Closed Bug 983590 Opened 12 years ago Closed 12 years ago

[Bluetooth] Phone reboots when turning on Bluedroid

Categories

(Firefox OS Graveyard :: Bluetooth, defect)

ARM
Gonk (Firefox OS)
defect
Not set
normal

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 985949

People

(Reporter: tzimmermann, Assigned: tzimmermann)

References

Details

Attachments

(1 file, 1 obsolete file)

We observed crashes when turning on Bluetooth on the Nexus 4. It doesn't happen very often and is hard to reproduce. The rough STR is - start Nexus 4 - open Settings app - turn on Bluetooth and touch button at bottom of the screen Expected: - BT turns on, Settings app minimized, App switcher is shown Actual result - Phone hangs for a second, then reboots Gecko rev: 173493:f073b3d6db1f
Attached file bt-logcat.txt —
I managed to get a logcat of the crash, but there isn't anything special happening near the EOF. The crash might either not be related to BT, or happen in the BT libraries.
I also had gdb attached to the process, but it didn't detect an error.
Bug 979370 is about to land and changes the initialization of Bluedroid. We should check if the crash is still observable with these patches.
Depends on: 979370
(In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #2) > I also had gdb attached to the process, but it didn't detect an error. Or can you enable minidump if gdb always fail to work to catch the crash?
Flags: needinfo?(tzimmermann)
(In reply to Shawn Huang [:shuang] [:shawnjohnjr] from comment #4) > (In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #2) > > I also had gdb attached to the process, but it didn't detect an error. > Or can you enable minidump if gdb always fail to work to catch the crash? I don't know this tool. What do I have to do?
Flags: needinfo?(tzimmermann)
Flags: needinfo?(shuang)
First you can reference, as i told the partner before: https://bugzilla.mozilla.org/show_bug.cgi?id=976883#c33 minidump is under /data/b2g/mozilla/Crash Reports/pending, you can adb pull out. You can see *.dmp file. And use minidump_stackwalk to parse dmp file and get backtrace.
Flags: needinfo?(shuang)
(In reply to Shawn Huang [:shuang] [:shawnjohnjr] from comment #6) > First you can reference, as i told the partner before: > https://bugzilla.mozilla.org/show_bug.cgi?id=976883#c33 > > minidump is under /data/b2g/mozilla/Crash Reports/pending, you can adb pull > out. > You can see *.dmp file. > And use minidump_stackwalk to parse dmp file and get backtrace. Sometimes optimization can cause minidump_stackwalk points to wrong place, this is why B2G_NOOPT=1
Hmm, nothing there. I have a debug build (DEBUG=1, NOOPT=0, PROF=0). Do I need to enabled it specifically?
Well, let's see if dmp file will be created and see if we can parse minidump or not. If we can't parse it, we might need to NOOPT=1. Do I need to turn on/off Bluetooth very fast? I also want to reproduce this bug here.
(In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #8) > Hmm, nothing there. I have a debug build (DEBUG=1, NOOPT=0, PROF=0). Do I > need to enabled it specifically? Ya. MOZ_CRASHREPORTER="1" /system/bin/b2g.sh You can refer to https://bugzilla.mozilla.org/show_bug.cgi?id=976883#c33
(In reply to Shawn Huang [:shuang] [:shawnjohnjr] from comment #9) > Well, let's see if dmp file will be created and see if we can parse minidump > or not. If we can't parse it, we might need to NOOPT=1. Do I need to turn > on/off Bluetooth very fast? I also want to reproduce this bug here. 'Very fast'? I don't know for sure. I tried to, but I can't say if it's really necessary. It seems necessary to have other things happening as well though. gwagner mentioned in bug 981239 that garbage collection can have an impact.
(In reply to Shawn Huang [:shuang] [:shawnjohnjr] from comment #10) > (In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #8) > > Hmm, nothing there. I have a debug build (DEBUG=1, NOOPT=0, PROF=0). Do I > > need to enabled it specifically? > Ya. MOZ_CRASHREPORTER="1" /system/bin/b2g.sh > > You can refer to https://bugzilla.mozilla.org/show_bug.cgi?id=976883#c33 Oh, I see! Thanks for the info. Will try.
When I switch on Bluetooth on the Nexus 4, I see a segmentation fault. The stack trace is: Program received signal SIGSEGV, Segmentation fault. 0xb52c7ea2 in CrashReporter::GetPendingDir (dir=0xbeef2ea0) at ../../../../mozilla-central/toolkit/crashreporter/nsExceptionHandler.cpp:2167 2167 MOZ_ASSERT(OOPInitialized()); (gdb) bt #0 0xb52c7ea2 in CrashReporter::GetPendingDir (dir=0xbeef2ea0) at ../../../../mozilla-central/toolkit/crashreporter/nsExceptionHandler.cpp:2167 #1 0xb52c7f7c in CrashReporter::MoveToPending (dumpFile=0xaeecb080, extraFile=0xaeecb110) at ../../../../mozilla-central/toolkit/crashreporter/nsExceptionHandler.cpp:2386 #2 0xb52c8230 in CrashReporter::CheckForLastRunCrash () at ../../../../mozilla-central/toolkit/crashreporter/nsExceptionHandler.cpp:2699 #3 0xb52c82f4 in CrashReporter::GetLastRunCrashID (id=...) at ../../../../mozilla-central/toolkit/crashreporter/nsExceptionHandler.cpp:2711 #4 0xb52b9f14 in nsXULAppInfo::GetLastRunCrashID (this=<optimized out>, aLastRunCrashID=<optimized out>) at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:864 #5 0xb42f533e in NS_InvokeByIndex (that=<optimized out>, methodIndex=14, paramCount=<optimized out>, params=<optimized out>) at ../../../../../../../../mozilla-central/xpcom/reflect/xptcall/src/md/unix/xptcinvoke_arm.cpp:164 #6 0xb4a6dbb4 in Invoke (this=0xbeef3028) at ../../../../../mozilla-central/js/xpconnect/src/XPCWrappedNative.cpp:2407 #7 CallMethodHelper::Call (this=0xbeef3028) at ../../../../../mozilla-central/js/xpconnect/src/XPCWrappedNative.cpp:1748 #8 0xb4a6dec0 in XPCWrappedNative::CallMethod (ccx=..., mode=<optimized out>) at ../../../../../mozilla-central/js/xpconnect/src/XPCWrappedNative.cpp:1715 #9 0xb4a70a52 in GetAttribute (ccx=...) at ../../../../../mozilla-central/js/xpconnect/src/xpcprivate.h:2085 #10 XPC_WN_GetterSetter (cx=0xb05db380, argc=0, vp=0xbeef3588) at ../../../../../mozilla-central/js/xpconnect/src/XPCWrappedNativeJSOps.cpp:1316 #11 0xb580015e in js::CallJSNative (cx=0xb05db380, native=0xb4a708e5 <XPC_WN_GetterSetter(JSContext*, unsigned int, JS::Value*)>, args=...) at ../../../../mozilla-central/js/src/jscntxtinlines.h:239 #12 0xb58015e6 in js::Invoke (cx=0xb05db380, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:476 #13 0xb580cc8a in js::Invoke (cx=0xb05db380, thisv=..., fval=..., argc=<optimized out>, argv=0x0, rval=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:532 #14 0xb580ce76 in js::InvokeGetterOrSetter (cx=<optimized out>, obj=0xafc383a0, fval=..., argc=0, argv=0x0, rval=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:604 #15 0xb5757450 in js::Shape::get (this=0xae62eec8, cx=0xb05db380, receiver=..., obj=<optimized out>, pobj=0xafc383a0, vp=...) at ../../../../mozilla-central/js/src/vm/Shape-inl.h:46 #16 0xb5757516 in NativeGetInline<(js::AllowGC)1> (cx=0xb05db380, obj=..., receiver=..., pobj=..., shape=..., vp=...) at ../../../../mozilla-central/js/src/jsobj.cpp:4344 #17 0xb575776c in GetPropertyHelperInline<(js::AllowGC)1> (cx=<optimized out>, obj=..., receiver=..., id=..., vp=...) at ../../../../mozilla-central/js/src/jsobj.cpp:4541 #18 0xb5807ade in getGeneric (vp=<optimized out>, id=<optimized out>, receiver=<optimized out>, obj=..., cx=<optimized out>) at ../../../../mozilla-central/js/src/jsobj.h:1001 #19 GetPropertyOperation (vp=..., lval=<optimized out>, pc=<optimized out>, script=<optimized out>, fp=<optimized out>, cx=<optimized out>) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:266 #20 Interpret (cx=0xb05db380, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:2409 #21 0xb580c3c6 in js::RunScript (cx=0xb05db380, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:423 #22 0xb580154c in RunScript (state=..., cx=0xb05db380) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:390 #23 js::Invoke (cx=0xb05db380, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:495 #24 0xb580cc8a in js::Invoke (cx=0xb05db380, thisv=..., fval=..., argc=<optimized out>, argv=0xbeef40f0, rval=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:532 #25 0xb56df198 in JS::Call (cx=0xb05db380, thisv=..., fval=..., args=<optimized out>, rval=...) at ../../../../mozilla-central/js/src/jsapi.cpp:4901 #26 0xb483f354 in mozilla::dom::EventListener::HandleEvent (this=<optimized out>, cx=0xb05db380, aThisVal=<optimized out>, event=..., aRv=...) at EventListenerBinding.cpp:44 #27 0xb4b68d24 in mozilla::dom::EventListener::HandleEvent<mozilla::dom::EventTarget*> (this=0xadc8b820, thisObjPtr=<optimized out>, event=..., aRv=..., aExceptionHandling=mozilla::dom::CallbackObject::eReportExceptions) at ../../dist/include/mozilla/dom/EventListenerBinding.h:53 #28 0xb4b68de4 in mozilla::EventListenerManager::HandleEventSubType (this=0xae1eabe0, aListener=<optimized out>, aDOMEvent=0xaf591e80, aCurrentTarget=0xae4c3c10) at ../../../../mozilla-central/dom/events/EventListenerManager.cpp:969 #29 0xb4b68f5a in mozilla::EventListenerManager::HandleEventInternal (this=0xae1eabe0, aPresContext=0xafedac00, aEvent=0xaf5b6560, aDOMEvent=0xbeef43d8, aCurrentTarget=0xae4c3c10, aEventStatus=0xbeef43dc) at ../../../../mozilla-central/dom/events/EventListenerManager.cpp:1033 #30 0xb4b64774 in HandleEvent (aEventStatus=0xbeef43dc, aCurrentTarget=0xae4c3c10, aDOMEvent=0xbeef43d8, aEvent=<optimized out>, aPresContext=<optimized out>, this=<optimized out>) at ../../dist/include/mozilla/EventListenerManager.h:328 ---Type <return> to continue, or q <return> to quit--- #31 mozilla::EventTargetChainItem::HandleEvent (this=<optimized out>, aVisitor=..., aCd=<optimized out>) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:197 #32 0xb4b652b4 in mozilla::EventTargetChainItem::HandleEventTargetChain (aChain=..., aVisitor=..., aCallback=0x0, aCd=...) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:287 #33 0xb4b65bb8 in mozilla::EventDispatcher::Dispatch (aTarget=<optimized out>, aPresContext=0xafedac00, aEvent=0xaf5b6560, aDOMEvent=0xaf591e80, aEventStatus=0xbeef447c, aCallback=0x0, aTargets=0x0) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:598 #34 0xb4b65e26 in mozilla::EventDispatcher::DispatchDOMEvent (aTarget=0xae4c3c10, aEvent=<optimized out>, aDOMEvent=0xaf591e80, aPresContext=0xafedac00, aEventStatus=0xbeef447c) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:665 #35 0xb4d4227a in nsINode::DispatchEvent (this=0xae4c3c10, aEvent=0xaf591e80, aRetVal=0xbeef449f) at ../../../../../mozilla-central/content/base/src/nsINode.cpp:1165 #36 0xb4d407f8 in mozilla::dom::EventTarget::DispatchEvent (this=<optimized out>, aEvent=<optimized out>, aRv=...) at ../../../../../mozilla-central/content/base/src/nsINode.cpp:2639 #37 0xb4839f68 in dispatchEvent (args=..., self=0xae4c3c10, cx=0xb6ad2240, obj=<optimized out>) at EventTargetBinding.cpp:167 #38 mozilla::dom::EventTargetBinding::dispatchEvent (cx=0xb6ad2240, obj=<optimized out>, self=0xae4c3c10, args=...) at EventTargetBinding.cpp:146 #39 0xb483a15c in mozilla::dom::EventTargetBinding::genericMethod (cx=0xb6ad2240, argc=<optimized out>, vp=<optimized out>) at EventTargetBinding.cpp:344 #40 0xb580015e in js::CallJSNative (cx=0xb6ad2240, native=0xb4839ffd <mozilla::dom::EventTargetBinding::genericMethod(JSContext*, unsigned int, JS::Value*)>, args=...) at ../../../../mozilla-central/js/src/jscntxtinlines.h:239 #41 0xb58015e6 in js::Invoke (cx=0xb6ad2240, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:476 #42 0xb580cc8a in js::Invoke (cx=0xb6ad2240, thisv=..., fval=..., argc=<optimized out>, argv=0xb1f1f0e8, rval=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:532 #43 0xb577c818 in js::DirectProxyHandler::call (this=<optimized out>, cx=<optimized out>, proxy=<optimized out>, args=...) at ../../../../mozilla-central/js/src/jsproxy.cpp:465 #44 0xb57c0260 in js::CrossCompartmentWrapper::call (this=0xb6543518, cx=0xb6ad2240, wrapper=..., args=...) at ../../../../mozilla-central/js/src/jswrapper.cpp:465 #45 0xb577c0b2 in js::Proxy::call (cx=<optimized out>, proxy=..., args=...) at ../../../../mozilla-central/js/src/jsproxy.cpp:2637 #46 0xb577c164 in js::proxy_Call (cx=0xb6ad2240, argc=<optimized out>, vp=<optimized out>) at ../../../../mozilla-central/js/src/jsproxy.cpp:3040 #47 0xb580015e in js::CallJSNative (cx=0xb6ad2240, native=0xb577c10d <js::proxy_Call(JSContext*, unsigned int, JS::Value*)>, args=...) at ../../../../mozilla-central/js/src/jscntxtinlines.h:239 #48 0xb58016b0 in js::Invoke (cx=0xb6ad2240, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:469 #49 0xb5802908 in Interpret (cx=0xb6ad2240, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:2614 #50 0xb580c3c6 in js::RunScript (cx=0xb6ad2240, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:423 #51 0xb580154c in RunScript (state=..., cx=0xb6ad2240) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:390 #52 js::Invoke (cx=0xb6ad2240, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:495 #53 0xb5719b34 in js_fun_apply (cx=0xb6ad2240, argc=<optimized out>, vp=0xb1f1f058) at ../../../../mozilla-central/js/src/jsfun.cpp:1010 #54 0xb580015e in js::CallJSNative (cx=0xb6ad2240, native=0xb5719a19 <js_fun_apply(JSContext*, unsigned int, JS::Value*)>, args=...) at ../../../../mozilla-central/js/src/jscntxtinlines.h:239 #55 0xb58015e6 in js::Invoke (cx=0xb6ad2240, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:476 #56 0xb5802908 in Interpret (cx=0xb6ad2240, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:2614 #57 0xb580c3c6 in js::RunScript (cx=0xb6ad2240, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:423 #58 0xb580154c in RunScript (state=..., cx=0xb6ad2240) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:390 #59 js::Invoke (cx=0xb6ad2240, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:495 #60 0xb580cc8a in js::Invoke (cx=0xb6ad2240, thisv=..., fval=..., argc=<optimized out>, argv=0xbeef6698, rval=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:532 #61 0xb56df094 in JS_CallFunctionValue (cx=0xb6ad2240, obj=<optimized out>, fval=..., args=..., rval=...) at ../../../../mozilla-central/js/src/jsapi.cpp:4889 #62 0xb4d38356 in nsFrameMessageManager::ReceiveMessage (this=0xae1eab20, aTarget=0xae4c3c10, aMessage=..., aIsSync=<optimized out>, aCloneData=0xbeef6748, ---Type <return> to continue, or q <return> to quit--- aCpows=0xbeef6754, aPrincipal=0x0, aJSONRetVal=0x0) at ../../../../../mozilla-central/content/base/src/nsFrameMessageManager.cpp:1046 #63 0xb4d38fee in nsSameProcessAsyncMessageBase::ReceiveMessage (this=0xaf591b0c, aTarget=0xae4c3c10, aManager=0xae1eab20) at ../../../../../mozilla-central/content/base/src/nsFrameMessageManager.cpp:1958 #64 0xb4d466ca in Run (this=0xaf591b00) at ../../../../../mozilla-central/content/base/src/nsInProcessTabChildGlobal.cpp:77 #65 nsAsyncMessageToParent::Run (this=0xaf591b00) at ../../../../../mozilla-central/content/base/src/nsInProcessTabChildGlobal.cpp:69 #66 0xb42f086a in ProcessNextEvent (result=0xbeef67f7, mayWait=false, this=0xb6a34780) at ../../../../mozilla-central/xpcom/threads/nsThread.cpp:694 #67 nsThread::ProcessNextEvent (this=0xb6a34780, mayWait=<optimized out>, result=0xbeef67f7) at ../../../../mozilla-central/xpcom/threads/nsThread.cpp:618 #68 0xb42aa8b8 in NS_ProcessNextEvent (thread=0xb6a34780, mayWait=<optimized out>) at ../../../../mozilla-central/xpcom/glue/nsThreadUtils.cpp:263 #69 0xb449dd14 in mozilla::ipc::MessagePump::Run (this=0xb6a01e80, aDelegate=0xb6a4e1a0) at ../../../../mozilla-central/ipc/glue/MessagePump.cpp:95 #70 0xb448b292 in MessageLoop::RunInternal (this=0xb6a4e1a0) at ../../../../mozilla-central/ipc/chromium/src/base/message_loop.cc:226 #71 0xb448b2aa in RunHandler (this=0xb6a4e1a0) at ../../../../mozilla-central/ipc/chromium/src/base/message_loop.cc:219 #72 MessageLoop::Run (this=0xb6a4e1a0) at ../../../../mozilla-central/ipc/chromium/src/base/message_loop.cc:193 #73 0xb4a17f3a in nsBaseAppShell::Run (this=0xb1f49940) at ../../../../mozilla-central/widget/xpwidgets/nsBaseAppShell.cpp:164 #74 0xb52ecb6e in nsAppStartup::Run (this=0xb6aedca0) at ../../../../../mozilla-central/toolkit/components/startup/nsAppStartup.cpp:276 #75 0xb52bec2e in XREMain::XRE_mainRun (this=0xbeef698c) at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:4010 #76 0xb52beea4 in XREMain::XRE_main (this=0xbeef698c, argc=<optimized out>, argv=<optimized out>, aAppData=<optimized out>) at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:4079 #77 0xb52bf014 in XRE_main (argc=1, argv=0xbeef8b44, aAppData=0x26908, aFlags=<optimized out>) at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:4291 #78 0x0000a4ec in do_main (argv=0xbeef8b44, argc=1) at ../../../../mozilla-central/b2g/app/nsBrowserApp.cpp:163 #79 main (argc=<optimized out>, argv=<optimized out>) at ../../../../mozilla-central/b2g/app/nsBrowserApp.cpp:256 (gdb)
(In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #13) > When I switch on Bluetooth on the Nexus 4, I see a segmentation fault. The > stack trace is: > Program received signal SIGSEGV, Segmentation fault. > 0xb52c7ea2 in CrashReporter::GetPendingDir (dir=0xbeef2ea0) at > ../../../../mozilla-central/toolkit/crashreporter/nsExceptionHandler.cpp:2167 > 2167 MOZ_ASSERT(OOPInitialized()); This is known issue. See bug 820716. I can still hit this bug all the time. :(
Program received signal SIGSEGV, Segmentation fault. 0xb4a39f52 in ~already_AddRefed (this=<optimized out>, __in_chrg=<optimized out>) at ../../dist/include/nsCOMPtr.h:177 177 MOZ_ASSERT(!mRawPtr); (gdb) bt #0 0xb4a39f52 in ~already_AddRefed (this=<optimized out>, __in_chrg=<optimized out>) at ../../dist/include/nsCOMPtr.h:177 #1 mozilla::dom::bluetooth::BluetoothServiceBluedroid::GetDefaultAdapterPathInternal (this=<optimized out>, aRunnable=<optimized out>) at ../../../../mozilla-central/dom/bluetooth/bluedroid/BluetoothServiceBluedroid.cpp:804 #2 0xb4a2c6b0 in mozilla::dom::bluetooth::BluetoothManager::GetDefaultAdapter (this=<optimized out>, aRv=...) at ../../../../mozilla-central/dom/bluetooth/BluetoothManager.cpp:157 #3 0xb46baee8 in mozilla::dom::BluetoothManagerBinding::getDefaultAdapter (cx=0xae7de2e0, obj=<optimized out>, self=<optimized out>, args=...) at BluetoothManagerBinding.cpp:283 #4 0xb48af570 in mozilla::dom::GenericBindingMethod (cx=0xae7de2e0, argc=<optimized out>, vp=<optimized out>) at ../../../../mozilla-central/dom/bindings/BindingUtils.cpp:2276 #5 0xb570015e in js::CallJSNative (cx=0xae7de2e0, native=0xb48af4b5 <mozilla::dom::GenericBindingMethod(JSContext*, unsigned int, JS::Value*)>, args=...) at ../../../../mozilla-central/js/src/jscntxtinlines.h:239 #6 0xb57015e6 in js::Invoke (cx=0xae7de2e0, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:476 #7 0xb5702908 in Interpret (cx=0xae7de2e0, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:2614 #8 0xb570c3c6 in js::RunScript (cx=0xae7de2e0, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:423 #9 0xb570154c in RunScript (state=..., cx=0xae7de2e0) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:390 #10 js::Invoke (cx=0xae7de2e0, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:495 #11 0xb570cc8a in js::Invoke (cx=0xae7de2e0, thisv=..., fval=..., argc=<optimized out>, argv=0xbefabf80, rval=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:532 #12 0xb55df198 in JS::Call (cx=0xae7de2e0, thisv=..., fval=..., args=<optimized out>, rval=...) at ../../../../mozilla-central/js/src/jsapi.cpp:4901 #13 0xb473f354 in mozilla::dom::EventListener::HandleEvent (this=<optimized out>, cx=0xae7de2e0, aThisVal=<optimized out>, event=..., aRv=...) at EventListenerBinding.cpp:44 #14 0xb4a68d24 in mozilla::dom::EventListener::HandleEvent<mozilla::dom::EventTarget*> (this=0xaf5f4ea0, thisObjPtr=<optimized out>, event=..., aRv=..., aExceptionHandling=mozilla::dom::CallbackObject::eReportExceptions) at ../../dist/include/mozilla/dom/EventListenerBinding.h:53 #15 0xb4a68de4 in mozilla::EventListenerManager::HandleEventSubType (this=0xadf45580, aListener=<optimized out>, aDOMEvent=0xad589e00, aCurrentTarget=0xae220d80) at ../../../../mozilla-central/dom/events/EventListenerManager.cpp:969 #16 0xb4a68f5a in mozilla::EventListenerManager::HandleEventInternal (this=0xadf45580, aPresContext=0xaeb92800, aEvent=0xadb665b0, aDOMEvent=0xbefac268, aCurrentTarget=0xae220d80, aEventStatus=0xbefac26c) at ../../../../mozilla-central/dom/events/EventListenerManager.cpp:1033 #17 0xb4a64774 in HandleEvent (aEventStatus=0xbefac26c, aCurrentTarget=0xae220d80, aDOMEvent=0xbefac268, aEvent=<optimized out>, aPresContext=<optimized out>, this=<optimized out>) at ../../dist/include/mozilla/EventListenerManager.h:328 #18 mozilla::EventTargetChainItem::HandleEvent (this=<optimized out>, aVisitor=..., aCd=<optimized out>) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:197 #19 0xb4a652b4 in mozilla::EventTargetChainItem::HandleEventTargetChain (aChain=..., aVisitor=..., aCallback=0x0, aCd=...) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:287 #20 0xb4a65bb8 in mozilla::EventDispatcher::Dispatch (aTarget=<optimized out>, aPresContext=0xaeb92800, aEvent=0xadb665b0, aDOMEvent=0xad589e00, aEventStatus=0xbefac30c, aCallback=0x0, aTargets=0x0) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:598 #21 0xb4a65e26 in mozilla::EventDispatcher::DispatchDOMEvent (aTarget=0xae21fad0, aEvent=<optimized out>, aDOMEvent=0xad589e00, aPresContext=0xaeb92800, aEventStatus=0xbefac30c) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:665 #22 0xb49d5474 in DispatchEvent (aRetVal=0xbefac32f, aEvent=0xad589e00, this=0xae220d80) at ../../../../mozilla-central/dom/base/nsGlobalWindow.cpp:9198 #23 nsGlobalWindow::DispatchEvent (this=0xae220d80, aEvent=0xad589e00, aRetVal=0xbefac32f) at ../../../../mozilla-central/dom/base/nsGlobalWindow.cpp:9173 #24 0xb4c407f8 in mozilla::dom::EventTarget::DispatchEvent (this=<optimized out>, aEvent=<optimized out>, aRv=...) at ../../../../../mozilla-central/content/base/src/nsINode.cpp:2639 #25 0xb4739f68 in dispatchEvent (args=..., self=0xae220d80, cx=0xae7de2e0, obj=<optimized out>) at EventTargetBinding.cpp:167 #26 mozilla::dom::EventTargetBinding::dispatchEvent (cx=0xae7de2e0, obj=<optimized out>, self=0xae220d80, args=...) at EventTargetBinding.cpp:146 #27 0xb473a15c in mozilla::dom::EventTargetBinding::genericMethod (cx=0xae7de2e0, argc=<optimized out>, vp=<optimized out>) at EventTargetBinding.cpp:344 ---Type <return> to continue, or q <return> to quit--- #28 0xb570015e in js::CallJSNative (cx=0xae7de2e0, native=0xb4739ffd <mozilla::dom::EventTargetBinding::genericMethod(JSContext*, unsigned int, JS::Value*)>, args=...) at ../../../../mozilla-central/js/src/jscntxtinlines.h:239 #29 0xb57015e6 in js::Invoke (cx=0xae7de2e0, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:476 #30 0xb5702908 in Interpret (cx=0xae7de2e0, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:2614 #31 0xb570c3c6 in js::RunScript (cx=0xae7de2e0, state=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:423 #32 0xb570154c in RunScript (state=..., cx=0xae7de2e0) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:390 #33 js::Invoke (cx=0xae7de2e0, args=..., construct=js::NO_CONSTRUCT) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:495 #34 0xb570cc8a in js::Invoke (cx=0xae7de2e0, thisv=..., fval=..., argc=<optimized out>, argv=0xbefad0c0, rval=...) at ../../../../mozilla-central/js/src/vm/Interpreter.cpp:532 #35 0xb55df198 in JS::Call (cx=0xae7de2e0, thisv=..., fval=..., args=<optimized out>, rval=...) at ../../../../mozilla-central/js/src/jsapi.cpp:4901 #36 0xb473f81a in mozilla::dom::EventHandlerNonNull::Call (this=0xaf50d200, cx=0xae7de2e0, aThisVal=..., event=..., aRv=...) at EventHandlerBinding.cpp:36 #37 0xb4a76ec2 in mozilla::dom::EventHandlerNonNull::Call<nsISupports*> (this=0xaf50d200, thisObjPtr=<optimized out>, event=..., aRv=..., aExceptionHandling=mozilla::dom::CallbackObject::eReportExceptions) at ../../dist/include/mozilla/dom/EventHandlerBinding.h:62 #38 0xb4a772be in nsJSEventListener::HandleEvent (this=0xaf50d220, aEvent=0xad5a3a30) at ../../../../mozilla-central/dom/events/nsJSEventListener.cpp:235 #39 0xb4a68dfc in mozilla::EventListenerManager::HandleEventSubType (this=0xaf233400, aListener=<optimized out>, aDOMEvent=0xad5a3a30, aCurrentTarget=0xad58f040) at ../../../../mozilla-central/dom/events/EventListenerManager.cpp:972 #40 0xb4a68f5a in mozilla::EventListenerManager::HandleEventInternal (this=0xaf233400, aPresContext=0x0, aEvent=0xadb66560, aDOMEvent=0xbefad4d8, aCurrentTarget=0xad58f040, aEventStatus=0xbefad4dc) at ../../../../mozilla-central/dom/events/EventListenerManager.cpp:1033 #41 0xb4a64774 in HandleEvent (aEventStatus=0xbefad4dc, aCurrentTarget=0xad58f040, aDOMEvent=0xbefad4d8, aEvent=<optimized out>, aPresContext=<optimized out>, this=<optimized out>) at ../../dist/include/mozilla/EventListenerManager.h:328 #42 mozilla::EventTargetChainItem::HandleEvent (this=<optimized out>, aVisitor=..., aCd=<optimized out>) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:197 #43 0xb4a652b4 in mozilla::EventTargetChainItem::HandleEventTargetChain (aChain=..., aVisitor=..., aCallback=0x0, aCd=...) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:287 #44 0xb4a65bb8 in mozilla::EventDispatcher::Dispatch (aTarget=<optimized out>, aPresContext=0x0, aEvent=0xadb66560, aDOMEvent=0xad5a3a30, aEventStatus=0xbefad57c, aCallback=0x0, aTargets=0x0) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:598 #45 0xb4a65e26 in mozilla::EventDispatcher::DispatchDOMEvent (aTarget=0xad58f040, aEvent=<optimized out>, aDOMEvent=0xad5a3a30, aPresContext=0x0, aEventStatus=0xbefad57c) at ../../../../mozilla-central/dom/events/EventDispatcher.cpp:665 #46 0xb4a26438 in nsWindowRoot::DispatchEvent (this=<optimized out>, aEvt=0xad5a3a30, aRetVal=0xbefad597) at ../../../../mozilla-central/dom/base/nsWindowRoot.cpp:80 #47 0xb4a759a4 in nsDOMEventTargetHelper::DispatchTrustedEvent (this=0xad58f040, event=0xad5a3a30) at ../../../../mozilla-central/dom/events/nsDOMEventTargetHelper.cpp:268 #48 0xb4a76334 in nsDOMEventTargetHelper::DispatchTrustedEvent (this=0xad58f040, aEventName=...) at ../../../../mozilla-central/dom/events/nsDOMEventTargetHelper.cpp:259 #49 0xb4a2bf1a in mozilla::dom::bluetooth::BluetoothManager::Notify (this=0xad58f040, aData=...) at ../../../../mozilla-central/dom/bluetooth/BluetoothManager.cpp:206 #50 0xb4a2e9e8 in Broadcast (aParam=<optimized out>, this=<optimized out>) at ../../dist/include/mozilla/Observer.h:67 #51 mozilla::dom::bluetooth::BluetoothService::DistributeSignal (this=<optimized out>, aSignal=...) at ../../../../mozilla-central/dom/bluetooth/BluetoothService.cpp:392 #52 0xb4a2eafe in mozilla::dom::bluetooth::BluetoothService::TryFiringAdapterAdded (this=0xb2088e80) at ../../../../mozilla-central/dom/bluetooth/BluetoothService.cpp:786 #53 0xb4a3834c in SetupAfterEnabledTask::Run (this=<optimized out>) at ../../../../mozilla-central/dom/bluetooth/bluedroid/BluetoothServiceBluedroid.cpp:117 #54 0xb41f086a in ProcessNextEvent (result=0xbefad7f7, mayWait=false, this=0xb6a34780) at ../../../../mozilla-central/xpcom/threads/nsThread.cpp:694 #55 nsThread::ProcessNextEvent (this=0xb6a34780, mayWait=<optimized out>, result=0xbefad7f7) at ../../../../mozilla-central/xpcom/threads/nsThread.cpp:618 #56 0xb41aa8b8 in NS_ProcessNextEvent (thread=0xb6a34780, mayWait=<optimized out>) at ../../../../mozilla-central/xpcom/glue/nsThreadUtils.cpp:263 #57 0xb439dd14 in mozilla::ipc::MessagePump::Run (this=0xb6a01e80, aDelegate=0xb6a4e1a0) at ../../../../mozilla-central/ipc/glue/MessagePump.cpp:95 #58 0xb438b292 in MessageLoop::RunInternal (this=0xb6a4e1a0) at ../../../../mozilla-central/ipc/chromium/src/base/message_loop.cc:226 #59 0xb438b2aa in RunHandler (this=0xb6a4e1a0) at ../../../../mozilla-central/ipc/chromium/src/base/message_loop.cc:219 #60 MessageLoop::Run (this=0xb6a4e1a0) at ../../../../mozilla-central/ipc/chromium/src/base/message_loop.cc:193 ---Type <return> to continue, or q <return> to quit--- #61 0xb4917f3a in nsBaseAppShell::Run (this=0xb1e498e0) at ../../../../mozilla-central/widget/xpwidgets/nsBaseAppShell.cpp:164 #62 0xb51ecb6e in nsAppStartup::Run (this=0xb205ddf0) at ../../../../../mozilla-central/toolkit/components/startup/nsAppStartup.cpp:276 #63 0xb51bec2e in XREMain::XRE_mainRun (this=0xbefad98c) at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:4010 #64 0xb51beea4 in XREMain::XRE_main (this=0xbefad98c, argc=<optimized out>, argv=<optimized out>, aAppData=<optimized out>) at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:4079 #65 0xb51bf014 in XRE_main (argc=1, argv=0xbefafb44, aAppData=0x26908, aFlags=<optimized out>) at ../../../../mozilla-central/toolkit/xre/nsAppRunner.cpp:4291 #66 0x0000a4ec in do_main (argv=0xbefafb44, argc=1) at ../../../../mozilla-central/b2g/app/nsBrowserApp.cpp:163 #67 main (argc=<optimized out>, argv=<optimized out>) at ../../../../mozilla-central/b2g/app/nsBrowserApp.cpp:256 (gdb)
Assignee: nobody → tzimmermann
Status: NEW → ASSIGNED
This looks like more fallout from bug 967364.
Depends on: 967364
Gregor, does this fix the crash for you? Eric, this changes makes the code work as before. But it looks to me as if the forget call should not be there in the first place, and we're currently leaking the runnable.
Attachment #8394676 - Flags: review?(echou)
Attachment #8394676 - Flags: feedback?(anygregor)
(In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #18) > Created attachment 8394676 [details] [diff] [review] > [01] Bug 983590: Correctly forget pointer references in Bluedroid backend > > Gregor, does this fix the crash for you? > > Eric, this changes makes the code work as before. But it looks to me as if > the forget call should not be there in the first place, and we're currently > leaking the runnable. Hm I don't see how this can fix anything. Maybe a compiler warning but that's about it.
Can you explain what you think is different with your patch?
Today I got this after opening the settings app: bt #0 0xb4b53776 in ~already_AddRefed (this=<optimized out>, __in_chrg=<optimized out>) at ../../dist/include/nsCOMPtr.h:165 #1 mozilla::dom::bluetooth::BluetoothServiceBluedroid::GetDefaultAdapterPathInternal (this=<optimized out>, aRunnable=<optimized out>) at ../../../dom/bluetooth/bluedroid/BluetoothServiceBluedroid.cpp:804 #2 0xb4b4ab66 in mozilla::dom::bluetooth::BluetoothRequestParent::DoRequest (this=0xad83d310, aRequest=<optimized out>) at ../../../dom/bluetooth/ipc/BluetoothParent.cpp:311 #3 0xb44caefa in mozilla::dom::bluetooth::PBluetoothParent::OnMessageReceived (this=0xad87b220, __msg=<optimized out>) at PBluetoothParent.cpp:413 #4 0xb44f632e in mozilla::dom::PContentParent::OnMessageReceived (this=0xad0c2c00, __msg=...) at PContentParent.cpp:2012 #5 0xb44a0998 in mozilla::ipc::MessageChannel::DispatchAsyncMessage (this=0xad0c2c30, aMsg=...) at ../../../ipc/glue/MessageChannel.cpp:1142 #6 0xb44a3a48 in mozilla::ipc::MessageChannel::OnMaybeDequeueOne (this=0xad0c2c30) at ../../../ipc/glue/MessageChannel.cpp:1039 #7 0xb44a03a4 in DispatchToMethod<mozilla::ipc::MessageChannel, void (mozilla::ipc::MessageChannel::*)()> (method= (void (mozilla::ipc::MessageChannel::*)(mozilla::ipc::MessageChannel * const)) 0xb44a39b5 <mozilla::ipc::MessageChannel::OnMaybeDequeueOne()>, obj=<optimized out>, arg=<optimized out>) at ../../../ipc/chromium/src/base/tuple.h:383 #8 RunnableMethod<mozilla::ipc::MessageChannel, void (mozilla::ipc::MessageChannel::*)(), Tuple0>::Run (this=<optimized out>) at ../../../ipc/chromium/src/base/task.h:307 #9 0xb44a0e1c in Run (this=<optimized out>) at ../../dist/include/mozilla/ipc/MessageChannel.h:383 #10 mozilla::ipc::MessageChannel::DequeueTask::Run (this=<optimized out>) at ../../dist/include/mozilla/ipc/MessageChannel.h:400 #11 0xb4492344 in MessageLoop::RunTask (this=0xb6a4e1a0, task=0xadc5bf80) at ../../../ipc/chromium/src/base/message_loop.cc:344 #12 0xb4492c82 in MessageLoop::DeferOrRunPendingTask (this=<optimized out>, pending_task=<optimized out>) at ../../../ipc/chromium/src/base/message_loop.cc:352 #13 0xb4493d7e in DoWork (this=<optimized out>) at ../../../ipc/chromium/src/base/message_loop.cc:430 #14 MessageLoop::DoWork (this=0xb6a4e1a0) at ../../../ipc/chromium/src/base/message_loop.cc:409 #15 0xb44a4a9e in mozilla::ipc::DoWorkRunnable::Run (this=<optimized out>) at ../../../ipc/glue/MessagePump.cpp:228 #16 0xb42f7ca2 in ProcessNextEvent (result=0xbec787f7, mayWait=false, this=0xb6a34680) at ../../../xpcom/threads/nsThread.cpp:694 #17 nsThread::ProcessNextEvent (this=0xb6a34680, mayWait=<optimized out>, result=0xbec787f7) at ../../../xpcom/threads/nsThread.cpp:618 #18 0xb42b1dd0 in NS_ProcessNextEvent (thread=0xb6a34680, mayWait=<optimized out>) at ../../../xpcom/glue/nsThreadUtils.cpp:263 #19 0xb44a4ee8 in mozilla::ipc::MessagePump::Run (this=0xb6a01df0, aDelegate=0xb6a4e1a0) at ../../../ipc/glue/MessagePump.cpp:95 #20 0xb449248a in MessageLoop::RunInternal (this=0xb6a4e1a0) at ../../../ipc/chromium/src/base/message_loop.cc:226 #21 0xb44924a2 in RunHandler (this=0xb6a4e1a0) at ../../../ipc/chromium/src/base/message_loop.cc:219 #22 MessageLoop::Run (this=0xb6a4e1a0) at ../../../ipc/chromium/src/base/message_loop.cc:193 #23 0xb4a30e4a in nsBaseAppShell::Run (this=0xb1f418e0) at ../../../widget/xpwidgets/nsBaseAppShell.cpp:164 #24 0xb5300dae in nsAppStartup::Run (this=0xb214fca0) at ../../../../toolkit/components/startup/nsAppStartup.cpp:276 #25 0xb52da7aa in XREMain::XRE_mainRun (this=0xbec7898c) at ../../../toolkit/xre/nsAppRunner.cpp:4008 #26 0xb52da9aa in XREMain::XRE_main (this=0xbec7898c, argc=<optimized out>, argv=<optimized out>, aAppData=<optimized out>) at ../../../toolkit/xre/nsAppRunner.cpp:4077 #27 0xb52dab00 in XRE_main (argc=1, argv=0xbec7ab44, aAppData=0x26908, aFlags=<optimized out>) at ../../../toolkit/xre/nsAppRunner.cpp:4289 #28 0x0000a4ec in do_main (argv=0xbec7ab44, argc=1) at ../../../b2g/app/nsBrowserApp.cpp:163 #29 main (argc=<optimized out>, argv=<optimized out>) at ../../../b2g/app/nsBrowserApp.cpp:256 (gdb) up #1 mozilla::dom::bluetooth::BluetoothServiceBluedroid::GetDefaultAdapterPathInternal (this=<optimized out>, aRunnable=<optimized out>) at ../../../dom/bluetooth/bluedroid/BluetoothServiceBluedroid.cpp:804 804 runnable.forget(); (gdb) p runnable $1 = {mRawPtr = 0x0} (gdb)
Uh STR is opening music app and not settings app.
Hi Gregor, (In reply to Gregor Wagner [:gwagner] from comment #20) > Can you explain what you think is different with your patch? In fact, last Friday I asked almost the same question to Thomas on irc about why his solution can solve the problem. The following is his answer: ==== tzimmermann> the problem is that forget returns |already_AddRefed|, which immediately gets deconstructed tzimmermann> it still has it's internal pointer set to the actual object. that makes the destructor assert and crash tzimmermann> if you look into xpcom/glue/nsCOMPtr.h you'll find already_AddRefed with operator << tzimmermann> the operator calls |take|, which clears the internal pointer. when the already_AddRefed gets destructed afterwards, the assertion will be fullfilled ==== I think what Thomas' tried to say is that http://dxr.mozilla.org/mozilla-central/source/xpcom/glue/nsCOMPtr.h?from=nsCOMPtr.h&case=true#168 will be executed when unused << runnable.forget(); is called. Therefore already_AddRefed.take() will be called as well, so runnable.mRawPtr will be cleared to nullptr, which can fulfill the assertion.
(In reply to Gregor Wagner [:gwagner] from comment #21) > Today I got this after opening the settings app: > > bt > #0 0xb4b53776 in ~already_AddRefed (this=<optimized out>, > __in_chrg=<optimized out>) at ../../dist/include/nsCOMPtr.h:165 > #1 > mozilla::dom::bluetooth::BluetoothServiceBluedroid:: > GetDefaultAdapterPathInternal (this=<optimized out>, aRunnable=<optimized > out>) > at ../../../dom/bluetooth/bluedroid/BluetoothServiceBluedroid.cpp:804 > #2 0xb4b4ab66 in mozilla::dom::bluetooth::BluetoothRequestParent::DoRequest > (this=0xad83d310, aRequest=<optimized out>) at > ../../../dom/bluetooth/ipc/BluetoothParent.cpp:311 > #3 0xb44caefa in > mozilla::dom::bluetooth::PBluetoothParent::OnMessageReceived > (this=0xad87b220, __msg=<optimized out>) at PBluetoothParent.cpp:413 > #4 0xb44f632e in mozilla::dom::PContentParent::OnMessageReceived > (this=0xad0c2c00, __msg=...) at PContentParent.cpp:2012 > #5 0xb44a0998 in mozilla::ipc::MessageChannel::DispatchAsyncMessage > (this=0xad0c2c30, aMsg=...) at ../../../ipc/glue/MessageChannel.cpp:1142 > #6 0xb44a3a48 in mozilla::ipc::MessageChannel::OnMaybeDequeueOne > (this=0xad0c2c30) at ../../../ipc/glue/MessageChannel.cpp:1039 > #7 0xb44a03a4 in DispatchToMethod<mozilla::ipc::MessageChannel, void > (mozilla::ipc::MessageChannel::*)()> (method= > (void (mozilla::ipc::MessageChannel::*)(mozilla::ipc::MessageChannel * > const)) 0xb44a39b5 <mozilla::ipc::MessageChannel::OnMaybeDequeueOne()>, > obj=<optimized out>, arg=<optimized out>) > at ../../../ipc/chromium/src/base/tuple.h:383 > #8 RunnableMethod<mozilla::ipc::MessageChannel, void > (mozilla::ipc::MessageChannel::*)(), Tuple0>::Run (this=<optimized out>) at > ../../../ipc/chromium/src/base/task.h:307 > #9 0xb44a0e1c in Run (this=<optimized out>) at > ../../dist/include/mozilla/ipc/MessageChannel.h:383 > #10 mozilla::ipc::MessageChannel::DequeueTask::Run (this=<optimized out>) at > ../../dist/include/mozilla/ipc/MessageChannel.h:400 > #11 0xb4492344 in MessageLoop::RunTask (this=0xb6a4e1a0, task=0xadc5bf80) at > ../../../ipc/chromium/src/base/message_loop.cc:344 > #12 0xb4492c82 in MessageLoop::DeferOrRunPendingTask (this=<optimized out>, > pending_task=<optimized out>) at > ../../../ipc/chromium/src/base/message_loop.cc:352 > #13 0xb4493d7e in DoWork (this=<optimized out>) at > ../../../ipc/chromium/src/base/message_loop.cc:430 > #14 MessageLoop::DoWork (this=0xb6a4e1a0) at > ../../../ipc/chromium/src/base/message_loop.cc:409 > #15 0xb44a4a9e in mozilla::ipc::DoWorkRunnable::Run (this=<optimized out>) > at ../../../ipc/glue/MessagePump.cpp:228 > #16 0xb42f7ca2 in ProcessNextEvent (result=0xbec787f7, mayWait=false, > this=0xb6a34680) at ../../../xpcom/threads/nsThread.cpp:694 > #17 nsThread::ProcessNextEvent (this=0xb6a34680, mayWait=<optimized out>, > result=0xbec787f7) at ../../../xpcom/threads/nsThread.cpp:618 > #18 0xb42b1dd0 in NS_ProcessNextEvent (thread=0xb6a34680, mayWait=<optimized > out>) at ../../../xpcom/glue/nsThreadUtils.cpp:263 > #19 0xb44a4ee8 in mozilla::ipc::MessagePump::Run (this=0xb6a01df0, > aDelegate=0xb6a4e1a0) at ../../../ipc/glue/MessagePump.cpp:95 > #20 0xb449248a in MessageLoop::RunInternal (this=0xb6a4e1a0) at > ../../../ipc/chromium/src/base/message_loop.cc:226 > #21 0xb44924a2 in RunHandler (this=0xb6a4e1a0) at > ../../../ipc/chromium/src/base/message_loop.cc:219 > #22 MessageLoop::Run (this=0xb6a4e1a0) at > ../../../ipc/chromium/src/base/message_loop.cc:193 > #23 0xb4a30e4a in nsBaseAppShell::Run (this=0xb1f418e0) at > ../../../widget/xpwidgets/nsBaseAppShell.cpp:164 > #24 0xb5300dae in nsAppStartup::Run (this=0xb214fca0) at > ../../../../toolkit/components/startup/nsAppStartup.cpp:276 > #25 0xb52da7aa in XREMain::XRE_mainRun (this=0xbec7898c) at > ../../../toolkit/xre/nsAppRunner.cpp:4008 > #26 0xb52da9aa in XREMain::XRE_main (this=0xbec7898c, argc=<optimized out>, > argv=<optimized out>, aAppData=<optimized out>) at > ../../../toolkit/xre/nsAppRunner.cpp:4077 > #27 0xb52dab00 in XRE_main (argc=1, argv=0xbec7ab44, aAppData=0x26908, > aFlags=<optimized out>) at ../../../toolkit/xre/nsAppRunner.cpp:4289 > #28 0x0000a4ec in do_main (argv=0xbec7ab44, argc=1) at > ../../../b2g/app/nsBrowserApp.cpp:163 > #29 main (argc=<optimized out>, argv=<optimized out>) at > ../../../b2g/app/nsBrowserApp.cpp:256 > (gdb) up > #1 > mozilla::dom::bluetooth::BluetoothServiceBluedroid:: > GetDefaultAdapterPathInternal (this=<optimized out>, aRunnable=<optimized > out>) > at ../../../dom/bluetooth/bluedroid/BluetoothServiceBluedroid.cpp:804 > 804 runnable.forget(); > (gdb) p runnable > $1 = {mRawPtr = 0x0} > (gdb) No idea why crash happened in this case. I thought mRawPtr = 0x0 can fulfill the assertion which is in the dtor of already_AddRefed.
Comment on attachment 8394676 [details] [diff] [review] [01] Bug 983590: Correctly forget pointer references in Bluedroid backend This patch will land as part of bug 985949.
Attachment #8394676 - Attachment is obsolete: true
Attachment #8394676 - Flags: review?(echou)
Attachment #8394676 - Flags: feedback?(anygregor)
Depends on: 985949
Hi Gregor, Does this bug still happen?
Flags: needinfo?(anygregor)
(In reply to Thomas Zimmermann [:tzimmermann] [:tdz] from comment #26) > Hi Gregor, > > Does this bug still happen? It works for me now.
Flags: needinfo?(anygregor)
Thanks. This issue has probably been fixed by bug 985949.
Status: ASSIGNED → RESOLVED
Closed: 12 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: