Closed Bug 99354 Opened 25 years ago Closed 24 years ago

crash [@ nsEditor::BeginUpdateViewBatch] after second email written offline and stored as "send later" - N621 [@ 0x00000008 - nsEditor::BeginTransaction][@ nsEditor::BeginUpdateViewBatch]

Categories

(MailNews Core :: Composition, defect, P3)

defect

Tracking

(Not tracked)

VERIFIED WORKSFORME
mozilla1.0

People

(Reporter: lukas_steiger, Assigned: kinmoz)

References

()

Details

(Keywords: crash, testcase, topcrash, Whiteboard: [Can't reproduce 03/13/02])

Crash Data

Attachments

(1 file)

Mozilla crash every time after a second email written offline and stored as "send later" to be sent later.
QA Contact: esther → gchan
Reporter, could you please provide more information? Build date, very specific steps to reproduce the prob., type of mail account (imap/pop/webmail), etc.. I tried doing send later with 2001-09-17-09-trunk (2001081703) on nt 4.0 & win2k and did not see a problem doing a send later for a 2nd mesg. This what I did: 1. logged into my imap mail account 2. went offline 3. Composed mesg, did a send later. 4. verified it stored the mesg in the folder called 'Unsent Messages' located under Local Folders account 5. Composed another mesg and did a send later. 6. verified it got stored 7. went back online and at the prompt, clicked the send button to send my unsent megs. Also tried going offline, compose a mesg, do a send later, go back online (sending the mesg when prompted), going offline again, doing a compose/send later, going back online and sending that mesg and there was no crash.
typo: buid id is 2001091703 NOT 2001081703.
inserting reporter's comments for steps to reproduce: Lukas Steiger wrote: > > Build date, very specific steps to reproduce the prob., type of mail > account (imap/pop/webmail), etc.. > > You nearly reproduced it. Now I have Build 2001091303 (0.94), it also > occured in v0.93 > > This what you need to do: > 1. log into your pop3 mail account > 2. go offline > 3. reply to a message stored in local folders, > 4. press "send later". > it gets stored in the folder called 'Unsent Messages' > located under Local Folders account > 5. Reply to another mesg and push "send later". > 6. now Mozilla crashes on my machine (OS W2K)
Reporter. Using 2001091703 commercial trunk on Win 2k. If I follow your steps to reproduce, i don't see a crash. When I reply to 2nd message, it gets stored in Unsent messages folder. No crash. I was not quite clear on > 3. reply to a message stored in local folders, I assume you mean replying to a message in a folder under the Local Folders account? > 5. Reply to another mesg and push "send later". Again I assume you mean replying to a message in a folder under the Local Folders account? So I wasn't sure whether you were replying to your inbox (or some sub folder in your pop mail account) mesgs for pop account or mail under local folder accounts. So i tested both. Replying to messages in my inbox: No problem. Replying to messages in a folder under Local Folder account: can't do it. There is a current bug out there, bug 100124, where in pop and for imap (local folder accounts only) that reply,reply all, etc. is disabled. So when i test this I can't even reply let alone do a send later. This bug has since been fixed. Can you try more current build and try creating a new profile using the same pop account and see if that works? Maybe your old profile is corrupted. thnks.
I looked at your talkback logs - here's the recurring stack trace: nsEditor::BeginUpdateViewBatch [d:\builds\seamonkey\mozilla\editor\base\nsEditor.cpp, line 4328] nsEditor::BeginTransaction [d:\builds\seamonkey\mozilla\editor\base\nsEditor.cpp, line 655] nsHTMLEditorLog::BeginTransaction [d:\builds\seamonkey\mozilla\editor\base\nsHTMLEditorLog.cpp, line 220] nsEditorShell::BeginBatchChanges [d:\builds\seamonkey\mozilla\editor\base\nsEditorShell.cpp, line 4806] nsMsgCompose::ConvertAndLoadComposeWindow [d:\builds\seamonkey\mozilla\mailnews\compose\src\nsMsgCompose.cpp, line 452] QuotingOutputStreamListener::OnStopRequest [d:\builds\seamonkey\mozilla\mailnews\compose\src\nsMsgCompose.cpp, line 1739] nsStreamConverter::OnStopRequest [d:\builds\seamonkey\mozilla\mailnews\mime\src\nsStreamConverter.cpp, line 1038] nsMsgProtocol::OnStopRequest [d:\builds\seamonkey\mozilla\mailnews\base\util\nsMsgProtocol.cpp, line 284] nsMailboxProtocol::OnStopRequest [d:\builds\seamonkey\mozilla\mailnews\local\src\nsMailboxProtocol.cpp, line 338] nsOnStopRequestEvent::HandleEvent [d:\builds\seamonkey\mozilla\netwerk\base\src\nsRequestObserverProxy.cpp, line 162] PL_HandleEvent [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 591] PL_ProcessPendingEvents [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 524] _md_EventReceiverProc [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 1072] nsAppShellService::Run [d:\builds\seamonkey\mozilla\xpfe\appshell\src\nsAppShellService.cpp, line 453] main1 [d:\builds\seamonkey\mozilla\xpfe\bootstrap\nsAppRunner.cpp, line 1276] main [d:\builds\seamonkey\mozilla\xpfe\bootstrap\nsAppRunner.cpp, line 1593] This would imply that the problem has to do with the compose window, and really nothing to do with send later. Is it always the same e-mail you're replying to, or do it not matter at all what the second email is? Is there anything special about the local mail you're replying to? Does it have html in it, for example, or is it from a mailing list? Is it hotmail mail with hotmail ads in it? Does this not happen when you're online?
Component: Mail Back End → Composition
taking
Assignee: mscott → bienvenu
Status: UNCONFIRMED → NEW
Ever confirmed: true
OK, I reproduced this crash. It doesn't really have to do with send later - if you do two replies while offline, you can run into this crash. The first thing that goes wrong is that in nsEditorShell::PrepareDocumentForEditing, we hit the assertion that mEditor should be null; it's not. Then we crash with the stack given. The view manager is horked. I'll try to track this down, but it looks like in some situations, the editor is not getting cleared out.
Here are my steps for reproducing this crash: 1. Send yourself the cnn home page (File | Send Page) 2. Read the message, in a folder which is configured for offline use). 3. Go offline. 4. Clear the disk and memory cache. 5. Reply to the message. Cancel the reply 6. Reply to a second message, probably doesn't matter which - crash What I've noticed is that if I do these steps w/o clearing the disk+memory cache, when I cancel the reply, it asks me if I want to save the changes (which it shouldn't, because I haven't changed anything, but that's a separate issue). But if I've cleared the caches, I don't get asked that question.
Status: NEW → ASSIGNED
The immediate cause of the problem is that in this scenario, we get two calls to nsEditorShell::EndPageLoad when we reply to the second message, and that gets the editor all messed up. I suspect this is due to some cruft left over from the reply to the first message, somehow, because of all the image urls it tries to fetch replying to the attached web page but fails because we're offline.
This crash with a bad view manager sounds very familiar. Kin might recall better than I the other bug.
Couple of more newer talk back ids linux 2.2 http://climate.mcom.com/reports/incidenttemplate.cfm?bbid=36892253 mac 9.1 http://climate.mcom.com/reports/incidenttemplate.cfm?bbid=36891617 http://climate.mcom.com/reports/incidenttemplate.cfm?bbid=36892125 I crashed doing a reply to a downloaded mesg w/netscape home page (10-18-01) in it while I was offline. Same stack trace as before: (mac stack) 0x00000008 nsEditor::BeginTransaction() [nsEditor.cpp, line 652] nsHTMLEditorLog::BeginTransaction() [nsHTMLEditorLog.cpp, line 219] nsEditorShell::BeginBatchChanges() [nsEditorShell.cpp, line 4805] nsMsgCompose::ConvertAndLoadComposeWindow() [nsMsgCompose.cpp, line 451] QuotingOutputStreamListener::OnStopRequest() [nsMsgCompose.cpp, line 1737]
Adding crash, topcrash keywords and N620 [@ 0x00000008 - nsEditor::BeginTransaction] so summary, since I've seen a few of these crashes on the N620 branch. Here are a couple of recent entries: 0x00000008 caeeec17 line Build: 2001101717 CrashDate: 2001-10-18 UptimeMinutes: 5 Total: 123 OS: MacOS version 9.1 Detailed : http://climate/reports/incidenttemplate.cfm?bbid=36892125 StackTrace: http://climate/reports/singleincidentinfo.cfm?dynamicBBID=36892125 (36892125) Comments: 10-17-rtm candidate (2nd one) mac 9.1reply all to a downloaded mesg w/netscape home page (todays)While i was offline I was doing reply 0x00000008 caeeec17 line Build: 2001101717 CrashDate: 2001-10-18 UptimeMinutes: 1 Total: 118 OS: MacOS version 9.1 Detailed : http://climate/reports/incidenttemplate.cfm?bbid=36891768 StackTrace: http://climate/reports/singleincidentinfo.cfm?dynamicBBID=36891768 (36891768) Comments: 10-17 rtm candidate (2nd build on 10-17)on mac 9.1did a reply to mesg whle offlne to todays 10-18 netscape home pagethis mesg was downloaded for offline use Changing Platform and OS to All since these recent crashes are on MacOS.
Keywords: crash, topcrash
OS: Windows 2000 → All
Hardware: PC → All
Summary: crash after second email written offline and stored as "send later" → crash after second email written offline and stored as "send later" - N620 [@ 0x00000008 - nsEditor::BeginTransaction]
Hmmm this looks just like bug 95243. The view manager is getting blown away the same way I saw when debugging that bug. It looks like I can prevent the crash by setting mEditor to null in the 2nd call to nsEditorShell::EndPageLoad() that happens ... sfraser suggested perhaps calling nsEditorShell::ResetEditingState() instead. We still need to figure out why nsEditorShell::OnStateChange() is getting called a 2nd time with the exact same flags. FYI, I can reproduce this bug following bienvenu's steps above, with any mail message containing an image.
reassigning to kin based on comments
Keywords: mailtrack
really reassigning
Assignee: bienvenu → kin
Status: ASSIGNED → NEW
Status: NEW → ASSIGNED
Priority: -- → P3
Target Milestone: --- → mozilla0.9.8
changing topcrash bugs to critical
Severity: normal → critical
I'm not seeing the signature nsEditor::BeginTransaction (from the summary) in any crash incidents in the Talkback database, either as the signature or the second frame beneath 0x00000008. Has this one mysteriously gone away?
You're right Tom. Using 20020111003 commercial trunk build on NT 4.0, I can't reproduce this crash anymore. Reporter, are you still having this problem? And what type of 'mesg' are you replying to when it crashes (ie html msg, mesg with attachment, embeded with web page (if so what type)) I tried following reporters steps and David's steps and I couldn't reproduce the 'same crash'. I was able to crash but stack trace is total different. Not sure I can constantly reproduce it. It has to do with replying to an old mesgs that have netscape home page ebeded in it. Tb1544744M and TB1544421Z
I didn't use Mozilla for writing emails offline in the last time. Now I tried to reproduce the bug and couldn't reproduce it either. Maybe it has mysteriously gone away... Lukas (lukas_steiger@hotmail.com)
Target Milestone: mozilla0.9.8 → mozilla0.9.9
I reproduced the bug in Build 0.97 (2001122106) and sent a talkback report with the bug number in the comment. Don't know whether the talkback logs are still the same, but the bug IS still the same. Lukas
Reporter, When replying/forwarding to an email mesg offline. Was there anything unique about the msg? Attachments, embeded web page, etc.. if so please describe. I know in one bug you mentioned jpeg attachment. Joaquin, I'll try to reprodce this again. I looked at the reporters talkback bugs: 1692856, 1599019. They are two totally different stack traces. And they don't reflect the orginal stack trace: nsEditor::BeginUpdateViewBatch. Not sure what to do, if I can't reproduce it. As it looks like the original stack error is now gone. For talkback id 1599019 nsAddrDatabase::NotifyCardEntryChange [d:\builds\seamonkey\mozilla\mailnews\addrbook\src\nsAddrDatabase.cpp, line 323] nsAddrDatabase::DeleteCard [d:\builds\seamonkey\mozilla\mailnews\addrbook\src\nsAddrDatabase.cpp, line 2285] nsAbAddressCollecter::CollectAddress [d:\builds\seamonkey\mozilla\mailnews\addrbook\src\nsAbAddressCollecter.cpp, line 195] Users comments: error occured while sending email after havin written it offline. One of the emails contained jpeg attachments It seems still not possible to use Mozilla as email-client, sending emails that were written offline... (see bug #99354, the "send later" bug seems to be fixed now ) 1. gone offline 2. replied to some email stored in local folders 3. forwarded some email containing (jpeg) attachments 4. gone online 5. accepted to send unsent email 6. mozilla crashed while sending the email containing attachments Talkback id 1692856 JS_GetFrameFunctionObject [d:\builds\seamonkey\mozilla\js\src\jsdbgapi.c, line 670] needsSecurityCheck [d:\builds\seamonkey\mozilla\dom\src\base\nsDOMClassInfo.cpp, line 2635] nsWindowSH::GetProperty [d:\builds\seamonkey\mozilla\dom\src\base\nsDOMClassInfo.cpp, line 2778] XPC_WN_Helper_GetProperty [d:\builds\seamonkey\mozilla\js\src\xpconnect\src\xpcwrappednativejsops.cpp, line 785]
I don't know anymore what I did yesterday (first talkback), better look at the talkback of today. I'll describe you what I did offline: 1. forwarded an email without attachment to a single address 2. forwarded another email without attachment to multiple addresses (selected them from my address book) 3. replied to that same email I forwarded in step 2 4. mozilla crashed, generated a talkback log 5. started mozilla again, sent the 3 unsent messages without problem The 2 emails were stored locally in my inbox folder. They're still in my inbox, I could post them if you want to look at the emails. Here follows part of the header of the 2 mails: X-UIDL: 385f7d310000123b X-Mozilla-Status: 0011 X-Mozilla-Status2: 00000000 X-Originating-IP: [128.151.203.42] MIME-version: 1.0 Content-type: text/plain; format=flowed Content-transfer-encoding: 8BIT X-OriginalArrivalTime: 15 Jan 2002 18:36:00.0969 (UTC) FILETIME=[7B060390:01C19DF3] Content-Length: 221 Status: O X-UIDL: 385f7d3100001239 X-Mozilla-Status: 0001 X-Mozilla-Status2: 00000000 MIME-version: 1.0 X-MIMEOLE: Produced By Microsoft Exchange V6.0.4712.0 Content-type: text/plain; charset=iso-8859-1 Content-transfer-encoding: 7BIT Thread-Topic: ISBT England thread-index: AcGd4MTgBd9S3BirTUOHdKL0TC4wZw== X-MS-Has-Attach: X-MS-TNEF-Correlator: Content-Length: 681 X-Keywords: Status: RO
Tried reproducing reporters steps in comment 23 and comment 22 and I was unable to reproduce the problem. no crashes. Mail was sent fine while offline. No problems using the addres book either. I was using commercial 2002-01-15-09-trunk build on win nt 4.0 Maybe update to a more current build? try new profile?
David or Kin, I was trying to follow david's step to reproduce in comment 9 and I noticed this result: -once I cleared memory and disk cache (while offline) I could not reply,reply all, forw a downloaded mesg while offline. Nothing happens. Tried various mesgs (text, html, w/attachments) nothing works after you clear the memory/disk cache. Works fine if you DONT clear the memory and disk cache. Is this a bug?
Using commercial trunk 2002-01-18-09-trunk NT 4.0 2002-01-18-08-trunk on linux 2.2 This bug DOES still exist.. I was able to replicate it in today's builds. I Could not replicate the situation I described in comment 25. Steps: 1.login to imap mail 2.download a few mesgs 3.I had compse mesg in html format set 4.Go offline 5.Go to Prefs and clear disk/memory cache 6.Reply to a downloaded mesg 7.Click the X in right top corner to kill the reply window 8.Repeat steps 6 and 7 as needed until crash. Talkback ids: TB1829044Q, TB1829507G, TB1829572Q - windows TB1832084W -linux Stack trace: nsEditor::BeginUpdateViewBatch [d:\builds\seamonkey\mozilla\editor\libeditor\base\nsEditor.cpp, line 4205] nsEditor::BeginTransaction [d:\builds\seamonkey\mozilla\editor\libeditor\base\nsEditor.cpp, line 658] nsHTMLEditorLog::BeginTransaction [d:\builds\seamonkey\mozilla\editor\libeditor\html\nsHTMLEditorLog.cpp, line 236] nsEditorShell::BeginBatchChanges [d:\builds\seamonkey\mozilla\editor\composer\src\nsEditorShell.cpp, line 4401] nsMsgCompose::ConvertAndLoadComposeWindow [d:\builds\seamonkey\mozilla\mailnews\compose\src\nsMsgCompose.cpp, line 494] QuotingOutputStreamListener::OnStopRequest [d:\builds\seamonkey\mozilla\mailnews\compose\src\nsMsgCompose.cpp, line 1975] nsStreamConverter::OnStopRequest [d:\builds\seamonkey\mozilla\mailnews\mime\src\nsStreamConverter.cpp, line 1059] nsImapCacheStreamListener::OnStopRequest [d:\builds\seamonkey\mozilla\mailnews\imap\src\nsImapProtocol.cpp, line 6821] nsOnStopRequestEvent::HandleEvent [d:\builds\seamonkey\mozilla\netwerk\base\src\nsRequestObserverProxy.cpp, line 213] PL_HandleEvent [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 591] PL_ProcessPendingEvents [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 524] _md_EventReceiverProc [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 1072]
Marking nsbeta1+
Keywords: nsbeta1+
--> mozilla1.0
Target Milestone: mozilla0.9.9 → mozilla1.0
This one was originally logged against N620. There are no incidents in the past 10 days of Talkback data for N621, M097, or M098 and only one on the Trunk from a build on 2/22. Any idea what might have changed to fix this one?
Keywords: testcase
Summary: crash after second email written offline and stored as "send later" - N620 [@ 0x00000008 - nsEditor::BeginTransaction] → crash after second email written offline and stored as "send later" - N620 [@ 0x00000008 - nsEditor::BeginTransaction][@ nsEditor::BeginUpdateViewBatch]
Still can reproduce this bug using 2002022703 on NT 4.0 I used steps in comment 9. Maybe that's why no one reports the problem? unless you clear the cache, the reply to a mesg won't crash? TB3447721W,TB3447885Z nsEditor::BeginUpdateViewBatch [d:\builds\seamonkey\mozilla\editor\libeditor\base\nsEditor.cpp, line 4192] nsEditor::BeginTransaction [d:\builds\seamonkey\mozilla\editor\libeditor\base\nsEditor.cpp, line 654] nsHTMLEditorLog::BeginTransaction [d:\builds\seamonkey\mozilla\editor\libeditor\html\nsHTMLEditorLog.cpp, line 236] nsEditorShell::BeginBatchChanges [d:\builds\seamonkey\mozilla\editor\composer\src\nsEditorShell.cpp, line 4410] nsMsgCompose::ConvertAndLoadComposeWindow [d:\builds\seamonkey\mozilla\mailnews\compose\src\nsMsgCompose.cpp, line 494] QuotingOutputStreamListener::OnStopRequest [d:\builds\seamonkey\mozilla\mailnews\compose\src\nsMsgCompose.cpp, line 1988] nsStreamConverter::OnStopRequest [d:\builds\seamonkey\mozilla\mailnews\mime\src\nsStreamConverter.cpp, line 1039] nsImapCacheStreamListener::OnStopRequest [d:\builds\seamonkey\mozilla\mailnews\imap\src\nsImapProtocol.cpp, line 6963] nsOnStopRequestEvent::HandleEvent [d:\builds\seamonkey\mozilla\netwerk\base\src\nsRequestObserverProxy.cpp, line 213] PL_HandleEvent [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 591] PL_ProcessPendingEvents [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 524] _md_EventReceiverProc [d:\builds\seamonkey\mozilla\xpcom\threads\plevent.c, line 1072]
Updating summary since this was/is a topcrasher for Netscape 6.21. I also see a few of these crashes with recent milestones and MozillaTrunk builds....so as gchan proved, this is still around. It looks like we have a reproducible testcase, so I won't bother cluttering the bug with more Talkback data.
Summary: crash after second email written offline and stored as "send later" - N620 [@ 0x00000008 - nsEditor::BeginTransaction][@ nsEditor::BeginUpdateViewBatch] → crash after second email written offline and stored as "send later" - N621 [@ 0x00000008 - nsEditor::BeginTransaction][@ nsEditor::BeginUpdateViewBatch]
I'm having a real hard time reproducing this bug with my debug build from today. gchan spent some time today trying to repro it too, but he couldn't crash it reliably. Just curious, how common is it for someone to take mail offline, clear both cache's, and reply twice to the same email with an image?
Sorry didn't post earlier was trying more testing.. Anyways, I was working with Kin and I can not reproduce this bug consistently. I was able to generate 2 crashes (w/same stack) but this was out of maybe 15 tries.. TB3723510Y & TB3724004G I tried both yesterday's and todays commercial trunk (2002030508 & 2002-03-06-06-trunk) and wasn't really successful in reproducing the crash. I don't know if jpatel or greer have any recent talkback/steps to reproduce this bug or not.. This definitly doesn't crash when you do a send later (original sub line of bug) and the only way I can somewhat create the bug is to follow David's steps in comment 9. Like Kin asked, how common is it to clear cache after going offline? Reporter do you still experience this in a current build?
I didn't experience that bug while replying emails offline in since v0.98, though I didn't explicitly try to reproduce the bug in the last time. Lukas
I still can't reproduce this bug. I'd like to move this off my mozilla1.0 plate, unless someone can tell me how to reliably reproduce this bug.
Whiteboard: [Can't reproduce 03/13/02]
Looking at the latest Talkback data, since N621 there are only 5 crashes reported for any recent milestone or mozillatrunk build. Since we are not able to reproduce this anymore (including the reporter), I'm going to mark this worksforme. If anyone does crash again or if this shows up in our topcrash reports we can reopen.
Status: ASSIGNED → RESOLVED
Closed: 24 years ago
Resolution: --- → WORKSFORME
This isn't happening on the trunk anymore, according to http://climate/reports/VeryFastSearchStackSigNEW.cfm?stacksig=nsEditor%3A%3ABeginUpdateViewBatch Looks like (according to the comments), this bug was elusive in obtaining steps to reproduce. Verified worksforme.
Status: RESOLVED → VERIFIED
QA Contact: gchan → stephend
Summary: crash after second email written offline and stored as "send later" - N621 [@ 0x00000008 - nsEditor::BeginTransaction][@ nsEditor::BeginUpdateViewBatch] → crash [@ nsEditor::BeginUpdateViewBatch] after second email written offline and stored as "send later" - N621 [@ 0x00000008 - nsEditor::BeginTransaction][@ nsEditor::BeginUpdateViewBatch]
Product: MailNews → Core
Product: Core → MailNews Core
Crash Signature: [@ nsEditor::BeginUpdateViewBatch] [@ 0x00000008 - nsEditor::BeginTransaction] [@ nsEditor::BeginUpdateViewBatch]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: