozilla-central/source/xpcom/glue/nsCOMPtr.h?from=nsCOMPtr.h&case=true#168
will be executed when
unused << runnable.forget();
is called. Therefore already_AddRefed.take() will be called as well, so runnable.mRawPtr will be cleared to nullptr, which can fulfill the assertion.
Comment 24•12 years ago
|
||
(In reply to Gregor Wagner [:gwagner] from comment #21)
> Today I got this after opening the settings app:
>
> bt
> #0 0xb4b53776 in ~already_AddRefed (this=<optimized out>,
> __in_chrg=<optimized out>) at ../../dist/include/nsCOMPtr.h:165
> #1
> mozilla::dom::bluetooth::BluetoothServiceBluedroid::
> GetDefaultAdapterPathInternal (this=<optimized out>, aRunnable=<optimized
> out>)
> at ../../../dom/bluetooth/bluedroid/BluetoothServiceBluedroid.cpp:804
> #2 0xb4b4ab66 in mozilla::dom::bluetooth::BluetoothRequestParent::DoRequest
> (this=0xad83d310, aRequest=<optimized out>) at
> ../../../dom/bluetooth/ipc/BluetoothParent.cpp:311
> #3 0xb44caefa in
> mozilla::dom::bluetooth::PBluetoothParent::OnMessageReceived
> (this=0xad87b220, __msg=<optimized out>) at PBluetoothParent.cpp:413
> #4 0xb44f632e in mozilla::dom::PContentParent::OnMessageReceived
> (this=0xad0c2c00, __msg=...) at PContentParent.cpp:2012
> #5 0xb44a0998 in mozilla::ipc::MessageChannel::DispatchAsyncMessage
> (this=0xad0c2c30, aMsg=...) at ../../../ipc/glue/MessageChannel.cpp:1142
> #6 0xb44a3a48 in mozilla::ipc::MessageChannel::OnMaybeDequeueOne
> (this=0xad0c2c30) at ../../../ipc/glue/MessageChannel.cpp:1039
> #7 0xb44a03a4 in DispatchToMethod<mozilla::ipc::MessageChannel, void
> (mozilla::ipc::MessageChannel::*)()> (method=
> (void (mozilla::ipc::MessageChannel::*)(mozilla::ipc::MessageChannel *
> const)) 0xb44a39b5 <mozilla::ipc::MessageChannel::OnMaybeDequeueOne()>,
> obj=<optimized out>, arg=<optimized out>)
> at ../../../ipc/chromium/src/base/tuple.h:383
> #8 RunnableMethod<mozilla::ipc::MessageChannel, void
> (mozilla::ipc::MessageChannel::*)(), Tuple0>::Run (this=<optimized out>) at
> ../../../ipc/chromium/src/base/task.h:307
> #9 0xb44a0e1c in Run (this=<optimized out>) at
> ../../dist/include/mozilla/ipc/MessageChannel.h:383
> #10 mozilla::ipc::MessageChannel::DequeueTask::Run (this=<optimized out>) at
> ../../dist/include/mozilla/ipc/MessageChannel.h:400
> #11 0xb4492344 in MessageLoop::RunTask (this=0xb6a4e1a0, task=0xadc5bf80) at
> ../../../ipc/chromium/src/base/message_loop.cc:344
> #12 0xb4492c82 in MessageLoop::DeferOrRunPendingTask (this=<optimized out>,
> pending_task=<optimized out>) at
> ../../../ipc/chromium/src/base/message_loop.cc:352
> #13 0xb4493d7e in DoWork (this=<optimized out>) at
> ../../../ipc/chromium/src/base/message_loop.cc:430
> #14 MessageLoop::DoWork (this=0xb6a4e1a0) at
> ../../../ipc/chromium/src/base/message_loop.cc:409
> #15 0xb44a4a9e in mozilla::ipc::DoWorkRunnable::Run (this=<optimized out>)
> at ../../../ipc/glue/MessagePump.cpp:228
> #16 0xb42f7ca2 in ProcessNextEvent (result=0xbec787f7, mayWait=false,
> this=0xb6a34680) at ../../../xpcom/threads/nsThread.cpp:694
> #17 nsThread::ProcessNextEvent (this=0xb6a34680, mayWait=<optimized out>,
> result=0xbec787f7) at ../../../xpcom/threads/nsThread.cpp:618
> #18 0xb42b1dd0 in NS_ProcessNextEvent (thread=0xb6a34680, mayWait=<optimized
> out>) at ../../../xpcom/glue/nsThreadUtils.cpp:263
> #19 0xb44a4ee8 in mozilla::ipc::MessagePump::Run (this=0xb6a01df0,
> aDelegate=0xb6a4e1a0) at ../../../ipc/glue/MessagePump.cpp:95
> #20 0xb449248a in MessageLoop::RunInternal (this=0xb6a4e1a0) at
> ../../../ipc/chromium/src/base/message_loop.cc:226
> #21 0xb44924a2 in RunHandler (this=0xb6a4e1a0) at
> ../../../ipc/chromium/src/base/message_loop.cc:219
> #22 MessageLoop::Run (this=0xb6a4e1a0) at
> ../../../ipc/chromium/src/base/message_loop.cc:193
> #23 0xb4a30e4a in nsBaseAppShell::Run (this=0xb1f418e0) at
> ../../../widget/xpwidgets/nsBaseAppShell.cpp:164
> #24 0xb5300dae in nsAppStartup::Run (this=0xb214fca0) at
> ../../../../toolkit/components/startup/nsAppStartup.cpp:276
> #25 0xb52da7aa in XREMain::XRE_mainRun (this=0xbec7898c) at
> ../../../toolkit/xre/nsAppRunner.cpp:4008
> #26 0xb52da9aa in XREMain::XRE_main (this=0xbec7898c, argc=<optimized out>,
> argv=<optimized out>, aAppData=<optimized out>) at
> ../../../toolkit/xre/nsAppRunner.cpp:4077
> #27 0xb52dab00 in XRE_main (argc=1, argv=0xbec7ab44, aAppData=0x26908,
> aFlags=<optimized out>) at ../../../toolkit/xre/nsAppRunner.cpp:4289
> #28 0x0000a4ec in do_main (argv=0xbec7ab44, argc=1) at
> ../../../b2g/app/nsBrowserApp.cpp:163
> #29 main (argc=<optimized out>, argv=<optimized out>) at
> ../../../b2g/app/nsBrowserApp.cpp:256
> (gdb) up
> #1
> mozilla::dom::bluetooth::BluetoothServiceBluedroid::
> GetDefaultAdapterPathInternal (this=<optimized out>, aRunnable=<optimized
> out>)
> at ../../../dom/bluetooth/bluedroid/BluetoothServiceBluedroid.cpp:804
> 804 runnable.forget();
> (gdb) p runnable
> $1 = {mRawPtr = 0x0}
> (gdb)
No idea why crash happened in this case. I thought mRawPtr = 0x0 can fulfill the assertion which is in the dtor of already_AddRefed.
| Assignee | ||
Comment 25•12 years ago
|
||
Comment on attachment 8394676 [details] [diff] [review]
[01] Bug 983590: Correctly forget pointer references in Bluedroid backend
This patch will land as part of bug 985949.
Attachment #8394676 -
Attachment is obsolete: true
Attachment #8394676 -
Flags: review?(echou)
Attachment #8394676 -
Flags: feedback?(anygregor)
| Assignee | ||
Comment 26•12 years ago
|
||
Hi Gregor,
Does this bug still happen?
Flags: needinfo?(anygregor)
Comment 27•12 years ago
|
||
(In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #26)
> Hi Gregor,
>
> Does this bug still happen?
It works for me now.
Flags: needinfo?(anygregor)
| Assignee | ||
Comment 28•12 years ago
|
||
Thanks. This issue has probably been fixed by bug 985949.
Status: ASSIGNED → RESOLVED
Closed: 12 years ago
Resolution: --- → DUPLICATE
You need to log in
before you can comment on or make changes to this bug.
Description
•