Closed Bug 1218205 Opened 9 years ago Closed 9 years ago

crash in seamonkey@0x64bd (mozalloc_abort) coming back from Safe Mode

Categories

(SeaMonkey :: General, defect)

x86_64
Linux
defect
Not set
critical

Tracking

(firefox44 affected)

RESOLVED DUPLICATE of bug 1213344
Tracking Status
firefox44 --- affected

People

(Reporter: tonymec, Unassigned)

Details

(Keywords: crash)

Crash Data

This bug was filed from the Socorro interface and is 
report bp-40df53b2-c294-4162-adaa-9a2862151025.
=============================================================

UA:"Mozilla/5.0 (X11; Linux x86_64; rv:44.0) Gecko/20100101 Firefox/44.0 SeaMonkey/2.41a1" ID:20151019003001 c-c:9579c61e62f5bdf1ac39e97074fec5b259d80256 m-c:d1a89632277fbaaf470c90a35573776048988f2d en-US

Crash happened when going back from Safe Mode ("Help → Restart with Addons Disabled" then untick "Restart with Addons Disabled" in the dialog before proceeding).

 SeaMonkey 2.41a1 Crash Report [@ seamonkey@0x64bd ]
Search Mozilla Support for Help
ID: 40df53b2-c294-4162-adaa-9a2862151025
Signature: seamonkey@0x64bd

    Details
    Metadata
    Modules
    Raw Dump
    Extensions

Signature 	seamonkey@0x64bd More Reports Search
UUID 	40df53b2-c294-4162-adaa-9a2862151025
Date Processed 	2015-10-25 16:03:26.149671
Uptime 	1239
Last Crash 	719020 seconds before submission
Install Age 	403464 since version was first installed.
Install Time 	2015-10-20 23:58:09
Product 	SeaMonkey
Version 	2.41a1
Build ID 	20151019003001
Release Channel 	nightly
OS 	Linux
OS Version 	0.0.0 Linux 3.16.7-29-desktop #1 SMP PREEMPT Fri Oct 23 00:46:04 UTC 2015 (6be6a97) x86_64
Build Architecture 	amd64
Build Architecture Info 	family 6 model 23 stepping 10 | 2
Crash Reason 	SIGSEGV
Crash Address 	0x0
User Comments 	Restarting "from" Safe Mode into normal "unsafe" mode
App Notes 	

OpenGL: Intel Open Source Technology Center -- Mesa DRI Intel(R) Q45/Q43  -- 2.1 Mesa 10.3.7 -- texture_from_pixmap
xpcom_runtime_abort([11707] ###!!! ABORT: NULL actor value passed to non-nullable param: file PImageBridgeChild.cpp, line 3100)

Processor Notes 	processor_ip-172-31-26-175_1263; MozillaProcessorAlgorithm2015; skunk_classifier: reject - not a plugin hang
EMCheckCompatibility 	

True

Winsock LSP 	

Adapter Vendor ID 	

Adapter Device ID 	

Bugzilla - Report this bug in SeaMonkey Core Plugins Toolkit
Related Bugs

Crashing Thread
Frame 	Module 	Signature 	Source 	 	Function
Ø 0 	seamonkey 	seamonkey@0x64bd 	mozalloc_abort(char const*)
Ø 1 	libxul.so 	libxul.so@0xc84779 	NS_DebugBreak
Ø 2 	libxul.so 	libxul.so@0xf14130 	mozilla::layers::PImageBridgeChild::Write(mozilla::layers::PCompositableChild*, IPC::Message*, bool)
Ø 3 	libxul.so 	libxul.so@0xf14330 	mozilla::layers::PImageBridgeChild::Write(mozilla::layers::OpRemoveTexture const&, IPC::Message*)
Ø 4 	libxul.so 	libxul.so@0xf18dc7 	mozilla::layers::PImageBridgeChild::Write(nsTArray<mozilla::layers::CompositableOperation> const&, IPC::Message*)
Ø 5 	libxul.so 	libxul.so@0xf18e32 	mozilla::layers::PImageBridgeChild::SendUpdateNoSwap(nsTArray<mozilla::layers::CompositableOperation> const&)
Ø 6 	libxul.so 	libxul.so@0x12b77de 	mozilla::layers::ImageBridgeChild::EndTransaction()
Ø 7 	libxul.so 	libxul.so@0x12b78a3 	mozilla::layers::FlushAllImagesSync
Ø 8 	libxul.so 	libxul.so@0xea18d0 	MessageLoop::RunTask(Task*)
Ø 9 	libxul.so 	libxul.so@0xea5de6 	MessageLoop::DeferOrRunPendingTask(MessageLoop::PendingTask const&)
Ø 10 	libxul.so 	libxul.so@0xea5f0d 	MessageLoop::DoWork()
Ø 11 	libxul.so 	libxul.so@0xea1d94 	base::MessagePumpDefault::Run(base::MessagePump::Delegate*)
Ø 12 	libxul.so 	libxul.so@0xea193b 	MessageLoop::Run()
Ø 13 	libxul.so 	libxul.so@0xea85d2 	base::Thread::ThreadMain()
Ø 14 	libxul.so 	libxul.so@0xea62eb 	ThreadFunc
Ø 15 	libpthread-2.19.so 	libpthread-2.19.so@0x80a3 	
Ø 16 	libc-2.19.so 	libc-2.19.so@0xe508c 	

Show other threads 


The above stack was painstakingly interpreted with the help of the corresponding crashreporter-symbols.zip
Summary: crash in seamonkey@0x64bd → crash in seamonkey@0x64bd coming back from Safe Mode
P.S.
Reproducible: Didn't try.
Happened again with identical stack, bp-167309b7-c4da-445c-81de-f58072151026
N.B.
1. I have 168 tabs and both crashes happened after I had dragged one of them in Safe Mode to a different point on the tab bar, I suppose this is not a factor? (I have a userChrome.css rule to display tabs on several rows instead of as a scrolling bar, and this means that, except in Safe Mode, I can only drag a tab onto the first row, i.e. to positions 1-69.)
2. There are more recent nightlies but I'm not using them because of bug 1218145 which is a non-starter for me.
Today I got the same crash in a build for which Socorro had the symbols. That's crash bp-c49066d2-767e-4896-898e-9dacb2151029 — here are the details:

Signature 	mozalloc_abort | NS_DebugBreak | mozilla::layers::PImageBridgeChild::Write More Reports Search
UUID 	c49066d2-767e-4896-898e-9dacb2151029
Date Processed 	2015-10-29 16:52:52.308977
Uptime 	38978
Last Crash 	180662 seconds before submission
Install Age 	101419 since version was first installed.
Install Time 	2015-10-28 12:42:00
Product 	SeaMonkey
Version 	2.41a1
Build ID 	20151028003002
Release Channel 	nightly
OS 	Linux
OS Version 	0.0.0 Linux 3.16.7-29-desktop #1 SMP PREEMPT Fri Oct 23 00:46:04 UTC 2015 (6be6a97) x86_64
Build Architecture 	amd64
Build Architecture Info 	family 6 model 23 stepping 10 | 2
Crash Reason 	SIGSEGV
Crash Address 	0x0
User Comments 	restarting out of Safe Mode
App Notes 	

OpenGL: Intel Open Source Technology Center -- Mesa DRI Intel(R) Q45/Q43  -- 2.1 Mesa 10.3.7 -- texture_from_pixmap
xpcom_runtime_abort([25445] ###!!! ABORT: NULL actor value passed to non-nullable param: file PImageBridgeChild.cpp, line 3100)

Processor Notes 	processor_ip-172-31-1-20_1284; MozillaProcessorAlgorithm2015; skunk_classifier: reject - not a plugin hang
EMCheckCompatibility 	

True

Winsock LSP 	

Adapter Vendor ID 	

Adapter Device ID 	

Bugzilla - Report this bug in SeaMonkey Core Plugins Toolkit
Related Bugs

    1215195NEW --- continued abort crash in mozilla::layers::PImageBridgeChild::Write
    1213344NEW --- shutdown crash in mozalloc_abort | NS_DebugBreak | mozilla::layers::PImageBridgeChild::Write and 100% CPU usage on certain page, ( replacing video element using innerHTML clones hidden video element )
    1208071RESOLVED FIXED abort crash in mozilla::layers::PImageBridgeChild::Write

Crashing Thread
Frame 	Module 	Signature 	Source
0 	seamonkey 	mozalloc_abort(char const*) 	/builds/slave/c-cen-t-lnx64/build/mozilla/memory/mozalloc/mozalloc_abort.cpp:33
1 	libxul.so 	NS_DebugBreak 	/builds/slave/c-cen-t-lnx64/build/mozilla/xpcom/base/nsDebugImpl.cpp:451
2 	libxul.so 	mozilla::layers::PImageBridgeChild::Write(mozilla::layers::PCompositableChild*, IPC::Message*, bool) 	/builds/slave/c-cen-t-lnx64/build/objdir/ipc/ipdl/PImageBridgeChild.cpp:3107
3 	libxul.so 	mozilla::layers::PImageBridgeChild::Write(mozilla::layers::OpRemoveTexture const&, IPC::Message*) 	/builds/slave/c-cen-t-lnx64/build/objdir/ipc/ipdl/PImageBridgeChild.cpp:2405
4 	libxul.so 	mozilla::layers::PImageBridgeChild::Write(nsTArray<mozilla::layers::CompositableOperation> const&, IPC::Message*) 	/builds/slave/c-cen-t-lnx64/build/objdir/ipc/ipdl/PImageBridgeChild.cpp:3315
5 	libxul.so 	mozilla::layers::PImageBridgeChild::SendUpdateNoSwap(nsTArray<mozilla::layers::CompositableOperation> const&) 	/builds/slave/c-cen-t-lnx64/build/objdir/ipc/ipdl/PImageBridgeChild.cpp:232
6 	libxul.so 	mozilla::layers::ImageBridgeChild::EndTransaction() 	gfx/layers/ipc/ImageBridgeChild.cpp
7 	libxul.so 	mozilla::layers::FlushAllImagesSync 	gfx/layers/ipc/ImageBridgeChild.cpp
8 	libxul.so 	MessageLoop::RunTask(Task*) 	ipc/chromium/src/base/message_loop.cc
9 	libxul.so 	MessageLoop::DeferOrRunPendingTask(MessageLoop::PendingTask const&) 	ipc/chromium/src/base/message_loop.cc
10 	libxul.so 	MessageLoop::DoWork() 	ipc/chromium/src/base/message_loop.cc
11 	libxul.so 	base::MessagePumpDefault::Run(base::MessagePump::Delegate*) 	ipc/chromium/src/base/message_pump_default.cc
12 	libxul.so 	MessageLoop::Run() 	ipc/chromium/src/base/message_loop.cc
13 	libxul.so 	base::Thread::ThreadMain() 	ipc/chromium/src/base/thread.cc
14 	libxul.so 	ThreadFunc 	ipc/chromium/src/base/platform_thread_posix.cc
Ø 15 	libpthread-2.19.so 	libpthread-2.19.so@0x80a3 	
Ø 16 	libc-2.19.so 	libc-2.19.so@0xe508c 	

and here are its changeset IDs from its seamonkey-2.41a1.en-US.linux-x86_64.txt:

20151028003002
http://hg.mozilla.org/mozilla-central/rev/2b333a1d94e805a59c619ee41a6dec7fdcce505d
http://hg.mozilla.org/comm-central/rev/487b69abf1ec
Crash Signature: [@ seamonkey@0x64bd] → [@ seamonkey@0x64bd] [@ mozalloc_abort | NS_DebugBreak | mozilla::layers::PImageBridgeChild::Write]
Summary: crash in seamonkey@0x64bd coming back from Safe Mode → crash in seamonkey@0x64bd (mozalloc_abort) coming back from Safe Mode
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.