Closed
Bug 1324493
Opened 8 years ago
Closed 5 years ago
[css-grid] Null-deref in [@ InvalidArrayIndex_CRASH] with css subgrid
Categories
(Core :: Layout, defect, P5)
Core
Layout
Tracking
()
RESOLVED
DUPLICATE
of bug 1248227
People
(Reporter: truber, Unassigned)
References
(Blocks 1 open bug)
Details
(Keywords: crash, testcase)
Attachments
(1 file)
(deleted),
text/html
|
Details |
The attached testcase causes a Null-deref crash in mozilla-central rev d4b3146a5567 with layout.css.grid-template-subgrid-value.enabled
==7630==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x7f3e7dcfc17e bp 0x7ffc85423b10 sp 0x7ffc85423af0 T0)
#0 0x7f3e7dcfc17d in InvalidArrayIndex_CRASH(unsigned long, unsigned long) /home/worker/workspace/build/src/xpcom/glue/nsTArray.cpp:35:3
#1 0x7f3e84be0402 in ElementAt /home/worker/workspace/build/src/obj-firefox/dist/include/nsTArray.h:1172:7
#2 0x7f3e84be0402 in operator[] /home/worker/workspace/build/src/obj-firefox/dist/include/nsTArray.h:1201
#3 0x7f3e84be0402 in MinSizingFor /home/worker/workspace/build/src/layout/generic/nsGridContainerFrame.cpp:1266
#4 0x7f3e84be0402 in nsGridContainerFrame::Tracks::Initialize(nsGridContainerFrame::TrackSizingFunctions const&, nsStyleCoord const&, unsigned int, int) /home/worker/workspace/build/src/layout/generic/nsGridContainerFrame.cpp:3678
#5 0x7f3e84bdf665 in nsGridContainerFrame::GridReflowInput::CalculateTrackSizes(nsGridContainerFrame::Grid const&, mozilla::LogicalSize&, SizingConstraint) /home/worker/workspace/build/src/layout/generic/nsGridContainerFrame.cpp:2574:3
#6 0x7f3e84c0997e in nsGridContainerFrame::Reflow(nsPresContext*, mozilla::ReflowOutput&, mozilla::ReflowInput const&, unsigned int&) /home/worker/workspace/build/src/layout/generic/nsGridContainerFrame.cpp:6133:5
#7 0x7f3e84acb30d in nsBlockReflowContext::ReflowBlock(mozilla::LogicalRect const&, bool, nsCollapsingMargin&, int, bool, nsLineBox*, mozilla::ReflowInput&, unsigned int&, mozilla::BlockReflowInput&) /home/worker/workspace/build/src/layout/generic/nsBlockReflowContext.cpp:306:3
#8 0x7f3e84abfdbc in nsBlockFrame::ReflowBlockFrame(mozilla::BlockReflowInput&, nsLineList_iterator, bool*) /home/worker/workspace/build/src/layout/generic/nsBlockFrame.cpp:3429:7
#9 0x7f3e84ab3876 in ReflowLine /home/worker/workspace/build/src/layout/generic/nsBlockFrame.cpp:2798:5
Updated•8 years ago
|
Blocks: subgrid
Priority: -- → P5
Summary: Null-deref in [@ InvalidArrayIndex_CRASH] with css subgrid → [css-grid] Null-deref in [@ InvalidArrayIndex_CRASH] with css subgrid
Updated•8 years ago
|
Blocks: css-grid-2
Updated•7 years ago
|
Has Regression Range: --- → irrelevant
status-firefox56:
--- → disabled
status-firefox57:
--- → disabled
status-firefox58:
--- → disabled
status-firefox-esr52:
--- → disabled
Flags: in-testsuite?
Comment 2•5 years ago
|
||
Testcase is pretty much the same as in bug 1248227, so duping.
Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → DUPLICATE
You need to log in
before you can comment on or make changes to this bug.
Description
•